2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-21482HIGH8.3SAP NetWeaver Master Data Management, versions - 710, 710.750, allows a malicious unauthorized user with access to the M...
CVE-2021-0446HIGH7.3In ImportVCardActivity, there is a possible way to bypass user consent due to a tapjacking/overlay attack. This could le...
CVE-2021-0445HIGH7.8In start of WelcomeActivity.java, there is a possible residual profile due to a confused deputy. This could lead to loca...
CVE-2021-0442HIGH7.8In updateInfo of android_hardware_input_InputApplicationHandle.cpp, there is a possible control of code flow due to a us...
CVE-2021-0439HIGH7.8In setPowerModeWithHandle of com_android_server_power_PowerManagerService.cpp, there is a possible out of bounds write d...
CVE-2021-0438HIGH7.8In several functions of InputDispatcher.cpp, WindowManagerService.java, and related files, there is a possible tapjackin...
CVE-2021-0437HIGH7.8In setPlayPolicy of DrmPlugin.cpp, there is a possible double free. This could lead to local escalation of privilege in ...
CVE-2021-0435HIGH7.5In avrc_proc_vendor_command of avrc_api.cc, there is a possible leak of heap data due to uninitialized data. This could ...
CVE-2021-0433HIGH8In onCreate of DeviceChooserActivity.java, there is a possible way to bypass user consent when pairing a Bluetooth devic...
CVE-2021-0432HIGH7In ClearPullerCacheIfNecessary and ForceClearPullerCache of StatsPullerManager.cpp, there is a possible use-after-free d...
CVE-2021-0431HIGH7.5In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds read due to a missing bounds check. This could lead ...
CVE-2021-0429HIGH7.8In pollOnce of ALooper.cpp, there is possible memory corruption due to a use after free. This could lead to local escala...
CVE-2021-0427HIGH7.8In parseExclusiveStateAnnotation of LogEvent.cpp, there is a possible out of bounds write due to a heap buffer overflow....
CVE-2021-0426HIGH7.8In parsePrimaryFieldFirstUidAnnotation of LogEvent.cpp, there is a possible out of bounds write due to a heap buffer ove...
CVE-2021-21731HIGH8.1A CSRF vulnerability exists in the management page of a ZTE product.The vulnerability is caused because the management p...
CVE-2021-28647HIGH7.8Trend Micro Password Manager version 5 (Consumer) is vulnerable to a DLL Hijacking vulnerability which could allow an at...
CVE-2021-28645HIGH7.8An incorrect permission assignment vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 co...
CVE-2021-25253HIGH7.8An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP...
CVE-2021-25250HIGH7.8An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP...
CVE-2021-29262HIGH7.5When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigest...
CVE-2021-29054HIGH8.8Certain Papoo products are affected by: Cross Site Request Forgery (CSRF) in the admin interface. This affects Papoo CMS...
CVE-2021-22497HIGH7.2Advanced Authentication versions prior to 6.3 SP4 have a potential broken authentication due to improper session managem...
CVE-2021-21545HIGH7.8Dell Peripheral Manager 1.3.1 or greater contains remediation for a local privilege escalation vulnerability that could ...
CVE-2021-3128HIGH7.5In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware < 3.0.0.4.386.42095 or < 9.0.0.4.386...
CVE-2021-3125HIGH7.5In TP-Link TL-XDR3230 < 1.0.12, TL-XDR1850 < 1.0.9, TL-XDR1860 < 1.0.14, TL-XDR3250 < 1.0.2, TL-XDR6060 Turbo < 1.1.8, T...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now