2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-42539HIGH8.8The affected product is vulnerable to a missing permission validation on system backup restore, which could lead to acco...
CVE-2021-42538HIGH8.8The affected product is vulnerable to a parameter injection via passphrase, which enables the attacker to supply uncontr...
CVE-2021-42536MEDIUM6.5The affected product is vulnerable to a disclosure of peer username and password by allowing all users access to read gl...
CVE-2021-42534MEDIUM6.1The affected product’s web application does not properly neutralize the input during webpage generation, which could all...
CVE-2021-42169CRITICAL9.8The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable f...
CVE-2021-38485HIGH8.8The affected product is vulnerable to improper input validation in the restore file. This enables an attacker to provide...
CVE-2021-30359HIGH7.8The Harmony Browse and the SandBlast Agent for Browsers installers must have admin privileges to execute some steps duri...
CVE-2021-0870HIGH8.1In RW_SetActivatedTagType of rw_main.cc, there is possible memory corruption due to a race condition. This could lead to...
CVE-2021-0708HIGH7.8In runDumpHeap of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused deput...
CVE-2021-0706MEDIUM5.5In startListening of PluginManagerImpl.java, there is a possible way to disable arbitrary app components due to a missin...
CVE-2021-0705HIGH7.8In sanitizeSbn of NotificationManagerService.java, there is a possible way to keep service running in foreground and kee...
CVE-2021-0703MEDIUM6.8In SecondStageMain of init.cpp, there is a possible use after free due to incorrect shared_ptr usage. This could lead to...
CVE-2021-0702MEDIUM5.5In RevertActiveSessions of apexd.cpp, there is a possible way to share the wrong file due to an unintentional MediaStore...
CVE-2021-0652HIGH7.8In VectorDrawable::VectorDrawable of VectorDrawable.java, there is a possible way to introduce a memory corruption due t...
CVE-2021-0651MEDIUM5.5In loadLabel of PackageItemInfo.java, there is a possible way to DoS a device by having a long label in an app due to in...
CVE-2021-0643MEDIUM5.5In getAllSubInfoList of SubscriptionController.java, there is a possible way to retrieve a long term identifier without ...
CVE-2021-0483HIGH7.8In multiple methods of AAudioService, there is a possible use-after-free due to a race condition. This could lead to loc...
CVE-2021-41747MEDIUM6.1Cross-Site Scripting (XSS) vulnerability exists in Csdn APP 4.10.0, which can be exploited by attackers to obtain sensit...
CVE-2021-41745CRITICAL9.8ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.
CVE-2021-41744CRITICAL9.8All versions of yongyou PLM are affected by a command injection issue. UFIDA PLM (Product Life Cycle Management) is a st...
CVE-2021-38481CRITICAL9.8The scheduler service running on a specific TCP port enables the user to start and stop jobs. There is no sanitation of ...
CVE-2021-38479HIGH7.5Many API function codes receive raw pointers remotely from the user and trust these pointers as valid in-bound memory re...
CVE-2021-38477CRITICAL9.8There are multiple API function codes that permit reading and writing data to or from files and directories, which could...
CVE-2021-38475HIGH8.8The database connection to the server is performed by calling a specific API, which could allow an unprivileged user to ...
CVE-2021-38473HIGH8.8The affected product’s code base doesn’t properly control arguments for specific functions, which could lead to a stack ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now