2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39714 | HIGH | 7.8 | 0.2% | Mar 16, 2022 | In ion_buffer_kmap_get of ion.c, there is a possible use-after-free due to an integer overflow. This could lead to local... |
| CVE-2021-39713 | HIGH | 7 | 0.2% | Mar 16, 2022 | Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel |
| CVE-2021-39709 | HIGH | 7.8 | 0.1% | Mar 16, 2022 | In sendSipAccountsRemovedNotification of SipAccountRegistry.java, there is a possible permission bypass due to an unsafe... |
| CVE-2021-39707 | HIGH | 7.8 | 0.1% | Mar 16, 2022 | In onReceive of AppRestrictionsFragment.java, there is a possible way to start a phone call without permissions due to a... |
| CVE-2021-39706 | HIGH | 7.8 | 0.6% | Mar 16, 2022 | In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missin... |
| CVE-2021-39704 | HIGH | 7.8 | 0.2% | Mar 16, 2022 | In deleteNotificationChannelGroup of NotificationManagerService.java, there is a possible way to run foreground service ... |
| CVE-2021-39703 | HIGH | 7.8 | 0.1% | Mar 16, 2022 | In updateState of UsbDeviceManager.java, there is a possible unauthorized access of files due to a confused deputy. This... |
| CVE-2021-39702 | HIGH | 7.8 | 0.3% | Mar 16, 2022 | In onCreate of RequestManageCredentials.java, there is a possible way for a third party app to install certificates with... |
| CVE-2021-39701 | HIGH | 7.8 | 0.4% | Mar 16, 2022 | In serviceConnection of ControlsProviderLifecycleManager.kt, there is a possible way to keep service running in foregrou... |
| CVE-2021-39698 | HIGH | 7.8 | 0.2% | Mar 16, 2022 | In aio_poll_complete_work of aio.c, there is a possible memory corruption due to a use after free. This could lead to lo... |
| CVE-2021-39697 | HIGH | 7.8 | 0.1% | Mar 16, 2022 | In checkFileUriDestination of DownloadProvider.java, there is a possible way to bypass external storage private director... |
| CVE-2021-39695 | HIGH | 7.8 | 0.1% | Mar 16, 2022 | In createOrUpdate of BasePermission.java, there is a possible permission bypass due to a logic error in the code. This c... |
| CVE-2021-39694 | HIGH | 7.8 | 0.1% | Mar 16, 2022 | In parse of RoleParser.java, there is a possible way for default apps to get permissions explicitly denied by the user d... |
| CVE-2021-39693 | HIGH | 7.8 | 0.1% | Mar 16, 2022 | In onUidStateChanged of AppOpsService.java, there is a possible way to access location without a visible indicator due t... |
| CVE-2021-39692 | HIGH | 7.8 | 0.7% | Mar 16, 2022 | In onCreate of SetupLayoutActivity.java, there is a possible way to setup a work profile bypassing user consent due to a... |
| CVE-2021-39686 | HIGH | 7 | 0.1% | Mar 16, 2022 | In several functions of binder.c, there is a possible way to represent the wrong domain to SELinux due to a race conditi... |
| CVE-2021-39685 | HIGH | 7.8 | 0.5% | Mar 16, 2022 | In various setup methods of the USB gadget subsystem, there is a possible out of bounds write due to an incorrect flag c... |
| CVE-2021-20299 | HIGH | 7.5 | 1.8% | Mar 16, 2022 | A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file with no actual parts c... |
| CVE-2021-0957 | HIGH | 7.8 | 0.1% | Mar 16, 2022 | In NotificationStackScrollLayout of NotificationStackScrollLayout.java, there is a possible way to bypass Factory Reset ... |
| CVE-2021-45851 | HIGH | 7.5 | 1.4% | Mar 16, 2022 | A Server-Side Request Forgery (SSRF) attack in FUXA 1.1.3 can be carried out leading to the obtaining of sensitive infor... |
| CVE-2021-43957 | HIGH | 7.5 | 1.2% | Mar 16, 2022 | Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct ... |
| CVE-2021-45848 | HIGH | 7.5 | 1.6% | Mar 15, 2022 | Denial of service (DoS) vulnerability in Nicotine+ 3.0.3 and later allows a user with a modified Soulseek client to cras... |
| CVE-2021-45010 | HIGH | 8.8 | 70.1% | Mar 15, 2022 | A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7... |
| CVE-2021-43305 | HIGH | 8.8 | 1.6% | Mar 14, 2022 | Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that... |
| CVE-2021-43304 | HIGH | 8.8 | 1.6% | Mar 14, 2022 | Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now