2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27918 | HIGH | 7.5 | 2.5% | Mar 11, 2021 | encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infinite loop if a custom TokenReader (for xml.NewToken... |
| CVE-2021-21371 | HIGH | 8.6 | 0.5% | Mar 10, 2021 | Tenable for Jira Cloud is an open source project designed to pull Tenable.io vulnerability data, then generate Jira Task... |
| CVE-2021-21265 | HIGH | 7.5 | 1.5% | Mar 10, 2021 | October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October before version 1... |
| CVE-2021-21772 | HIGH | 8.1 | 4.3% | Mar 10, 2021 | A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf... |
| CVE-2021-0465 | HIGH | 7.8 | 0.1% | Mar 10, 2021 | In GenerateFaceMask of face.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lea... |
| CVE-2021-0464 | HIGH | 7.8 | 0.1% | Mar 10, 2021 | In sound_trigger_event_alloc of platform.h, there is a possible out of bounds write due to a heap buffer overflow. This ... |
| CVE-2021-0389 | HIGH | 7.8 | 0.1% | Mar 10, 2021 | In setNightModeActivated of UiModeManagerService.java, there is a missing permission check. This could lead to local esc... |
| CVE-2021-0388 | HIGH | 7.8 | 0.1% | Mar 10, 2021 | In onReceive of ImsPhoneCallTracker.java, there is a possible misattribution of data usage due to an incorrect broadcast... |
| CVE-2021-0386 | HIGH | 7.8 | 0.3% | Mar 10, 2021 | In onCreate of UsbConfirmActivity, there is a possible tapjacking vector due to an insecure default value. This could le... |
| CVE-2021-0385 | HIGH | 7.8 | 0.1% | Mar 10, 2021 | In createConnectToAvailableNetworkNotification of ConnectToNetworkNotificationBuilder.java, there is a possible connecti... |
| CVE-2021-0383 | HIGH | 7.8 | 0.1% | Mar 10, 2021 | In done of CaptivePortalLoginActivity.java, there is a confused deputy. This could lead to local escalation of privilege... |
| CVE-2021-0380 | HIGH | 7.8 | 0.1% | Mar 10, 2021 | In onReceive of DcTracker.java, there is a possible way to trigger a provisioning URL and modify other telephony setting... |
| CVE-2021-0399 | HIGH | 7.8 | 0.4% | Mar 10, 2021 | In qtaguid_untag of xt_qtaguid.c, there is a possible memory corruption due to a use after free. This could lead to loca... |
| CVE-2021-0398 | HIGH | 7.8 | 0.1% | Mar 10, 2021 | In bindServiceLocked of ActiveServices.java, there is a possible foreground service launch due to a confused deputy. Thi... |
| CVE-2021-0395 | HIGH | 7.8 | 0.1% | Mar 10, 2021 | In StopServicesAndLogViolations of reboot.cpp, there is possible memory corruption due to a use after free. This could l... |
| CVE-2021-0393 | HIGH | 7.8 | 1.0% | Mar 10, 2021 | In Scanner::LiteralBuffer::NewCapacity of scanner.cc, there is a possible out of bounds write due to an integer overflow... |
| CVE-2021-0392 | HIGH | 7.8 | 0.2% | Mar 10, 2021 | In main of main.cpp, there is a possible memory corruption due to a double free. This could lead to local escalation of ... |
| CVE-2021-0391 | HIGH | 7.8 | 0.7% | Mar 10, 2021 | In onCreate() of ChooseTypeAndAccountActivity.java, there is a possible way to learn the existence of an account, withou... |
| CVE-2021-0390 | HIGH | 7.8 | 0.2% | Mar 10, 2021 | In various methods of WifiNetworkSuggestionsManager.java, there is a possible modification of suggested networks due to ... |
| CVE-2021-0376 | HIGH | 7.8 | 0.1% | Mar 10, 2021 | In checkUriPermission and related functions of MediaProvider.java, there is a possible way to access external files due ... |
| CVE-2021-0372 | HIGH | 7.8 | 0.1% | Mar 10, 2021 | In getMediaOutputSliceAction of RemoteMediaSlice.java, there is a possible permission bypass due to an unsafe PendingInt... |
| CVE-2021-0369 | HIGH | 7.8 | 0.1% | Mar 10, 2021 | In CrossProfileAppsServiceImpl.java, there is the possibility of an application's INTERACT_ACROSS_PROFILES grant state n... |
| CVE-2021-20671 | HIGH | 7.2 | 1.8% | Mar 10, 2021 | Invalid file validation on the upload feature in GROWI versions v4.2.2 allows a remote attacker with administrative priv... |
| CVE-2021-20670 | HIGH | 7.5 | 1.5% | Mar 10, 2021 | Improper access control vulnerability in GROWI versions v4.2.2 and earlier allows a remote unauthenticated attacker to r... |
| CVE-2021-3310 | HIGH | 7.8 | 1.0% | Mar 10, 2021 | Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now