2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-0527 | HIGH | 7.8 | 0.1% | Jun 21, 2021 | In memory management driver, there is a possible memory corruption due to a use after free. This could lead to local esc... |
| CVE-2021-0526 | HIGH | 7.8 | 0.1% | Jun 21, 2021 | In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local... |
| CVE-2021-0525 | HIGH | 7.8 | 0.1% | Jun 21, 2021 | In memory management driver, there is a possible out of bounds write due to a use after free. This could lead to local e... |
| CVE-2021-0523 | HIGH | 7.3 | 0.1% | Jun 21, 2021 | In onCreate of WifiScanModeActivity.java, there is a possible way to enable Wi-Fi scanning without user consent due to a... |
| CVE-2021-0522 | HIGH | 7.5 | 1.4% | Jun 21, 2021 | In ConnectionHandler::SdpCb of connection_handler.cc, there is a possible out of bounds read due to a use after free. Th... |
| CVE-2021-0521 | MEDIUM | 5.5 | 0.1% | Jun 21, 2021 | In getAllPackages of PackageManagerService, there is a possible information disclosure due to a missing permission check... |
| CVE-2021-0520 | HIGH | 7 | 0.2% | Jun 21, 2021 | In several functions of MemoryFileSystem.cpp and related files, there is a possible use after free due to a race conditi... |
| CVE-2021-0517 | HIGH | 7.5 | 0.8% | Jun 21, 2021 | In updateCapabilities of ConnectivityService.java, there is a possible incorrect network state determination due to a lo... |
| CVE-2021-0516 | CRITICAL | 9.8 | 1.6% | Jun 21, 2021 | In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free. This... |
| CVE-2021-0513 | HIGH | 7.8 | 0.2% | Jun 21, 2021 | In deleteNotificationChannel and related functions of NotificationManagerService.java, there is a possible permission by... |
| CVE-2021-0512 | HIGH | 7.8 | 0.3% | Jun 21, 2021 | In __hidinput_change_resolution_multipliers of hid-input.c, there is a possible out of bounds write due to a heap buffer... |
| CVE-2021-0511 | HIGH | 7.8 | 0.2% | Jun 21, 2021 | In Dex2oat of dex2oat.cc, there is a possible way to inject bytecode into an app due to improper input validation. This ... |
| CVE-2021-0510 | HIGH | 7.8 | 0.2% | Jun 21, 2021 | In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds write due to an integer overflow. This could lead ... |
| CVE-2021-0509 | HIGH | 7 | 0.2% | Jun 21, 2021 | In various functions of CryptoPlugin.cpp, there is a possible use after free due to a race condition. This could lead to... |
| CVE-2021-0508 | HIGH | 7 | 0.2% | Jun 21, 2021 | In various functions of DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to lo... |
| CVE-2021-0507 | HIGH | 8.8 | 1.0% | Jun 21, 2021 | In handle_rc_metamsg_cmd of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This coul... |
| CVE-2021-0506 | HIGH | 7.3 | 0.3% | Jun 21, 2021 | In ActivityPicker.java, there is a possible bypass of user interaction in intent resolution due to a tapjacking/overlay ... |
| CVE-2021-0505 | HIGH | 7.8 | 0.1% | Jun 21, 2021 | In the Settings app, there is a possible way to disable an always-on VPN due to a missing permission check. This could l... |
| CVE-2021-0504 | MEDIUM | 6.5 | 0.3% | Jun 21, 2021 | In avrc_pars_browse_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This c... |
| CVE-2021-0478 | HIGH | 7.8 | 0.3% | Jun 21, 2021 | In updateDrawable of StatusBarIconView.java, there is a possible permission bypass due to an uncaught exception. This co... |
| CVE-2021-29060 | MEDIUM | 5.3 | 3.1% | Jun 21, 2021 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Color-String version 1.5.5 and below whic... |
| CVE-2021-29059 | HIGH | 7.5 | 2.8% | Jun 21, 2021 | A vulnerability was discovered in IS-SVG version 2.1.0 to 4.2.2 and below where a Regular Expression Denial of Service (... |
| CVE-2021-20249 | — | — | — | Jun 21, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-20248 | — | — | — | Jun 21, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-28833 | MEDIUM | 6.1 | 0.7% | Jun 21, 2021 | Increments Qiita::Markdown before 0.34.0 allows XSS via a crafted gist link, a different vulnerability than CVE-2021-287... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now