2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-0684 | HIGH | 7.8 | 0.1% | Oct 6, 2021 | In TouchInputMapper::sync of TouchInputMapper.cpp, there is a possible out of bounds write due to a use after free. This... |
| CVE-2021-0683 | HIGH | 7.8 | 0.2% | Oct 6, 2021 | In runTraceIpcStop of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused d... |
| CVE-2021-0682 | MEDIUM | 5.5 | 0.1% | Oct 6, 2021 | In sendAccessibilityEvent of NotificationManagerService.java, there is a possible disclosure of notification data due to... |
| CVE-2021-0681 | MEDIUM | 5.5 | 0.1% | Oct 6, 2021 | In system properties, there is a possible information disclosure due to a missing permission check. This could lead to l... |
| CVE-2021-0680 | MEDIUM | 5.5 | 0.1% | Oct 6, 2021 | In system properties, there is a possible information disclosure due to a missing permission check. This could lead to l... |
| CVE-2021-0644 | MEDIUM | 5.5 | 0.1% | Oct 6, 2021 | In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identi... |
| CVE-2021-0636 | HIGH | 7.8 | 0.3% | Oct 6, 2021 | When extracting the incorrectly formatted avi file, the memory is damaged, the playback interface shows that the video c... |
| CVE-2021-0635 | HIGH | 7.8 | 0.3% | Oct 6, 2021 | When extracting the incorrectly formatted flv file, the memory is damaged, the playback interface shows that the video c... |
| CVE-2021-0598 | HIGH | 7.3 | 0.1% | Oct 6, 2021 | In onCreate of ConfirmConnectActivity.java, there is a possible pairing of untrusted Bluetooth devices due to a tapjacki... |
| CVE-2021-0595 | HIGH | 7.8 | 0.2% | Oct 6, 2021 | In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profi... |
| CVE-2021-28702 | HIGH | 7.6 | 0.4% | Oct 6, 2021 | PCI devices with RMRRs not deassigned correctly Certain PCI devices in a system might be assigned Reserved Memory Region... |
| CVE-2021-3848 | MEDIUM | 5.5 | 0.2% | Oct 6, 2021 | An arbitrary file creation by privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service, Worry-F... |
| CVE-2021-36178 | MEDIUM | 6.5 | 0.6% | Oct 6, 2021 | A insufficiently protected credentials in Fortinet FortiSDNConnector version 1.1.7 and below allows attacker to disclose... |
| CVE-2021-36175 | MEDIUM | 5.4 | 0.6% | Oct 6, 2021 | An improper neutralization of input vulnerability [CWE-79] in FortiWebManager versions 6.2.3 and below, 6.0.2 and below ... |
| CVE-2021-36170 | LOW | 3.2 | 0.2% | Oct 6, 2021 | An information disclosure vulnerability [CWE-200] in FortiAnalyzerVM and FortiManagerVM versions 7.0.0 and 6.4.6 and bel... |
| CVE-2021-33602 | MEDIUM | 5.3 | 0.6% | Oct 6, 2021 | A vulnerability affecting the F-Secure Antivirus engine was discovered when the engine tries to unpack a zip archive (LZ... |
| CVE-2021-24021 | MEDIUM | 5.4 | 0.6% | Oct 6, 2021 | An improper neutralization of input vulnerability [CWE-79] in FortiAnalyzer versions 6.4.3 and below, 6.2.7 and below an... |
| CVE-2021-24019 | CRITICAL | 9.8 | 3.8% | Oct 6, 2021 | An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below ... |
| CVE-2021-41122 | MEDIUM | 4.3 | 0.8% | Oct 5, 2021 | Vyper is a Pythonic Smart Contract Language for the EVM. In affected versions external functions did not properly valida... |
| CVE-2021-33849 | MEDIUM | 5.4 | 1.0% | Oct 5, 2021 | A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser i... |
| CVE-2021-31988 | HIGH | 8.8 | 0.9% | Oct 5, 2021 | A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the ... |
| CVE-2021-31987 | HIGH | 7.5 | 0.9% | Oct 5, 2021 | A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass b... |
| CVE-2021-31986 | MEDIUM | 6.8 | 0.8% | Oct 5, 2021 | User controlled parameters related to SMTP notifications are not correctly validated. This can lead to a buffer overflow... |
| CVE-2021-41124 | HIGH | 7.5 | 1.1% | Oct 5, 2021 | Scrapy-splash is a library which provides Scrapy and JavaScript integration. In affected versions users who use [`HttpAu... |
| CVE-2021-41120 | HIGH | 7.5 | 1.5% | Oct 5, 2021 | sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL to the payment... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now