2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-21485MEDIUM6.5An unauthorized attacker may be able to entice an administrator to invoke telnet commands of an SAP NetWeaver Applicatio...
CVE-2021-21483MEDIUM4.9Under certain conditions SAP Solution Manager, version - 720, allows a high privileged attacker to get access to sensiti...
CVE-2021-21482HIGH8.3SAP NetWeaver Master Data Management, versions - 710, 710.750, allows a malicious unauthorized user with access to the M...
CVE-2021-0471MEDIUM5.5In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to an integer overflow. This could lead t...
CVE-2021-0468MEDIUM6.6In LK, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation...
CVE-2021-0446HIGH7.3In ImportVCardActivity, there is a possible way to bypass user consent due to a tapjacking/overlay attack. This could le...
CVE-2021-0445HIGH7.8In start of WelcomeActivity.java, there is a possible residual profile due to a confused deputy. This could lead to loca...
CVE-2021-0444MEDIUM5.5In onActivityResult of QuickContactActivity.java, there is an unnecessary return of an intent. This could lead to local ...
CVE-2021-0443MEDIUM4.7In several functions of ScreenshotHelper.java and related files, there is a possible incorrectly saved screenshot due to...
CVE-2021-0442HIGH7.8In updateInfo of android_hardware_input_InputApplicationHandle.cpp, there is a possible control of code flow due to a us...
CVE-2021-0439HIGH7.8In setPowerModeWithHandle of com_android_server_power_PowerManagerService.cpp, there is a possible out of bounds write d...
CVE-2021-0438HIGH7.8In several functions of InputDispatcher.cpp, WindowManagerService.java, and related files, there is a possible tapjackin...
CVE-2021-0437HIGH7.8In setPlayPolicy of DrmPlugin.cpp, there is a possible double free. This could lead to local escalation of privilege in ...
CVE-2021-0436MEDIUM5.5In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds read due to integer overflow. This could...
CVE-2021-0435HIGH7.5In avrc_proc_vendor_command of avrc_api.cc, there is a possible leak of heap data due to uninitialized data. This could ...
CVE-2021-0433HIGH8In onCreate of DeviceChooserActivity.java, there is a possible way to bypass user consent when pairing a Bluetooth devic...
CVE-2021-0432HIGH7In ClearPullerCacheIfNecessary and ForceClearPullerCache of StatsPullerManager.cpp, there is a possible use-after-free d...
CVE-2021-0431HIGH7.5In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds read due to a missing bounds check. This could lead ...
CVE-2021-0430CRITICAL9.8In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a missing bounds check. This could...
CVE-2021-0429HIGH7.8In pollOnce of ALooper.cpp, there is possible memory corruption due to a use after free. This could lead to local escala...
CVE-2021-0428MEDIUM5.5In getSimSerialNumber of TelephonyManager.java, there is a possible way to read a trackable identifier due to a missing ...
CVE-2021-0427HIGH7.8In parseExclusiveStateAnnotation of LogEvent.cpp, there is a possible out of bounds write due to a heap buffer overflow....
CVE-2021-0426HIGH7.8In parsePrimaryFieldFirstUidAnnotation of LogEvent.cpp, there is a possible out of bounds write due to a heap buffer ove...
CVE-2021-0400MEDIUM5.5In injectBestLocation and handleUpdateLocation of GnssLocationProvider.java, there is a possible incorrect reporting of ...
CVE-2021-29999CRITICAL9.8An issue was discovered in Wind River VxWorks through 6.8. There is a possible stack overflow in dhcp server.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now