2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-46006 | MEDIUM | 6.5 | 7.2% | Mar 30, 2022 | In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function... |
| CVE-2021-45900 | MEDIUM | 6.5 | 0.7% | Mar 30, 2022 | Vivoh Webinar Manager before 3.6.3.0 has improper API authentication. When a user logs in to the administration configur... |
| CVE-2021-38362 | MEDIUM | 6.5 | 0.9% | Mar 30, 2022 | In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint tha... |
| CVE-2021-40645 | MEDIUM | 6.5 | 1.1% | Mar 30, 2022 | An SQL Injection vulnerability exists in glorylion JFinalOA as of 9/7/2021 in the defkey parameter getHaveDoneTaskDataLi... |
| CVE-2021-40644 | MEDIUM | 6.5 | 1.1% | Mar 30, 2022 | An SQL Injection vulnerability exists in oasys oa_system as of 9/7/2021 in resources/mappers/notice-mapper.xml. |
| CVE-2021-44310 | MEDIUM | 4.8 | 0.6% | Mar 30, 2022 | An issue was discovered in Firmware Analysis and Comparison Tool v3.2. With administrator privileges, the attacker could... |
| CVE-2021-39791 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In WallpaperManagerService, there is a possible way to determine whether an app is installed, without query permissions,... |
| CVE-2021-39788 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In TelecomManager, there is a possible way to check if a particular self managed phone account was registered on the dev... |
| CVE-2021-39786 | MEDIUM | 6.7 | 0.1% | Mar 30, 2022 | In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr... |
| CVE-2021-39779 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In getCallStateUsingPackage of Telecom Service, there is a missing permission check. This could lead to local informatio... |
| CVE-2021-39778 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In Telecomm, there is a possible way to determine whether an app is installed, without query permissions, due to imprope... |
| CVE-2021-39777 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to a miss... |
| CVE-2021-39775 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In People, there is a possible way to determine whether an app is installed, without query permissions, due to side chan... |
| CVE-2021-39774 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of s... |
| CVE-2021-39773 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In VpnManagerService, there is a possible disclosure of installed VPN packages due to side channel information disclosur... |
| CVE-2021-39770 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In Framework, there is a possible disclosure of the device owner package due to a missing permission check. This could l... |
| CVE-2021-39769 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In Device Policy, there is a possible way to determine whether an app is installed, without query permissions, due to a ... |
| CVE-2021-39766 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side ch... |
| CVE-2021-39765 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In Gallery, there is a possible permission bypass due to a confused deputy. This could lead to local information disclos... |
| CVE-2021-39761 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In Media, there is a possible way to determine whether an app is installed, without query permissions, due to side chann... |
| CVE-2021-39760 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In AudioService, there is a possible way to determine whether an app is installed, without query permissions, due to sid... |
| CVE-2021-39757 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In PermissionController, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local ... |
| CVE-2021-39756 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In Framework, there is a possible way to determine whether an app is installed, without query permissions, due to side c... |
| CVE-2021-39755 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In DevicePolicyManager, there is a possible way to reveal the existence of an installed package without proper query per... |
| CVE-2021-39754 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In ContextImpl, there is a possible way to determine whether an app is installed, without query permissions, due to side... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now