2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25468MEDIUM4.4A possible guessing and confirming a byte memory vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allo...
CVE-2021-25467MEDIUM6.7Assuming system privilege is gained, possible buffer overflow vulnerabilities in the Vision DSP kernel driver prior to S...
CVE-2021-38925HIGH7.5IBM Sterling B2B Integrator Standard Edition 5.2.0. 0 through 6.1.1.0 uses weaker than expected cryptographic algorithms...
CVE-2021-29903CRITICAL9.8IBM Sterling B2B Integrator Standard Edition 5.2.6.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker c...
CVE-2021-29855MEDIUM5.4IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnera...
CVE-2021-29837HIGH8.8IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which c...
CVE-2021-29836MEDIUM5.4IBM Sterling B2B Integrator Standard Edition 5.2.0.0. through 6.1.1.0 is vulnerable to cross-site scripting. This vulner...
CVE-2021-29798CRITICAL9.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker c...
CVE-2021-29764MEDIUM5.4IBM Sterling B2B Integrator 5.2.0.0 through 6.1.1.0 is vulnerable to stored cross-site scripting. This vulnerability all...
CVE-2021-29761MEDIUM4.3IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to obtain sensiti...
CVE-2021-29760MEDIUM4.3IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to download unaut...
CVE-2021-29758MEDIUM4.3IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authenticated user to perform action...
CVE-2021-39351MEDIUM6.5The WP Bannerize WordPress plugin is vulnerable to authenticated SQL injection via the id parameter found in the ~/Class...
CVE-2021-39350MEDIUM6.1The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parame...
CVE-2021-20264HIGH7.8An insecure modification flaw in the /etc/passwd file was found in the openjdk-1.8 and openjdk-11 containers. This flaw ...
CVE-2021-0695MEDIUM5.5In get_sock_stat of xt_qtaguid.c, there is a possible out of bounds read due to a use after free. This could lead to loc...
CVE-2021-0693MEDIUM5.5In openFile of HeapDumpProvider.java, there is a possible way to retrieve generated heap dumps from debuggable apps due ...
CVE-2021-0692HIGH7.8In sendBroadcastToInstaller of FirstScreenBroadcast.java, there is a possible activity launch due to an unsafe PendingIn...
CVE-2021-0691MEDIUM6.7In the SELinux policy configured in system_app.te, there is a possible way for system_app to gain code execution in othe...
CVE-2021-0690MEDIUM6.5In ih264d_mark_err_slice_skip of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer ove...
CVE-2021-0689MEDIUM5.5In RGB_to_BGR1_portable of SkSwizzler_opts.h, there is a possible out of bounds read due to a missing bounds check. This...
CVE-2021-0688HIGH7In lockNow of PhoneWindowManager.java, there is a possible lock screen bypass due to a race condition. This could lead t...
CVE-2021-0687MEDIUM5In ellipsize of Layout.java, there is a possible ANR due to improper input validation. This could lead to local denial o...
CVE-2021-0686MEDIUM5.5In getDefaultSmsPackage of RoleManagerService.java, there is a possible way to get information about the default sms app...
CVE-2021-0685HIGH7.8In ParsedIntentInfo of ParsedIntentInfo.java, there is a possible parcel serialization/deserialization mismatch due to u...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now