2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-0319HIGH7.3In checkCallerIsSystemOr of CompanionDeviceManagerService.java, there is a possible way to get a nearby Bluetooth device...
CVE-2021-0318HIGH7.8In appendEventsToCacheLocked of SensorEventConnection.cpp, there is a possible out of bounds write due to a use-after-fr...
CVE-2021-0317HIGH7.8In createOrUpdate of Permission.java and related code, there is possible permission escalation due to a logic error. Thi...
CVE-2021-0315HIGH7.3In onCreate of GrantCredentialsPermissionActivity.java, there is a possible way to convince the user to grant an app acc...
CVE-2021-0313HIGH7.5In isWordBreakAfter of LayoutUtils.cpp, there is a possible way to slow or crash a TextView due to improper input valida...
CVE-2021-0310HIGH7.8In LazyServiceRegistrar of LazyServiceRegistrar.cpp, there is a possible memory corruption due to a use after free. This...
CVE-2021-0307HIGH7.8In updatePermissionSourcePackage of PermissionManagerService.java, there is a possible automatic runtime permission gran...
CVE-2021-0306HIGH7.8In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Andro...
CVE-2021-0303HIGH7In dispatchGraphTerminationMessage() of packages/services/Car/computepipe/runner/graph/StreamSetObserver.cpp, there is a...
CVE-2021-21241HIGH7.4The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is a in...
CVE-2021-3121HIGH8.6An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka...
CVE-2021-3116HIGH7.5before_upstream_connection in AuthPlugin in http/proxy/auth.py in proxy.py before 2.3.1 accepts incorrect Proxy-Authoriz...
CVE-2021-21116HIGH8.8Heap buffer overflow in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit h...
CVE-2021-21114HIGH8.8Use after free in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap co...
CVE-2021-21113HIGH8.8Heap buffer overflow in Skia in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit he...
CVE-2021-21112HIGH8.8Use after free in Blink in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap co...
CVE-2021-1065HIGH7.1NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which input data is not validated, which may lead to...
CVE-2021-1064HIGH7.1NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which it obtains a value from an untrusted source, c...
CVE-2021-1063HIGH7.8NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input offset is not validated, which may le...
CVE-2021-1062HIGH7.1NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input data length is not validated, which m...
CVE-2021-1060HIGH7.1NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input index i...
CVE-2021-1059HIGH7.8NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input index is not validated, which may lea...
CVE-2021-1058HIGH7.1NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input data si...
CVE-2021-1057HIGH7.8NVIDIA Virtual GPU Manager NVIDIA vGPU manager contains a vulnerability in the vGPU plugin in which it allows guests to ...
CVE-2021-3025HIGH8.8Invision Community IPS Community Suite before 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir param...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now