2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21482 | HIGH | 8.3 | 0.4% | Apr 13, 2021 | SAP NetWeaver Master Data Management, versions - 710, 710.750, allows a malicious unauthorized user with access to the M... |
| CVE-2021-0446 | HIGH | 7.3 | 0.1% | Apr 13, 2021 | In ImportVCardActivity, there is a possible way to bypass user consent due to a tapjacking/overlay attack. This could le... |
| CVE-2021-0445 | HIGH | 7.8 | 0.1% | Apr 13, 2021 | In start of WelcomeActivity.java, there is a possible residual profile due to a confused deputy. This could lead to loca... |
| CVE-2021-0442 | HIGH | 7.8 | 0.1% | Apr 13, 2021 | In updateInfo of android_hardware_input_InputApplicationHandle.cpp, there is a possible control of code flow due to a us... |
| CVE-2021-0439 | HIGH | 7.8 | 0.1% | Apr 13, 2021 | In setPowerModeWithHandle of com_android_server_power_PowerManagerService.cpp, there is a possible out of bounds write d... |
| CVE-2021-0438 | HIGH | 7.8 | 0.1% | Apr 13, 2021 | In several functions of InputDispatcher.cpp, WindowManagerService.java, and related files, there is a possible tapjackin... |
| CVE-2021-0437 | HIGH | 7.8 | 0.2% | Apr 13, 2021 | In setPlayPolicy of DrmPlugin.cpp, there is a possible double free. This could lead to local escalation of privilege in ... |
| CVE-2021-0435 | HIGH | 7.5 | 1.7% | Apr 13, 2021 | In avrc_proc_vendor_command of avrc_api.cc, there is a possible leak of heap data due to uninitialized data. This could ... |
| CVE-2021-0433 | HIGH | 8 | 0.6% | Apr 13, 2021 | In onCreate of DeviceChooserActivity.java, there is a possible way to bypass user consent when pairing a Bluetooth devic... |
| CVE-2021-0432 | HIGH | 7 | 0.1% | Apr 13, 2021 | In ClearPullerCacheIfNecessary and ForceClearPullerCache of StatsPullerManager.cpp, there is a possible use-after-free d... |
| CVE-2021-0431 | HIGH | 7.5 | 1.7% | Apr 13, 2021 | In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds read due to a missing bounds check. This could lead ... |
| CVE-2021-0429 | HIGH | 7.8 | 0.1% | Apr 13, 2021 | In pollOnce of ALooper.cpp, there is possible memory corruption due to a use after free. This could lead to local escala... |
| CVE-2021-0427 | HIGH | 7.8 | 0.1% | Apr 13, 2021 | In parseExclusiveStateAnnotation of LogEvent.cpp, there is a possible out of bounds write due to a heap buffer overflow.... |
| CVE-2021-0426 | HIGH | 7.8 | 0.1% | Apr 13, 2021 | In parsePrimaryFieldFirstUidAnnotation of LogEvent.cpp, there is a possible out of bounds write due to a heap buffer ove... |
| CVE-2021-21731 | HIGH | 8.1 | 0.4% | Apr 13, 2021 | A CSRF vulnerability exists in the management page of a ZTE product.The vulnerability is caused because the management p... |
| CVE-2021-28647 | HIGH | 7.8 | 0.5% | Apr 13, 2021 | Trend Micro Password Manager version 5 (Consumer) is vulnerable to a DLL Hijacking vulnerability which could allow an at... |
| CVE-2021-28645 | HIGH | 7.8 | 0.5% | Apr 13, 2021 | An incorrect permission assignment vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 co... |
| CVE-2021-25253 | HIGH | 7.8 | 1.9% | Apr 13, 2021 | An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP... |
| CVE-2021-25250 | HIGH | 7.8 | 0.5% | Apr 13, 2021 | An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP... |
| CVE-2021-29262 | HIGH | 7.5 | 7.8% | Apr 13, 2021 | When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigest... |
| CVE-2021-29054 | HIGH | 8.8 | 0.8% | Apr 13, 2021 | Certain Papoo products are affected by: Cross Site Request Forgery (CSRF) in the admin interface. This affects Papoo CMS... |
| CVE-2021-22497 | HIGH | 7.2 | 0.8% | Apr 12, 2021 | Advanced Authentication versions prior to 6.3 SP4 have a potential broken authentication due to improper session managem... |
| CVE-2021-21545 | HIGH | 7.8 | 0.3% | Apr 12, 2021 | Dell Peripheral Manager 1.3.1 or greater contains remediation for a local privilege escalation vulnerability that could ... |
| CVE-2021-3128 | HIGH | 7.5 | 2.2% | Apr 12, 2021 | In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386... |
| CVE-2021-3125 | HIGH | 7.5 | 1.5% | Apr 12, 2021 | In TP-Link TL-XDR3230 < 1.0.12, TL-XDR1850 < 1.0.9, TL-XDR1860 < 1.0.14, TL-XDR3250 < 1.0.2, TL-XDR6060 Turbo < 1.1.8, T... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now