2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-46006MEDIUM6.5In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function...
CVE-2021-45900MEDIUM6.5Vivoh Webinar Manager before 3.6.3.0 has improper API authentication. When a user logs in to the administration configur...
CVE-2021-38362MEDIUM6.5In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint tha...
CVE-2021-40645MEDIUM6.5An SQL Injection vulnerability exists in glorylion JFinalOA as of 9/7/2021 in the defkey parameter getHaveDoneTaskDataLi...
CVE-2021-40644MEDIUM6.5An SQL Injection vulnerability exists in oasys oa_system as of 9/7/2021 in resources/mappers/notice-mapper.xml.
CVE-2021-44310MEDIUM4.8An issue was discovered in Firmware Analysis and Comparison Tool v3.2. With administrator privileges, the attacker could...
CVE-2021-39791MEDIUM5.5In WallpaperManagerService, there is a possible way to determine whether an app is installed, without query permissions,...
CVE-2021-39788MEDIUM5.5In TelecomManager, there is a possible way to check if a particular self managed phone account was registered on the dev...
CVE-2021-39786MEDIUM6.7In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr...
CVE-2021-39779MEDIUM5.5In getCallStateUsingPackage of Telecom Service, there is a missing permission check. This could lead to local informatio...
CVE-2021-39778MEDIUM5.5In Telecomm, there is a possible way to determine whether an app is installed, without query permissions, due to imprope...
CVE-2021-39777MEDIUM5.5In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to a miss...
CVE-2021-39775MEDIUM5.5In People, there is a possible way to determine whether an app is installed, without query permissions, due to side chan...
CVE-2021-39774MEDIUM5.5In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of s...
CVE-2021-39773MEDIUM5.5In VpnManagerService, there is a possible disclosure of installed VPN packages due to side channel information disclosur...
CVE-2021-39770MEDIUM5.5In Framework, there is a possible disclosure of the device owner package due to a missing permission check. This could l...
CVE-2021-39769MEDIUM5.5In Device Policy, there is a possible way to determine whether an app is installed, without query permissions, due to a ...
CVE-2021-39766MEDIUM5.5In Settings, there is a possible way to determine whether an app is installed, without query permissions, due to side ch...
CVE-2021-39765MEDIUM5.5In Gallery, there is a possible permission bypass due to a confused deputy. This could lead to local information disclos...
CVE-2021-39761MEDIUM5.5In Media, there is a possible way to determine whether an app is installed, without query permissions, due to side chann...
CVE-2021-39760MEDIUM5.5In AudioService, there is a possible way to determine whether an app is installed, without query permissions, due to sid...
CVE-2021-39757MEDIUM5.5In PermissionController, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local ...
CVE-2021-39756MEDIUM5.5In Framework, there is a possible way to determine whether an app is installed, without query permissions, due to side c...
CVE-2021-39755MEDIUM5.5In DevicePolicyManager, there is a possible way to reveal the existence of an installed package without proper query per...
CVE-2021-39754MEDIUM5.5In ContextImpl, there is a possible way to determine whether an app is installed, without query permissions, due to side...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now