2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-21457HIGH8.8SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources...
CVE-2021-21456HIGH8.8SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources...
CVE-2021-21455HIGH8.8SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated DIB file received from untrusted sources...
CVE-2021-21454HIGH8.8SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RLE file received from untrusted sources...
CVE-2021-21453HIGH8.8SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated RLE file received from untrusted sources...
CVE-2021-21452HIGH8.8SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated GIF file received from untrusted sources...
CVE-2021-21451HIGH8.8SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated SGI file received from untrusted sources...
CVE-2021-21450HIGH8.8SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PSD file received from untrusted sources...
CVE-2021-21449HIGH8.8SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources...
CVE-2021-21448MEDIUM6.5SAP GUI for Windows, version - 7.60, allows an attacker to spoof logon credentials for Application Server ABAP backend s...
CVE-2021-21447MEDIUM5.4SAP BusinessObjects Business Intelligence platform, versions 410, 420, allows an authenticated attacker to inject malici...
CVE-2021-21446HIGH7.5SAP NetWeaver AS ABAP, versions 740, 750, 751, 752, 753, 754, 755, allows an unauthenticated attacker to prevent legitim...
CVE-2021-21445MEDIUM5.4SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated dat...
CVE-2021-23240HIGH7.8selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and es...
CVE-2021-23239LOW2.5The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existen...
CVE-2021-0322MEDIUM5In onCreate of SlicePermissionActivity.java, there is a possible misleading string displayed due to improper input valid...
CVE-2021-0321MEDIUM5.5In enforceDumpPermissionForPackage of ActivityManagerService.java, there is a possible way to determine if a package is ...
CVE-2021-0320MEDIUM4.7In is_device_locked and set_device_locked of keystore_keymaster_enforcement.h, there is a possible bypass of lockscreen ...
CVE-2021-0319HIGH7.3In checkCallerIsSystemOr of CompanionDeviceManagerService.java, there is a possible way to get a nearby Bluetooth device...
CVE-2021-0318HIGH7.8In appendEventsToCacheLocked of SensorEventConnection.cpp, there is a possible out of bounds write due to a use-after-fr...
CVE-2021-0317HIGH7.8In createOrUpdate of Permission.java and related code, there is possible permission escalation due to a logic error. Thi...
CVE-2021-0316CRITICAL9.8In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible out of bounds write due to a missing bounds check. This ...
CVE-2021-0315HIGH7.3In onCreate of GrantCredentialsPermissionActivity.java, there is a possible way to convince the user to grant an app acc...
CVE-2021-0313HIGH7.5In isWordBreakAfter of LayoutUtils.cpp, there is a possible way to slow or crash a TextView due to improper input valida...
CVE-2021-0312MEDIUM6.5In WAVSource::read of WAVExtractor.cpp, there is a possible out of bounds write due to an integer overflow. This could l...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now