2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23555 | CRITICAL | 9.8 | 2.7% | Feb 11, 2022 | The package vm2 before 3.9.6 are vulnerable to Sandbox Bypass via direct access to host error objects generated by node ... |
| CVE-2021-20001 | CRITICAL | 9.8 | 1.6% | Feb 11, 2022 | It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 co... |
| CVE-2021-4046 | MEDIUM | 5.4 | 0.4% | Feb 11, 2022 | The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vuln... |
| CVE-2021-4035 | MEDIUM | 4.8 | 0.4% | Feb 11, 2022 | A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of ... |
| CVE-2021-44111 | MEDIUM | 4.4 | 0.5% | Feb 11, 2022 | A Directory Traversal vulnerability exists in S-Cart 6.7 via download in sc-admin/backup. |
| CVE-2021-39688 | MEDIUM | 5.5 | 0.1% | Feb 11, 2022 | In TBD of TBD, there is a possible out of bounds read due to TBD. This could lead to local information disclosure with n... |
| CVE-2021-39687 | MEDIUM | 5.5 | 0.1% | Feb 11, 2022 | In HandleTransactionIoEvent of actuator_driver.cc, there is a possible out of bounds read due to a heap buffer overflow.... |
| CVE-2021-39677 | HIGH | 7.5 | 0.4% | Feb 11, 2022 | In startVideoStream() there is a possibility of an OOB Read in the heap, when the camera buffer is ‘zero’ in size.Produc... |
| CVE-2021-39676 | HIGH | 7.8 | 0.1% | Feb 11, 2022 | In writeThrowable of AndroidFuture.java, there is a possible parcel serialization/deserialization mismatch due to improp... |
| CVE-2021-39675 | CRITICAL | 9.8 | 5.9% | Feb 11, 2022 | In GKI_getbuf of gki_buffer.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead t... |
| CVE-2021-39674 | HIGH | 7.8 | 0.1% | Feb 11, 2022 | In btm_sec_connected and btm_sec_disconnected of btm_sec.cc file , there is a possible use after free. This could lead t... |
| CVE-2021-39672 | HIGH | 7.8 | 0.1% | Feb 11, 2022 | In fastboot, there is a possible secure boot bypass due to a configuration error. This could lead to local escalation of... |
| CVE-2021-39671 | MEDIUM | 6.5 | 0.5% | Feb 11, 2022 | In code generated by aidl_const_expressions.cpp, there is a possible out of bounds read due to uninitialized data. This ... |
| CVE-2021-39669 | HIGH | 7.8 | 0.1% | Feb 11, 2022 | In onCreate of InstallCaCertificateWarning.java, there is a possible way to mislead an user about CA installation circum... |
| CVE-2021-39668 | HIGH | 7.8 | 0.1% | Feb 11, 2022 | In onActivityViewReady of DetailDialog.kt, there is a possible Intent Redirect due to a confused deputy. This could lead... |
| CVE-2021-39666 | MEDIUM | 5.5 | 0.1% | Feb 11, 2022 | In extract of MediaMetricsItem.h, there is a possible out of bounds read due to improper input validation. This could le... |
| CVE-2021-39665 | MEDIUM | 6.5 | 0.7% | Feb 11, 2022 | In checkSpsUpdated of AAVCAssembler.cpp, there is a possible out of bounds read due to a heap buffer overflow. This coul... |
| CVE-2021-39664 | MEDIUM | 5.5 | 0.1% | Feb 11, 2022 | In LoadedPackage::Load of LoadedArsc.cpp, there is a possible out of bounds read due to a missing bounds check. This cou... |
| CVE-2021-39663 | HIGH | 7.8 | 0.1% | Feb 11, 2022 | In openFileAndEnforcePathPermissionsHelper of MediaProvider.java, there is a possible bypass of a permissions check due ... |
| CVE-2021-39662 | HIGH | 7.8 | 0.1% | Feb 11, 2022 | In checkUriPermission of MediaProvider.java , there is a possible way to gain access to the content of media provider co... |
| CVE-2021-39658 | CRITICAL | 9.8 | 0.6% | Feb 11, 2022 | ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does ... |
| CVE-2021-39635 | CRITICAL | 9.1 | 0.5% | Feb 11, 2022 | ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions... |
| CVE-2021-39631 | MEDIUM | 5.5 | 0.1% | Feb 11, 2022 | In clear_data_dlg_text of strings.xml, there is a possible situation when "Clear storage" functionality sets up the wron... |
| CVE-2021-39619 | HIGH | 7.8 | 0.1% | Feb 11, 2022 | In updatePackageMappingsData of UsageStatsService.java, there is a possible way to bypass security and privacy settings ... |
| CVE-2021-39616 | CRITICAL | 9.8 | 0.6% | Feb 11, 2022 | Summary:Product: AndroidVersions: Android SoCAndroid ID: A-204686438 |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now