2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-0684HIGH7.8In TouchInputMapper::sync of TouchInputMapper.cpp, there is a possible out of bounds write due to a use after free. This...
CVE-2021-0683HIGH7.8In runTraceIpcStop of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused d...
CVE-2021-0682MEDIUM5.5In sendAccessibilityEvent of NotificationManagerService.java, there is a possible disclosure of notification data due to...
CVE-2021-0681MEDIUM5.5In system properties, there is a possible information disclosure due to a missing permission check. This could lead to l...
CVE-2021-0680MEDIUM5.5In system properties, there is a possible information disclosure due to a missing permission check. This could lead to l...
CVE-2021-0644MEDIUM5.5In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identi...
CVE-2021-0636HIGH7.8When extracting the incorrectly formatted avi file, the memory is damaged, the playback interface shows that the video c...
CVE-2021-0635HIGH7.8When extracting the incorrectly formatted flv file, the memory is damaged, the playback interface shows that the video c...
CVE-2021-0598HIGH7.3In onCreate of ConfirmConnectActivity.java, there is a possible pairing of untrusted Bluetooth devices due to a tapjacki...
CVE-2021-0595HIGH7.8In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profi...
CVE-2021-28702HIGH7.6PCI devices with RMRRs not deassigned correctly Certain PCI devices in a system might be assigned Reserved Memory Region...
CVE-2021-3848MEDIUM5.5An arbitrary file creation by privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service, Worry-F...
CVE-2021-36178MEDIUM6.5A insufficiently protected credentials in Fortinet FortiSDNConnector version 1.1.7 and below allows attacker to disclose...
CVE-2021-36175MEDIUM5.4An improper neutralization of input vulnerability [CWE-79] in FortiWebManager versions 6.2.3 and below, 6.0.2 and below ...
CVE-2021-36170LOW3.2An information disclosure vulnerability [CWE-200] in FortiAnalyzerVM and FortiManagerVM versions 7.0.0 and 6.4.6 and bel...
CVE-2021-33602MEDIUM5.3A vulnerability affecting the F-Secure Antivirus engine was discovered when the engine tries to unpack a zip archive (LZ...
CVE-2021-24021MEDIUM5.4An improper neutralization of input vulnerability [CWE-79] in FortiAnalyzer versions 6.4.3 and below, 6.2.7 and below an...
CVE-2021-24019CRITICAL9.8An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below ...
CVE-2021-41122MEDIUM4.3Vyper is a Pythonic Smart Contract Language for the EVM. In affected versions external functions did not properly valida...
CVE-2021-33849MEDIUM5.4A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser i...
CVE-2021-31988HIGH8.8A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the ...
CVE-2021-31987HIGH7.5A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass b...
CVE-2021-31986MEDIUM6.8User controlled parameters related to SMTP notifications are not correctly validated. This can lead to a buffer overflow...
CVE-2021-41124HIGH7.5Scrapy-splash is a library which provides Scrapy and JavaScript integration. In affected versions users who use [`HttpAu...
CVE-2021-41120HIGH7.5sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL to the payment...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now