2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39797 | HIGH | 7.8 | 0.1% | Apr 12, 2022 | In several functions of of LauncherApps.java, there is a possible escalation of privilege due to a logic error in the co... |
| CVE-2021-39796 | HIGH | 7.3 | 0.2% | Apr 12, 2022 | In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmf... |
| CVE-2021-39794 | HIGH | 7.8 | 0.3% | Apr 12, 2022 | In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless deb... |
| CVE-2021-0707 | HIGH | 7.8 | 0.2% | Apr 12, 2022 | In dma_buf_release of dma-buf.c, there is a possible memory corruption due to a use after free. This could lead to local... |
| CVE-2021-0694 | HIGH | 7.8 | 0.1% | Apr 12, 2022 | In setServiceForegroundInnerLocked of ActiveServices.java, there is a possible way for a background application to regai... |
| CVE-2021-42255 | HIGH | 7.8 | 0.3% | Apr 12, 2022 | AppGuard Enterprise before 6.7.100.1 creates a Temporary File in a Directory with Insecure Permissions. Local users can ... |
| CVE-2021-32040 | HIGH | 7.5 | 1.9% | Apr 12, 2022 | It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and caus... |
| CVE-2021-42029 | HIGH | 7.8 | 0.2% | Apr 12, 2022 | A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (... |
| CVE-2021-40368 | HIGH | 7.5 | 0.9% | Apr 12, 2022 | A vulnerability has been identified in SIMATIC S7-400 CPU 412-1 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 DP V7 (... |
| CVE-2021-4047 | HIGH | 7.5 | 0.9% | Apr 11, 2022 | The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was... |
| CVE-2021-46740 | HIGH | 7.5 | 0.7% | Apr 11, 2022 | The device authentication service module has a defect vulnerability introduced in the design process.Successful exploita... |
| CVE-2021-40065 | HIGH | 7.5 | 0.7% | Apr 11, 2022 | The communication module has a service logic error vulnerability.Successful exploitation of this vulnerability may affec... |
| CVE-2021-43442 | HIGH | 8.1 | 0.9% | Apr 11, 2022 | A Logic Flaw vulnerability exists in i3 International Inc Annexxus Camera V5.2.0 build 150317 (Ax46), V5.0.9 build 15110... |
| CVE-2021-38930 | HIGH | 7.5 | 1.4% | Apr 11, 2022 | IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remo... |
| CVE-2021-38929 | HIGH | 7.5 | 1.4% | Apr 11, 2022 | IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remo... |
| CVE-2021-37292 | HIGH | 7.2 | 6.7% | Apr 11, 2022 | An Access Control vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 due to an undocu... |
| CVE-2021-40219 | HIGH | 8.8 | 3.3% | Apr 11, 2022 | Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit ... |
| CVE-2021-32162 | HIGH | 8.8 | 2.6% | Apr 11, 2022 | A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 through the File Manager feature. |
| CVE-2021-32159 | HIGH | 8.8 | 2.3% | Apr 11, 2022 | A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature. |
| CVE-2021-32156 | HIGH | 8.8 | 2.3% | Apr 11, 2022 | A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature. |
| CVE-2021-43498 | HIGH | 7.5 | 1.6% | Apr 8, 2022 | An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden,... |
| CVE-2021-43515 | HIGH | 7.8 | 1.0% | Apr 8, 2022 | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the... |
| CVE-2021-43521 | HIGH | 7.5 | 1.3% | Apr 8, 2022 | A Buffer Overflow vulnerability exists in zlog 1.2.15 via zlog_conf_build_with_file in src/zlog/src/conf.c. |
| CVE-2021-43483 | HIGH | 8 | 0.5% | Apr 8, 2022 | An Access Control vulnerability exists in CLARO KAON CG3000 1.00.67 in the router configuration, which could allow a mal... |
| CVE-2021-40656 | HIGH | 8.8 | 1.0% | Apr 8, 2022 | libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now