2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26936 | HIGH | 7.8 | 0.5% | Feb 10, 2021 | The replay-sorcery program in ReplaySorcery 0.4.0 through 0.5.0, when using the default setuid-root configuration, allow... |
| CVE-2021-20353 | HIGH | 8.2 | 5.2% | Feb 10, 2021 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack w... |
| CVE-2021-0341 | HIGH | 7.5 | 0.9% | Feb 10, 2021 | In verifyHostName of OkHostnameVerifier.java, there is a possible way to accept a certificate for the wrong domain due t... |
| CVE-2021-0340 | HIGH | 8.8 | 2.1% | Feb 10, 2021 | In parseNextBox of IsoInterface.java, there is a possible leak of unredacted location information due to improper input ... |
| CVE-2021-0339 | HIGH | 7.8 | 0.7% | Feb 10, 2021 | In loadAnimation of WindowContainer.java, there is a possible way to keep displaying a malicious app while a target app ... |
| CVE-2021-0338 | MEDIUM | 5.5 | 0.1% | Feb 10, 2021 | In SystemSettingsValidators, there is a possible permanent denial of service due to missing bounds checks on UI settings... |
| CVE-2021-0337 | HIGH | 7.8 | 0.2% | Feb 10, 2021 | In moveInMediaStore of FileSystemProvider.java, there is a possible file exposure due to stale metadata. This could lead... |
| CVE-2021-0336 | HIGH | 7.8 | 0.3% | Feb 10, 2021 | In onReceive of BluetoothPermissionRequest.java, there is a possible permissions bypass due to a mutable PendingIntent. ... |
| CVE-2021-0335 | MEDIUM | 6.5 | 0.8% | Feb 10, 2021 | In process of C2SoftHevcDec.cpp, there is a possible out of bounds write due to a use after free. This could lead to rem... |
| CVE-2021-0334 | HIGH | 7.8 | 0.3% | Feb 10, 2021 | In onTargetSelected of ResolverActivity.java, there is a possible settings bypass allowing an app to become the default ... |
| CVE-2021-0333 | HIGH | 7.3 | 0.3% | Feb 10, 2021 | In onCreate of BluetoothPermissionActivity.java, there is a possible permissions bypass due to a tapjacking overlay that... |
| CVE-2021-0332 | HIGH | 7.8 | 0.2% | Feb 10, 2021 | In bootFinished of SurfaceFlinger.cpp, there is a possible memory corruption due to a use after free. This could lead to... |
| CVE-2021-0331 | HIGH | 7.3 | 0.3% | Feb 10, 2021 | In onCreate of NotificationAccessConfirmationActivity.java, there is a possible overlay attack due to an insecure defaul... |
| CVE-2021-0330 | HIGH | 7.8 | 0.3% | Feb 10, 2021 | In add_user_ce and remove_user_ce of storaged.cpp, there is a possible use-after-free due to improper locking. This coul... |
| CVE-2021-0329 | HIGH | 7.8 | 0.3% | Feb 10, 2021 | In several native functions called by AdvertiseManager.java, there is a possible out of bounds write due to a missing bo... |
| CVE-2021-0328 | HIGH | 7.8 | 0.2% | Feb 10, 2021 | In onBatchScanReports and deliverBatchScan of GattService.java, there is a possible way to retrieve Bluetooth scan resul... |
| CVE-2021-0327 | HIGH | 7.8 | 0.3% | Feb 10, 2021 | In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due to non-restored bind... |
| CVE-2021-0326 | HIGH | 7.5 | 4.7% | Feb 10, 2021 | In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead... |
| CVE-2021-0325 | HIGH | 8.8 | 2.0% | Feb 10, 2021 | In ih264d_parse_pslice of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow. ... |
| CVE-2021-0314 | HIGH | 7.3 | 0.3% | Feb 10, 2021 | In onCreate of UninstallerActivity, there is a possible way to uninstall an all without informed user consent due to a t... |
| CVE-2021-0305 | HIGH | 7.8 | 0.5% | Feb 10, 2021 | In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local es... |
| CVE-2021-0302 | HIGH | 7.8 | 0.7% | Feb 10, 2021 | In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local es... |
| CVE-2021-27135 | CRITICAL | 9.8 | 7.5% | Feb 10, 2021 | xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fau... |
| CVE-2021-23881 | MEDIUM | 4.8 | 0.6% | Feb 10, 2021 | A stored cross site scripting vulnerability in ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 February ... |
| CVE-2021-23876 | HIGH | 7.8 | 0.4% | Feb 10, 2021 | Bypass Remote Procedure call in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated priv... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now