2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-0311 | MEDIUM | 6.5 | 1.1% | Jan 11, 2021 | In ElementaryStreamQueue::dequeueAccessUnitH264() of ESQueue.cpp, there is a possible out of bounds write due to a missi... |
| CVE-2021-0310 | HIGH | 7.8 | 0.2% | Jan 11, 2021 | In LazyServiceRegistrar of LazyServiceRegistrar.cpp, there is a possible memory corruption due to a use after free. This... |
| CVE-2021-0309 | MEDIUM | 5.5 | 0.2% | Jan 11, 2021 | In onCreate of grantCredentialsPermissionActivity, there is a confused deputy. This could lead to local information disc... |
| CVE-2021-0308 | MEDIUM | 6.8 | 0.4% | Jan 11, 2021 | In ReadLogicalParts of basicmbr.cc, there is a possible out of bounds write due to a missing bounds check. This could le... |
| CVE-2021-0307 | HIGH | 7.8 | 0.2% | Jan 11, 2021 | In updatePermissionSourcePackage of PermissionManagerService.java, there is a possible automatic runtime permission gran... |
| CVE-2021-0306 | HIGH | 7.8 | 0.3% | Jan 11, 2021 | In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Andro... |
| CVE-2021-0304 | MEDIUM | 5.5 | 0.2% | Jan 11, 2021 | In several functions of GlobalScreenshot.java, there is a possible permission bypass due to an unsafe PendingIntent. Thi... |
| CVE-2021-0303 | HIGH | 7 | 0.1% | Jan 11, 2021 | In dispatchGraphTerminationMessage() of packages/services/Car/computepipe/runner/graph/StreamSetObserver.cpp, there is a... |
| CVE-2021-0301 | MEDIUM | 6.7 | 0.2% | Jan 11, 2021 | In ged, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr... |
| CVE-2021-21241 | HIGH | 7.4 | 0.9% | Jan 11, 2021 | The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is a in... |
| CVE-2021-0342 | MEDIUM | 6.7 | 0.2% | Jan 11, 2021 | In tun_get_user of tun.c, there is possible memory corruption due to a use after free. This could lead to local escalati... |
| CVE-2021-23253 | MEDIUM | 5.3 | 0.8% | Jan 11, 2021 | Opera Mini for Android below 53.1 displays URL left-aligned in the address field. This allows a malicious attacker to cr... |
| CVE-2021-3121 | HIGH | 8.6 | 3.5% | Jan 11, 2021 | An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka... |
| CVE-2021-3118 | CRITICAL | 9.8 | 1.8% | Jan 11, 2021 | EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has multiple SQL Injection issues in the login form and the passwo... |
| CVE-2021-3116 | HIGH | 7.5 | 1.7% | Jan 11, 2021 | before_upstream_connection in AuthPlugin in http/proxy/auth.py in proxy.py before 2.3.1 accepts incorrect Proxy-Authoriz... |
| CVE-2021-21116 | HIGH | 8.8 | 1.4% | Jan 8, 2021 | Heap buffer overflow in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit h... |
| CVE-2021-21115 | CRITICAL | 9.6 | 1.4% | Jan 8, 2021 | User after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised t... |
| CVE-2021-21114 | HIGH | 8.8 | 1.4% | Jan 8, 2021 | Use after free in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap co... |
| CVE-2021-21113 | HIGH | 8.8 | 1.5% | Jan 8, 2021 | Heap buffer overflow in Skia in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit he... |
| CVE-2021-21112 | HIGH | 8.8 | 1.4% | Jan 8, 2021 | Use after free in Blink in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap co... |
| CVE-2021-21111 | CRITICAL | 9.6 | 1.1% | Jan 8, 2021 | Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker who convinced a use... |
| CVE-2021-21110 | CRITICAL | 9.6 | 3.1% | Jan 8, 2021 | Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform... |
| CVE-2021-21109 | CRITICAL | 9.6 | 1.3% | Jan 8, 2021 | Use after free in payments in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the ren... |
| CVE-2021-21108 | CRITICAL | 9.6 | 1.3% | Jan 8, 2021 | Use after free in media in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the render... |
| CVE-2021-21107 | CRITICAL | 9.6 | 1.1% | Jan 8, 2021 | Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compr... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now