2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-0489HIGH7.8In memory management driver, there is a possible out of bounds write due to a missing bounds check. This could lead to l...
CVE-2021-0487HIGH7.8In onCreate of CalendarDebugActivity.java, there is a possible way to export calendar data to the sdcard without user co...
CVE-2021-0485HIGH7.8In getMinimalSize of PipBoundsAlgorithm.java, there is a possible bypass of restrictions on background processes due to ...
CVE-2021-0484MEDIUM5.5In readVector of IMediaPlayer.cpp, there is a possible read of uninitialized heap data due to a missing bounds check. Th...
CVE-2021-0482HIGH7In BinderDiedCallback of MediaCodec.cpp, there is a possible memory corruption due to a use after free. This could lead ...
CVE-2021-0481HIGH7.8In onActivityResult of EditUserPhotoController.java, there is a possible access of unauthorized files due to an unexpect...
CVE-2021-0480MEDIUM5.5In createPendingIntent of SnoozeHelper.java, there is a possible broadcast intent containing a sensitive identifier. Thi...
CVE-2021-0477HIGH7.8In notifyScreenshotError of ScreenshotNotificationsController.java, there is a possible permission bypass due to an unsa...
CVE-2021-0476HIGH7In FindOrCreatePeer of btif_av.cc, there is a possible use after free due to a race condition. This could lead to local ...
CVE-2021-0475HIGH8.8In on_l2cap_data_ind of btif_sock_l2cap.cc, there is possible memory corruption due to a use after free. This could lead...
CVE-2021-0474CRITICAL9.8In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead...
CVE-2021-0473HIGH8.8In rw_t3t_process_error of rw_t3t.cc, there is a possible double free due to uninitialized data. This could lead to remo...
CVE-2021-0472HIGH7.8In shouldLockKeyguard of LockTaskController.java, there is a possible way to exit App Pinning without a PIN due to a per...
CVE-2021-0466HIGH7.5In startIpClient of ClientModeImpl.java, there is a possible identifier which could be used to track a device. This coul...
CVE-2021-28213HIGH7.5Example EDK2 encrypted private key in the IpSecDxe.efi present potential security risks.
CVE-2021-28211MEDIUM6.7A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.
CVE-2021-28210HIGH7.8An unlimited recursion in DxeCore in EDK II.
CVE-2021-23230MEDIUM4.3A SQL Injection vulnerability in the OPCUA interface of Gallagher Command Centre allows a remote unprivileged Command Ce...
CVE-2021-23211MEDIUM4.4Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows Cloud end-t...
CVE-2021-23205HIGH8.1Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configura...
CVE-2021-23204MEDIUM6.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gallagher Command Centre Server allows OSDP ...
CVE-2021-23182MEDIUM4.4Cleartext Storage of Sensitive Information in Memory vulnerability in Gallagher Command Centre Server allows OSDP reader...
CVE-2021-23140HIGH8.8Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an ...
CVE-2021-23136MEDIUM6.5Improper Authorization vulnerability in Gallagher Command Centre Server allows macro overrides to be performed by an unp...
CVE-2021-22915CRITICAL9.8Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 s...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now