2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-39714HIGH7.8In ion_buffer_kmap_get of ion.c, there is a possible use-after-free due to an integer overflow. This could lead to local...
CVE-2021-39713HIGH7Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel
CVE-2021-39709HIGH7.8In sendSipAccountsRemovedNotification of SipAccountRegistry.java, there is a possible permission bypass due to an unsafe...
CVE-2021-39707HIGH7.8In onReceive of AppRestrictionsFragment.java, there is a possible way to start a phone call without permissions due to a...
CVE-2021-39706HIGH7.8In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missin...
CVE-2021-39704HIGH7.8In deleteNotificationChannelGroup of NotificationManagerService.java, there is a possible way to run foreground service ...
CVE-2021-39703HIGH7.8In updateState of UsbDeviceManager.java, there is a possible unauthorized access of files due to a confused deputy. This...
CVE-2021-39702HIGH7.8In onCreate of RequestManageCredentials.java, there is a possible way for a third party app to install certificates with...
CVE-2021-39701HIGH7.8In serviceConnection of ControlsProviderLifecycleManager.kt, there is a possible way to keep service running in foregrou...
CVE-2021-39698HIGH7.8In aio_poll_complete_work of aio.c, there is a possible memory corruption due to a use after free. This could lead to lo...
CVE-2021-39697HIGH7.8In checkFileUriDestination of DownloadProvider.java, there is a possible way to bypass external storage private director...
CVE-2021-39695HIGH7.8In createOrUpdate of BasePermission.java, there is a possible permission bypass due to a logic error in the code. This c...
CVE-2021-39694HIGH7.8In parse of RoleParser.java, there is a possible way for default apps to get permissions explicitly denied by the user d...
CVE-2021-39693HIGH7.8In onUidStateChanged of AppOpsService.java, there is a possible way to access location without a visible indicator due t...
CVE-2021-39692HIGH7.8In onCreate of SetupLayoutActivity.java, there is a possible way to setup a work profile bypassing user consent due to a...
CVE-2021-39686HIGH7In several functions of binder.c, there is a possible way to represent the wrong domain to SELinux due to a race conditi...
CVE-2021-39685HIGH7.8In various setup methods of the USB gadget subsystem, there is a possible out of bounds write due to an incorrect flag c...
CVE-2021-20299HIGH7.5A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file with no actual parts c...
CVE-2021-0957HIGH7.8In NotificationStackScrollLayout of NotificationStackScrollLayout.java, there is a possible way to bypass Factory Reset ...
CVE-2021-45851HIGH7.5A Server-Side Request Forgery (SSRF) attack in FUXA 1.1.3 can be carried out leading to the obtaining of sensitive infor...
CVE-2021-43957HIGH7.5Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct ...
CVE-2021-45848HIGH7.5Denial of service (DoS) vulnerability in Nicotine+ 3.0.3 and later allows a user with a modified Soulseek client to cras...
CVE-2021-45010HIGH8.8A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7...
CVE-2021-43305HIGH8.8Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that...
CVE-2021-43304HIGH8.8Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now