2021 CVE Vulnerabilities

23,466 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-22363HIGH7.5There is a resource management error vulnerability in eCNS280_TD V100R005C10SPC650. An attacker needs to perform specifi...
CVE-2021-22342MEDIUM4.9There is an information leak vulnerability in Huawei products. A module does not deal with specific input sufficiently. ...
CVE-2021-3044CRITICAL9.8An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker wit...
CVE-2021-32644MEDIUM5.4Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering...
CVE-2021-22366MEDIUM5.5There is an out-of-bounds read vulnerability in eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300. Th...
CVE-2021-22365LOW3.3There is an out of bounds read vulnerability in eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300. A ...
CVE-2021-22361HIGH7.8There is an improper authorization vulnerability in eCNS280 V100R005C00, V100R005C10 and eSE620X vESS V100R001C10SPC200,...
CVE-2021-34428LOW3.5For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDe...
CVE-2021-35206MEDIUM6.1Gitpod before 0.6.0 allows unvalidated redirects.
CVE-2021-35046MEDIUM6.1A session fixation vulnerability was discovered in Ice Hrm 29.0.0 OS which allows an attacker to hijack a valid user ses...
CVE-2021-35045MEDIUM6.1Cross site scripting (XSS) vulnerability in Ice Hrm 29.0.0.OS, allows attackers to execute arbitrary code via the parame...
CVE-2021-34244HIGH8.8A cross site request forgery (CSRF) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to create n...
CVE-2021-34243MEDIUM5.4A stored cross site scripting (XSS) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to execute ...
CVE-2021-0608HIGH7.8In handleAppLaunch of AppLaunchActivity.java, there is a possible arbitrary activity launch due to a confused deputy. Th...
CVE-2021-0607HIGH7.8In iaxxx_calc_i2s_div of iaxxx-codec.c, there is a possible hardware port write with user controlled data due to a missi...
CVE-2021-0606MEDIUM6.7In drm_syncobj_handle_to_fd of drm_syncobj.c, there is a possible use after free due to incorrect refcounting. This coul...
CVE-2021-0605MEDIUM4.4In pfkey_dump of af_key.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to loca...
CVE-2021-0553HIGH7.3In onBindViewHolder of AppSwitchPreference.java, there is a possible bypass of device admin setttings due to unclear UI....
CVE-2021-0552MEDIUM5.5In getEndItemSliceAction of MediaOutputSlice.java, there is a possible permission bypass due to an unsafe PendingIntent....
CVE-2021-0551MEDIUM6.5In bind of MediaControlPanel.java, there is a possible way to lock up the system UI using a malicious media file due to ...
CVE-2021-0550HIGH7.8In onLoadFailed of AnnotateActivity.java, there is a possible way to gain WRITE_EXTERNAL_STORAGE permissions without use...
CVE-2021-0549MEDIUM4.4In sspRequestCallback of BondStateMachine.java, there is a possible leak of Bluetooth MAC addresses due to log informati...
CVE-2021-0548HIGH7.8In rw_i93_send_to_lower of rw_i93.cc, there is a possible out of bounds write due to a missing bounds check. This could ...
CVE-2021-0547HIGH7.8In onReceive of NetInitiatedActivity.java, there is a possible way to supply an attacker-controlled value to a GPS HAL h...
CVE-2021-0546MEDIUM6.7In phNxpNciHal_print_res_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now