2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-1140CRITICAL9.8Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote ...
CVE-2021-1138CRITICAL9.8Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote ...
CVE-2021-1301CRITICAL9.8Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks aga...
CVE-2021-1300CRITICAL9.8Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks aga...
CVE-2021-2108CRITICAL9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). The suppor...
CVE-2021-2101CRITICAL9.1Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Print Server). Support...
CVE-2021-2100CRITICAL9.1Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Print Server). Support...
CVE-2021-2075CRITICAL9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples). Supported versions...
CVE-2021-2064CRITICAL9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). The suppor...
CVE-2021-2047CRITICAL9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). Supported ...
CVE-2021-2029CRITICAL9.8Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions ...
CVE-2021-1994CRITICAL9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported ver...
CVE-2021-3110CRITICAL9.8The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller...
CVE-2021-25323CRITICAL9.1The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the p...
CVE-2021-22851CRITICAL9.8HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (d...
CVE-2021-22850CRITICAL9.8HGiga EIP product lacks ineffective access control in certain pages that allow attackers to access database or perform p...
CVE-2021-3177CRITICAL9.8Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execu...
CVE-2021-25294CRITICAL9.8OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occ...
CVE-2021-21245CRITICAL9.8OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user control...
CVE-2021-21242CRITICAL9.8OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lea...
CVE-2021-21244CRITICAL9.8OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth ...
CVE-2021-21243CRITICAL9.8OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods ...
CVE-2021-0211CRITICAL10An improper check for unusual or exceptional conditions in Juniper Networks Junos OS and Junos OS Evolved Routing Protoc...
CVE-2021-23926CRITICAL9.1The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from maliciou...
CVE-2021-20618CRITICAL9.8Privilege chaining vulnerability in acmailer ver. 4.0.2 and earlier, and acmailer DB ver. 1.1.4 and earlier allows remot...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now