2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-26936HIGH7.8The replay-sorcery program in ReplaySorcery 0.4.0 through 0.5.0, when using the default setuid-root configuration, allow...
CVE-2021-20353HIGH8.2IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack w...
CVE-2021-0341HIGH7.5In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due t...
CVE-2021-0340HIGH8.8In parseNextBox of IsoInterface.java, there is a possible leak of unredacted location information due to improper input ...
CVE-2021-0339HIGH7.8In loadAnimation of WindowContainer.java, there is a possible way to keep displaying a malicious app while a target app ...
CVE-2021-0338MEDIUM5.5In SystemSettingsValidators, there is a possible permanent denial of service due to missing bounds checks on UI settings...
CVE-2021-0337HIGH7.8In moveInMediaStore of FileSystemProvider.java, there is a possible file exposure due to stale metadata. This could lead...
CVE-2021-0336HIGH7.8In onReceive of BluetoothPermissionRequest.java, there is a possible permissions bypass due to a mutable PendingIntent. ...
CVE-2021-0335MEDIUM6.5In process of C2SoftHevcDec.cpp, there is a possible out of bounds write due to a use after free. This could lead to rem...
CVE-2021-0334HIGH7.8In onTargetSelected of ResolverActivity.java, there is a possible settings bypass allowing an app to become the default ...
CVE-2021-0333HIGH7.3In onCreate of BluetoothPermissionActivity.java, there is a possible permissions bypass due to a tapjacking overlay that...
CVE-2021-0332HIGH7.8In bootFinished of SurfaceFlinger.cpp, there is a possible memory corruption due to a use after free. This could lead to...
CVE-2021-0331HIGH7.3In onCreate of NotificationAccessConfirmationActivity.java, there is a possible overlay attack due to an insecure defaul...
CVE-2021-0330HIGH7.8In add_user_ce and remove_user_ce of storaged.cpp, there is a possible use-after-free due to improper locking. This coul...
CVE-2021-0329HIGH7.8In several native functions called by AdvertiseManager.java, there is a possible out of bounds write due to a missing bo...
CVE-2021-0328HIGH7.8In onBatchScanReports and deliverBatchScan of GattService.java, there is a possible way to retrieve Bluetooth scan resul...
CVE-2021-0327HIGH7.8In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due to non-restored bind...
CVE-2021-0326HIGH7.5In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead...
CVE-2021-0325HIGH8.8In ih264d_parse_pslice of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow. ...
CVE-2021-0314HIGH7.3In onCreate of UninstallerActivity, there is a possible way to uninstall an all without informed user consent due to a t...
CVE-2021-0305HIGH7.8In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local es...
CVE-2021-0302HIGH7.8In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local es...
CVE-2021-27135CRITICAL9.8xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fau...
CVE-2021-23881MEDIUM4.8A stored cross site scripting vulnerability in ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 February ...
CVE-2021-23876HIGH7.8Bypass Remote Procedure call in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated priv...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now