2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-0456MEDIUM6.7In the Citadel chip firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to ...
CVE-2021-0455MEDIUM6.7In the Citadel chip firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to ...
CVE-2021-0454MEDIUM6.7In the Citadel chip firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to ...
CVE-2021-0453MEDIUM4.4In the Titan-M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead ...
CVE-2021-0452MEDIUM4.4In the Titan M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead ...
CVE-2021-0451MEDIUM4.4In the Titan M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead ...
CVE-2021-0450MEDIUM4.4In the Titan M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead ...
CVE-2021-0449MEDIUM4.4In the Titan M chip firmware, there is a possible disclosure of stack memory due to uninitialized data. This could lead ...
CVE-2021-0389HIGH7.8In setNightModeActivated of UiModeManagerService.java, there is a missing permission check. This could lead to local esc...
CVE-2021-0388HIGH7.8In onReceive of ImsPhoneCallTracker.java, there is a possible misattribution of data usage due to an incorrect broadcast...
CVE-2021-0387MEDIUM6.4In FindQuotaDeviceForUuid of QuotaUtils.cpp, there is a possible use-after-free due to a race condition. This could lead...
CVE-2021-0386HIGH7.8In onCreate of UsbConfirmActivity, there is a possible tapjacking vector due to an insecure default value. This could le...
CVE-2021-0385HIGH7.8In createConnectToAvailableNetworkNotification of ConnectToNetworkNotificationBuilder.java, there is a possible connecti...
CVE-2021-0384Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-0383HIGH7.8In done of CaptivePortalLoginActivity.java, there is a confused deputy. This could lead to local escalation of privilege...
CVE-2021-0382MEDIUM5.5In checkSlicePermission of SliceManagerService.java, there is a possible resource exposure due to an incorrect permissio...
CVE-2021-0381MEDIUM5.5In updateNotifications of DeviceStorageMonitorService.java, there is a possible permission bypass due to an unsafe Pendi...
CVE-2021-0380HIGH7.8In onReceive of DcTracker.java, there is a possible way to trigger a provisioning URL and modify other telephony setting...
CVE-2021-0379MEDIUM6.5In getUpTo17bits of pvmp3_getbits.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could ...
CVE-2021-24030CRITICAL9.8The fbgames protocol handler registered as part of Facebook Gameroom does not properly quote arguments passed to the exe...
CVE-2021-24025CRITICAL9.8Due to incorrect string size calculations inside the preg_quote function, a large input string passed to the function ca...
CVE-2021-20265MEDIUM5.5A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a s...
CVE-2021-0399HIGH7.8In qtaguid_untag of xt_qtaguid.c, there is a possible memory corruption due to a use after free. This could lead to loca...
CVE-2021-0398HIGH7.8In bindServiceLocked of ActiveServices.java, there is a possible foreground service launch due to a confused deputy. Thi...
CVE-2021-0397CRITICAL9.8In sdp_copy_raw_data of sdp_discovery.cc, there is a possible system compromise due to a double free. This could lead to...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now