2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42539 | HIGH | 8.8 | 0.7% | Oct 22, 2021 | The affected product is vulnerable to a missing permission validation on system backup restore, which could lead to acco... |
| CVE-2021-42538 | HIGH | 8.8 | 0.9% | Oct 22, 2021 | The affected product is vulnerable to a parameter injection via passphrase, which enables the attacker to supply uncontr... |
| CVE-2021-42536 | MEDIUM | 6.5 | 0.9% | Oct 22, 2021 | The affected product is vulnerable to a disclosure of peer username and password by allowing all users access to read gl... |
| CVE-2021-42534 | MEDIUM | 6.1 | 0.6% | Oct 22, 2021 | The affected product’s web application does not properly neutralize the input during webpage generation, which could all... |
| CVE-2021-42169 | CRITICAL | 9.8 | 2.7% | Oct 22, 2021 | The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable f... |
| CVE-2021-38485 | HIGH | 8.8 | 0.9% | Oct 22, 2021 | The affected product is vulnerable to improper input validation in the restore file. This enables an attacker to provide... |
| CVE-2021-30359 | HIGH | 7.8 | 3.9% | Oct 22, 2021 | The Harmony Browse and the SandBlast Agent for Browsers installers must have admin privileges to execute some steps duri... |
| CVE-2021-0870 | HIGH | 8.1 | 7.0% | Oct 22, 2021 | In RW_SetActivatedTagType of rw_main.cc, there is possible memory corruption due to a race condition. This could lead to... |
| CVE-2021-0708 | HIGH | 7.8 | 0.1% | Oct 22, 2021 | In runDumpHeap of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused deput... |
| CVE-2021-0706 | MEDIUM | 5.5 | 0.1% | Oct 22, 2021 | In startListening of PluginManagerImpl.java, there is a possible way to disable arbitrary app components due to a missin... |
| CVE-2021-0705 | HIGH | 7.8 | 0.3% | Oct 22, 2021 | In sanitizeSbn of NotificationManagerService.java, there is a possible way to keep service running in foreground and kee... |
| CVE-2021-0703 | MEDIUM | 6.8 | 0.1% | Oct 22, 2021 | In SecondStageMain of init.cpp, there is a possible use after free due to incorrect shared_ptr usage. This could lead to... |
| CVE-2021-0702 | MEDIUM | 5.5 | 0.1% | Oct 22, 2021 | In RevertActiveSessions of apexd.cpp, there is a possible way to share the wrong file due to an unintentional MediaStore... |
| CVE-2021-0652 | HIGH | 7.8 | 0.2% | Oct 22, 2021 | In VectorDrawable::VectorDrawable of VectorDrawable.java, there is a possible way to introduce a memory corruption due t... |
| CVE-2021-0651 | MEDIUM | 5.5 | 0.1% | Oct 22, 2021 | In loadLabel of PackageItemInfo.java, there is a possible way to DoS a device by having a long label in an app due to in... |
| CVE-2021-0643 | MEDIUM | 5.5 | 0.1% | Oct 22, 2021 | In getAllSubInfoList of SubscriptionController.java, there is a possible way to retrieve a long term identifier without ... |
| CVE-2021-0483 | HIGH | 7.8 | 0.1% | Oct 22, 2021 | In multiple methods of AAudioService, there is a possible use-after-free due to a race condition. This could lead to loc... |
| CVE-2021-41747 | MEDIUM | 6.1 | 0.6% | Oct 22, 2021 | Cross-Site Scripting (XSS) vulnerability exists in Csdn APP 4.10.0, which can be exploited by attackers to obtain sensit... |
| CVE-2021-41745 | CRITICAL | 9.8 | 1.3% | Oct 22, 2021 | ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions. |
| CVE-2021-41744 | CRITICAL | 9.8 | 1.5% | Oct 22, 2021 | All versions of yongyou PLM are affected by a command injection issue. UFIDA PLM (Product Life Cycle Management) is a st... |
| CVE-2021-38481 | CRITICAL | 9.8 | 0.9% | Oct 22, 2021 | The scheduler service running on a specific TCP port enables the user to start and stop jobs. There is no sanitation of ... |
| CVE-2021-38479 | HIGH | 7.5 | 0.8% | Oct 22, 2021 | Many API function codes receive raw pointers remotely from the user and trust these pointers as valid in-bound memory re... |
| CVE-2021-38477 | CRITICAL | 9.8 | 1.1% | Oct 22, 2021 | There are multiple API function codes that permit reading and writing data to or from files and directories, which could... |
| CVE-2021-38475 | HIGH | 8.8 | 0.9% | Oct 22, 2021 | The database connection to the server is performed by calling a specific API, which could allow an unprivileged user to ... |
| CVE-2021-38473 | HIGH | 8.8 | 0.9% | Oct 22, 2021 | The affected product’s code base doesn’t properly control arguments for specific functions, which could lead to a stack ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now