2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-0587HIGH7.8In StreamOut::prepareForWriting of StreamOut.cpp, there is a possible out of bounds write due to a use after free. This ...
CVE-2021-0586HIGH7.8In onCreate of DevicePickerFragment.java, there is a possible way to trick the user to select an unwanted bluetooth devi...
CVE-2021-0577HIGH7.8In flv extractor, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escala...
CVE-2021-0514HIGH8.1In several functions of the V8 library, there is a possible use after free due to a race condition. This could lead to r...
CVE-2021-0486HIGH7.8In onPackageAddedInternal of PermissionManagerService.java, there is possible access to external storage due to a permis...
CVE-2021-0441HIGH7.3In onCreate of PermissionActivity.java, there is a possible permission bypass due to Confusing UI. This could lead to lo...
CVE-2021-35469HIGH7.8The Lexmark Printer Software G2, G3 and G4 Installation Packages have a local escalation of privilege vulnerability due ...
CVE-2021-33677HIGH7.5SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 702, 730, 731, 804, 740, 750, 784, expose functions to exte...
CVE-2021-33676HIGH7.2A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with hi...
CVE-2021-33671HIGH8.8SAP NetWeaver Guided Procedures (Administration Workset), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, does not perfor...
CVE-2021-33670HIGH7.5SAP NetWeaver AS for Java (Http Service Monitoring Filter), versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows ...
CVE-2021-20782HIGH8.8Cross-site request forgery (CSRF) vulnerability in Software License Manager versions prior to 4.4.6 allows remote attack...
CVE-2021-20781HIGH8.8Cross-site request forgery (CSRF) vulnerability in WordPress Meta Data Filter & Taxonomies Filter versions prior to v.1....
CVE-2021-20748HIGH7.5Retty App for Android versions prior to 4.8.13 and Retty App for iOS versions prior to 4.11.14 uses a hard-coded API key...
CVE-2021-22000HIGH7.8VMware Thinapp version 5.x prior to 5.2.10 contain a DLL hijacking vulnerability due to insecure loading of DLLs. A mali...
CVE-2021-21995HIGH7.5OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-bounds read issue. A malicious actor wit...
CVE-2021-20423HIGH8.8IBM Cloud Pak for Applications 4.3 could allow an authenticated user gain escalated privilesges due to improper applicat...
CVE-2021-20422HIGH7.5IBM Cloud Pak for Applications 4.3 could disclose sensitive information to a malicious attacker by accessing data stored...
CVE-2021-20360HIGH7.5IBM Cloud Pak for Applications 4.3 uses weaker than expected cryptographic algorithms that could allow an attacker to de...
CVE-2021-36122HIGH8.8An issue was discovered in Echo ShareCare 8.15.5. The UnzipFile feature in Access/EligFeedParse_Sup/UnzipFile_Upd.cfm is...
CVE-2021-36121HIGH8.8An issue was discovered in Echo ShareCare 8.15.5. The file-upload feature in Access/DownloadFeed_Mnt/FileUpload_Upd.cfm ...
CVE-2021-20593HIGH7.1Incorrect Implementation of Authentication Algorithm in Mitsubishi Electric Air Conditioning System/Centralized Controll...
CVE-2021-36376HIGH7.8dandavison delta before 0.8.3 on Windows resolves an executable's pathname as a relative path from the current directory...
CVE-2021-31225HIGH7.3SES Evolution before 2.1.0 allows deleting some resources not currently in use by any security policy by leveraging acce...
CVE-2021-34331HIGH7.8A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). Th...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now