2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-27918HIGH7.5encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infinite loop if a custom TokenReader (for xml.NewToken...
CVE-2021-21371HIGH8.6Tenable for Jira Cloud is an open source project designed to pull Tenable.io vulnerability data, then generate Jira Task...
CVE-2021-21265HIGH7.5October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October before version 1...
CVE-2021-21772HIGH8.1A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf...
CVE-2021-0465HIGH7.8In GenerateFaceMask of face.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lea...
CVE-2021-0464HIGH7.8In sound_trigger_event_alloc of platform.h, there is a possible out of bounds write due to a heap buffer overflow. This ...
CVE-2021-0389HIGH7.8In setNightModeActivated of UiModeManagerService.java, there is a missing permission check. This could lead to local esc...
CVE-2021-0388HIGH7.8In onReceive of ImsPhoneCallTracker.java, there is a possible misattribution of data usage due to an incorrect broadcast...
CVE-2021-0386HIGH7.8In onCreate of UsbConfirmActivity, there is a possible tapjacking vector due to an insecure default value. This could le...
CVE-2021-0385HIGH7.8In createConnectToAvailableNetworkNotification of ConnectToNetworkNotificationBuilder.java, there is a possible connecti...
CVE-2021-0383HIGH7.8In done of CaptivePortalLoginActivity.java, there is a confused deputy. This could lead to local escalation of privilege...
CVE-2021-0380HIGH7.8In onReceive of DcTracker.java, there is a possible way to trigger a provisioning URL and modify other telephony setting...
CVE-2021-0399HIGH7.8In qtaguid_untag of xt_qtaguid.c, there is a possible memory corruption due to a use after free. This could lead to loca...
CVE-2021-0398HIGH7.8In bindServiceLocked of ActiveServices.java, there is a possible foreground service launch due to a confused deputy. Thi...
CVE-2021-0395HIGH7.8In StopServicesAndLogViolations of reboot.cpp, there is possible memory corruption due to a use after free. This could l...
CVE-2021-0393HIGH7.8In Scanner::LiteralBuffer::NewCapacity of scanner.cc, there is a possible out of bounds write due to an integer overflow...
CVE-2021-0392HIGH7.8In main of main.cpp, there is a possible memory corruption due to a double free. This could lead to local escalation of ...
CVE-2021-0391HIGH7.8In onCreate() of ChooseTypeAndAccountActivity.java, there is a possible way to learn the existence of an account, withou...
CVE-2021-0390HIGH7.8In various methods of WifiNetworkSuggestionsManager.java, there is a possible modification of suggested networks due to ...
CVE-2021-0376HIGH7.8In checkUriPermission and related functions of MediaProvider.java, there is a possible way to access external files due ...
CVE-2021-0372HIGH7.8In getMediaOutputSliceAction of RemoteMediaSlice.java, there is a possible permission bypass due to an unsafe PendingInt...
CVE-2021-0369HIGH7.8In CrossProfileAppsServiceImpl.java, there is the possibility of an application's INTERACT_ACROSS_PROFILES grant state n...
CVE-2021-20671HIGH7.2Invalid file validation on the upload feature in GROWI versions v4.2.2 allows a remote attacker with administrative priv...
CVE-2021-20670HIGH7.5Improper access control vulnerability in GROWI versions v4.2.2 and earlier allows a remote unauthenticated attacker to r...
CVE-2021-3310HIGH7.8Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now