2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-39627HIGH7.8In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe...
CVE-2021-39626HIGH7.8In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. Th...
CVE-2021-39625HIGH7.3In showCarrierAppInstallationNotification of EuiccNotificationManager.java, there is a possible way to gain an access to...
CVE-2021-39623CRITICAL9.8In doRead of SimpleDecodingSource.cpp, there is a possible out of bounds write due to an incorrect bounds check. This co...
CVE-2021-39622HIGH7.8In GBoard, there is a possible way to bypass Factory Reset Protection due to a missing permission check. This could lead...
CVE-2021-39621HIGH7.8In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe...
CVE-2021-39620HIGH7.8In ipcSetDataReference of Parcel.cpp, there is a possible way to corrupt memory due to a use after free. This could lead...
CVE-2021-39618HIGH7.8In multiple methods of EuiccNotificationManager.java, there is a possible way to install existing packages without user ...
CVE-2021-38127MEDIUM6.1Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7...
CVE-2021-38126MEDIUM6.1Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7...
CVE-2021-36920MEDIUM5.4Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versio...
CVE-2021-36199MEDIUM5.3Running a vulnerability scanner against VideoEdge NVRs can cause some functionality to stop.
CVE-2021-28507HIGH7.1An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for Open...
CVE-2021-28506CRITICAL9.1An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentic...
CVE-2021-28501HIGH7.8An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and Ter...
CVE-2021-28500HIGH7.8An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and Ter...
CVE-2021-23567HIGH7.5The package colors after 1.4.0 are vulnerable to Denial of Service (DoS) that was introduced through an infinite loop in...
CVE-2021-23566MEDIUM5.5The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which ...
CVE-2021-23157HIGH7.8WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a heap-based buffer overflow, which may allow an attac...
CVE-2021-23138HIGH7.8WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a stack-based buffer overflow, which may allow an atta...
CVE-2021-20613HIGH7.5Improper initialization vulnerability in MELSEC-F series FX3U-ENET Firmware version 1.16 and prior, FX3U-ENET-L Firmware...
CVE-2021-20612HIGH7.5Lack of administrator control over security vulnerability in MELSEC-F series FX3U-ENET Firmware version 1.14 and prior, ...
CVE-2021-1049CRITICAL9.8Hacker one bug ID: 1343975Product: AndroidVersions: Android SoCAndroid ID: A-204256722
CVE-2021-1037MEDIUM5.3The broadcast that DevicePickerFragment sends when a new device is paired doesn't have any permission checks, so any app...
CVE-2021-1036HIGH7.8In LocationSettingsActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This cou...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now