2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39627 | HIGH | 7.8 | 0.1% | Jan 14, 2022 | In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe... |
| CVE-2021-39626 | HIGH | 7.8 | 0.2% | Jan 14, 2022 | In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. Th... |
| CVE-2021-39625 | HIGH | 7.3 | 0.1% | Jan 14, 2022 | In showCarrierAppInstallationNotification of EuiccNotificationManager.java, there is a possible way to gain an access to... |
| CVE-2021-39623 | CRITICAL | 9.8 | 2.0% | Jan 14, 2022 | In doRead of SimpleDecodingSource.cpp, there is a possible out of bounds write due to an incorrect bounds check. This co... |
| CVE-2021-39622 | HIGH | 7.8 | 0.1% | Jan 14, 2022 | In GBoard, there is a possible way to bypass Factory Reset Protection due to a missing permission check. This could lead... |
| CVE-2021-39621 | HIGH | 7.8 | 0.1% | Jan 14, 2022 | In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe... |
| CVE-2021-39620 | HIGH | 7.8 | 0.1% | Jan 14, 2022 | In ipcSetDataReference of Parcel.cpp, there is a possible way to corrupt memory due to a use after free. This could lead... |
| CVE-2021-39618 | HIGH | 7.8 | 0.1% | Jan 14, 2022 | In multiple methods of EuiccNotificationManager.java, there is a possible way to install existing packages without user ... |
| CVE-2021-38127 | MEDIUM | 6.1 | 0.6% | Jan 14, 2022 | Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7... |
| CVE-2021-38126 | MEDIUM | 6.1 | 0.6% | Jan 14, 2022 | Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7... |
| CVE-2021-36920 | MEDIUM | 5.4 | 0.6% | Jan 14, 2022 | Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versio... |
| CVE-2021-36199 | MEDIUM | 5.3 | 1.0% | Jan 14, 2022 | Running a vulnerability scanner against VideoEdge NVRs can cause some functionality to stop. |
| CVE-2021-28507 | HIGH | 7.1 | 0.7% | Jan 14, 2022 | An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for Open... |
| CVE-2021-28506 | CRITICAL | 9.1 | 1.4% | Jan 14, 2022 | An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentic... |
| CVE-2021-28501 | HIGH | 7.8 | 0.8% | Jan 14, 2022 | An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and Ter... |
| CVE-2021-28500 | HIGH | 7.8 | 0.9% | Jan 14, 2022 | An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and Ter... |
| CVE-2021-23567 | HIGH | 7.5 | 1.7% | Jan 14, 2022 | The package colors after 1.4.0 are vulnerable to Denial of Service (DoS) that was introduced through an infinite loop in... |
| CVE-2021-23566 | MEDIUM | 5.5 | 0.4% | Jan 14, 2022 | The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which ... |
| CVE-2021-23157 | HIGH | 7.8 | 8.2% | Jan 14, 2022 | WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a heap-based buffer overflow, which may allow an attac... |
| CVE-2021-23138 | HIGH | 7.8 | 9.3% | Jan 14, 2022 | WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a stack-based buffer overflow, which may allow an atta... |
| CVE-2021-20613 | HIGH | 7.5 | 3.6% | Jan 14, 2022 | Improper initialization vulnerability in MELSEC-F series FX3U-ENET Firmware version 1.16 and prior, FX3U-ENET-L Firmware... |
| CVE-2021-20612 | HIGH | 7.5 | 3.6% | Jan 14, 2022 | Lack of administrator control over security vulnerability in MELSEC-F series FX3U-ENET Firmware version 1.14 and prior, ... |
| CVE-2021-1049 | CRITICAL | 9.8 | 0.7% | Jan 14, 2022 | Hacker one bug ID: 1343975Product: AndroidVersions: Android SoCAndroid ID: A-204256722 |
| CVE-2021-1037 | MEDIUM | 5.3 | 0.3% | Jan 14, 2022 | The broadcast that DevicePickerFragment sends when a new device is paired doesn't have any permission checks, so any app... |
| CVE-2021-1036 | HIGH | 7.8 | 0.3% | Jan 14, 2022 | In LocationSettingsActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This cou... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now