2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-0311MEDIUM6.5In ElementaryStreamQueue::dequeueAccessUnitH264() of ESQueue.cpp, there is a possible out of bounds write due to a missi...
CVE-2021-0310HIGH7.8In LazyServiceRegistrar of LazyServiceRegistrar.cpp, there is a possible memory corruption due to a use after free. This...
CVE-2021-0309MEDIUM5.5In onCreate of grantCredentialsPermissionActivity, there is a confused deputy. This could lead to local information disc...
CVE-2021-0308MEDIUM6.8In ReadLogicalParts of basicmbr.cc, there is a possible out of bounds write due to a missing bounds check. This could le...
CVE-2021-0307HIGH7.8In updatePermissionSourcePackage of PermissionManagerService.java, there is a possible automatic runtime permission gran...
CVE-2021-0306HIGH7.8In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Andro...
CVE-2021-0304MEDIUM5.5In several functions of GlobalScreenshot.java, there is a possible permission bypass due to an unsafe PendingIntent. Thi...
CVE-2021-0303HIGH7In dispatchGraphTerminationMessage() of packages/services/Car/computepipe/runner/graph/StreamSetObserver.cpp, there is a...
CVE-2021-0301MEDIUM6.7In ged, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr...
CVE-2021-21241HIGH7.4The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is a in...
CVE-2021-0342MEDIUM6.7In tun_get_user of tun.c, there is possible memory corruption due to a use after free. This could lead to local escalati...
CVE-2021-23253MEDIUM5.3Opera Mini for Android below 53.1 displays URL left-aligned in the address field. This allows a malicious attacker to cr...
CVE-2021-3121HIGH8.6An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka...
CVE-2021-3118CRITICAL9.8EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has multiple SQL Injection issues in the login form and the passwo...
CVE-2021-3116HIGH7.5before_upstream_connection in AuthPlugin in http/proxy/auth.py in proxy.py before 2.3.1 accepts incorrect Proxy-Authoriz...
CVE-2021-21116HIGH8.8Heap buffer overflow in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit h...
CVE-2021-21115CRITICAL9.6User after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised t...
CVE-2021-21114HIGH8.8Use after free in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap co...
CVE-2021-21113HIGH8.8Heap buffer overflow in Skia in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit he...
CVE-2021-21112HIGH8.8Use after free in Blink in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap co...
CVE-2021-21111CRITICAL9.6Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker who convinced a use...
CVE-2021-21110CRITICAL9.6Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform...
CVE-2021-21109CRITICAL9.6Use after free in payments in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the ren...
CVE-2021-21108CRITICAL9.6Use after free in media in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the render...
CVE-2021-21107CRITICAL9.6Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compr...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now