2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39782 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In Telephony, there is a possible unauthorized modification of the PLMN SIM file due to a missing permission check. This... |
| CVE-2021-39781 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In SmsController, there is a possible information disclosure due to a permissions bypass. This could lead to local escal... |
| CVE-2021-39780 | HIGH | 7.8 | 0.3% | Mar 30, 2022 | In Traceur, there is a possible bypass of developer settings requirements for capturing system traces due to a missing p... |
| CVE-2021-39776 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In NFC, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege ... |
| CVE-2021-39772 | HIGH | 8.8 | 0.2% | Mar 30, 2022 | In Bluetooth, there is a possible way to access the a2dp audio control switch due to a missing permission check. This co... |
| CVE-2021-39771 | HIGH | 7.8 | 0.3% | Mar 30, 2022 | In Settings, there is a possible way to misrepresent which app wants to add a wifi network due to improper input validat... |
| CVE-2021-39768 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In Settings, there is a possible way to add an auto-connect WiFi network without the user's consent due to a missing per... |
| CVE-2021-39767 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In miniadb, there is a possible way to get read/write access to recovery system properties due to an insecure default va... |
| CVE-2021-39764 | HIGH | 7.8 | 0.3% | Mar 30, 2022 | In Settings, there is a possible way to display an incorrect app name due to improper input validation. This could lead ... |
| CVE-2021-39763 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In Settings, there is a possible way to make the user enable WiFi due to improper input validation. This could lead to l... |
| CVE-2021-39762 | HIGH | 7.5 | 0.7% | Mar 30, 2022 | In tremolo, there is a possible out of bounds read due to an integer overflow. This could lead to remote information dis... |
| CVE-2021-39759 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In libstagefright, there is a possible out of bounds write due to an integer overflow. This could lead to local escalati... |
| CVE-2021-39758 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In WindowManager, there is a possible way to start a foreground activity from the background due to a missing permission... |
| CVE-2021-39752 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In Bubbles, there is a possible way to interfere with Bubbles due to a permissions bypass. This could lead to local esca... |
| CVE-2021-39750 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In PackageManager, there is a possible way to change the splash screen theme of other apps due to a missing permission c... |
| CVE-2021-39749 | HIGH | 7.8 | 0.2% | Mar 30, 2022 | In WindowManager, there is a possible way to start non-exported and protected activities due to a missing permission che... |
| CVE-2021-39746 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In PermissionController, there is a possible way to delete some local files due to an unsafe PendingIntent. This could l... |
| CVE-2021-39743 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In PackageManager, there is a possible way to update the last usage time of another package due to a missing permission ... |
| CVE-2021-39741 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In Keymaster, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation... |
| CVE-2021-23851 | HIGH | 7.2 | 1.5% | Mar 30, 2022 | A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer... |
| CVE-2021-23850 | HIGH | 7.2 | 1.5% | Mar 30, 2022 | A specially crafted TCP/IP packet may cause a camera recovery image telnet interface to crash. It may also cause a buffe... |
| CVE-2021-1033 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In createGeneralSlice of ConnectedDevicesSliceProvider.java.java, there is a possible permission bypass due to an unsafe... |
| CVE-2021-1000 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In createBluetoothDeviceSlice of ConnectedDevicesSliceProvider.java, there is a possible permission bypass due to an uns... |
| CVE-2021-44082 | HIGH | 8.3 | 2.8% | Mar 29, 2022 | textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthentica... |
| CVE-2021-43109 | HIGH | 7.5 | 1.2% | Mar 29, 2022 | An SQL Injection vulnerability exits in PuneethReddyHC online-shopping-system as of 11/01/2021 via the p parameter in pr... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now