2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-4101 | HIGH | 8.8 | 1.0% | Feb 11, 2022 | Heap buffer overflow in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exp... |
| CVE-2021-4100 | HIGH | 8.8 | 0.7% | Feb 11, 2022 | Object lifecycle issue in ANGLE in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit... |
| CVE-2021-4099 | HIGH | 8.8 | 0.7% | Feb 11, 2022 | Use after free in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit h... |
| CVE-2021-4098 | HIGH | 7.4 | 0.6% | Feb 11, 2022 | Insufficient data validation in Mojo in Google Chrome prior to 96.0.4664.110 allowed a remote attacker who had compromis... |
| CVE-2021-46366 | HIGH | 8.8 | 0.7% | Feb 11, 2022 | An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerabil... |
| CVE-2021-46365 | HIGH | 7.8 | 1.6% | Feb 11, 2022 | An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via... |
| CVE-2021-46364 | HIGH | 7.8 | 1.5% | Feb 11, 2022 | A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via... |
| CVE-2021-46363 | HIGH | 7.8 | 1.8% | Feb 11, 2022 | An issue in the Export function of Magnolia v6.2.3 and below allows attackers to perform Formula Injection attacks via c... |
| CVE-2021-39677 | HIGH | 7.5 | 0.4% | Feb 11, 2022 | In startVideoStream() there is a possibility of an OOB Read in the heap, when the camera buffer is ‘zero’ in size.Produc... |
| CVE-2021-39676 | HIGH | 7.8 | 0.1% | Feb 11, 2022 | In writeThrowable of AndroidFuture.java, there is a possible parcel serialization/deserialization mismatch due to improp... |
| CVE-2021-39674 | HIGH | 7.8 | 0.1% | Feb 11, 2022 | In btm_sec_connected and btm_sec_disconnected of btm_sec.cc file , there is a possible use after free. This could lead t... |
| CVE-2021-39672 | HIGH | 7.8 | 0.1% | Feb 11, 2022 | In fastboot, there is a possible secure boot bypass due to a configuration error. This could lead to local escalation of... |
| CVE-2021-39669 | HIGH | 7.8 | 0.1% | Feb 11, 2022 | In onCreate of InstallCaCertificateWarning.java, there is a possible way to mislead an user about CA installation circum... |
| CVE-2021-39668 | HIGH | 7.8 | 0.1% | Feb 11, 2022 | In onActivityViewReady of DetailDialog.kt, there is a possible Intent Redirect due to a confused deputy. This could lead... |
| CVE-2021-39663 | HIGH | 7.8 | 0.1% | Feb 11, 2022 | In openFileAndEnforcePathPermissionsHelper of MediaProvider.java, there is a possible bypass of a permissions check due ... |
| CVE-2021-39662 | HIGH | 7.8 | 0.1% | Feb 11, 2022 | In checkUriPermission of MediaProvider.java , there is a possible way to gain access to the content of media provider co... |
| CVE-2021-39619 | HIGH | 7.8 | 0.1% | Feb 11, 2022 | In updatePackageMappingsData of UsageStatsService.java, there is a possible way to bypass security and privacy settings ... |
| CVE-2021-22824 | HIGH | 7.5 | 14.2% | Feb 11, 2022 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in denial of service, due t... |
| CVE-2021-22806 | HIGH | 7.5 | 0.9% | Feb 11, 2022 | A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could cause data exfiltration and unaut... |
| CVE-2021-22804 | HIGH | 7.5 | 1.3% | Feb 11, 2022 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause disclosure o... |
| CVE-2021-22800 | HIGH | 7.5 | 1.0% | Feb 11, 2022 | A CWE-20: Improper Input Validation vulnerability exists that could cause a Denial of Service when a crafted packet is s... |
| CVE-2021-22798 | HIGH | 7.5 | 0.9% | Feb 11, 2022 | A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause Sensitive data such as login crede... |
| CVE-2021-22796 | HIGH | 7.8 | 1.2% | Feb 11, 2022 | A CWE-287: Improper Authentication vulnerability exists that could allow remote code execution when a malicious file is ... |
| CVE-2021-22788 | HIGH | 7.5 | 1.0% | Feb 11, 2022 | A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attacker sends a speciall... |
| CVE-2021-22787 | HIGH | 7.5 | 1.0% | Feb 11, 2022 | A CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of the device when an attack... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now