2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25468 | MEDIUM | 4.4 | 0.1% | Oct 6, 2021 | A possible guessing and confirming a byte memory vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allo... |
| CVE-2021-25467 | MEDIUM | 6.7 | 0.1% | Oct 6, 2021 | Assuming system privilege is gained, possible buffer overflow vulnerabilities in the Vision DSP kernel driver prior to S... |
| CVE-2021-38925 | HIGH | 7.5 | 0.7% | Oct 6, 2021 | IBM Sterling B2B Integrator Standard Edition 5.2.0. 0 through 6.1.1.0 uses weaker than expected cryptographic algorithms... |
| CVE-2021-29903 | CRITICAL | 9.8 | 1.1% | Oct 6, 2021 | IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker c... |
| CVE-2021-29855 | MEDIUM | 5.4 | 0.5% | Oct 6, 2021 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnera... |
| CVE-2021-29837 | HIGH | 8.8 | 0.4% | Oct 6, 2021 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which c... |
| CVE-2021-29836 | MEDIUM | 5.4 | 0.5% | Oct 6, 2021 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0. through 6.1.1.0 is vulnerable to cross-site scripting. This vulner... |
| CVE-2021-29798 | CRITICAL | 9.8 | 1.1% | Oct 6, 2021 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker c... |
| CVE-2021-29764 | MEDIUM | 5.4 | 0.5% | Oct 6, 2021 | IBM Sterling B2B Integrator 5.2.0.0 through 6.1.1.0 is vulnerable to stored cross-site scripting. This vulnerability all... |
| CVE-2021-29761 | MEDIUM | 4.3 | 0.7% | Oct 6, 2021 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensiti... |
| CVE-2021-29760 | MEDIUM | 4.3 | 0.6% | Oct 6, 2021 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to download unaut... |
| CVE-2021-29758 | MEDIUM | 4.3 | 0.6% | Oct 6, 2021 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to perform action... |
| CVE-2021-39351 | MEDIUM | 6.5 | 1.1% | Oct 6, 2021 | The WP Bannerize WordPress plugin is vulnerable to authenticated SQL injection via the id parameter found in the ~/Class... |
| CVE-2021-39350 | MEDIUM | 6.1 | 2.1% | Oct 6, 2021 | The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parame... |
| CVE-2021-20264 | HIGH | 7.8 | 0.3% | Oct 6, 2021 | An insecure modification flaw in the /etc/passwd file was found in the openjdk-1.8 and openjdk-11 containers. This flaw ... |
| CVE-2021-0695 | MEDIUM | 5.5 | 0.1% | Oct 6, 2021 | In get_sock_stat of xt_qtaguid.c, there is a possible out of bounds read due to a use after free. This could lead to loc... |
| CVE-2021-0693 | MEDIUM | 5.5 | 0.1% | Oct 6, 2021 | In openFile of HeapDumpProvider.java, there is a possible way to retrieve generated heap dumps from debuggable apps due ... |
| CVE-2021-0692 | HIGH | 7.8 | 0.1% | Oct 6, 2021 | In sendBroadcastToInstaller of FirstScreenBroadcast.java, there is a possible activity launch due to an unsafe PendingIn... |
| CVE-2021-0691 | MEDIUM | 6.7 | 0.1% | Oct 6, 2021 | In the SELinux policy configured in system_app.te, there is a possible way for system_app to gain code execution in othe... |
| CVE-2021-0690 | MEDIUM | 6.5 | 0.8% | Oct 6, 2021 | In ih264d_mark_err_slice_skip of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer ove... |
| CVE-2021-0689 | MEDIUM | 5.5 | 0.1% | Oct 6, 2021 | In RGB_to_BGR1_portable of SkSwizzler_opts.h, there is a possible out of bounds read due to a missing bounds check. This... |
| CVE-2021-0688 | HIGH | 7 | 0.2% | Oct 6, 2021 | In lockNow of PhoneWindowManager.java, there is a possible lock screen bypass due to a race condition. This could lead t... |
| CVE-2021-0687 | MEDIUM | 5 | 0.1% | Oct 6, 2021 | In ellipsize of Layout.java, there is a possible ANR due to improper input validation. This could lead to local denial o... |
| CVE-2021-0686 | MEDIUM | 5.5 | 0.1% | Oct 6, 2021 | In getDefaultSmsPackage of RoleManagerService.java, there is a possible way to get information about the default sms app... |
| CVE-2021-0685 | HIGH | 7.8 | 0.2% | Oct 6, 2021 | In ParsedIntentInfo of ParsedIntentInfo.java, there is a possible parcel serialization/deserialization mismatch due to u... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now