2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-2345MEDIUM5.4Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp...
CVE-2021-2343MEDIUM4.3Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Suppo...
CVE-2021-2342MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af...
CVE-2021-2339MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected...
CVE-2021-2338MEDIUM6.1Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Email Marketing Stand-Alone). Supp...
CVE-2021-25701MEDIUM5.5The fUSBHub driver in the PCoIP Software Client prior to version 21.07.0 had an error in object management during the ha...
CVE-2021-23411MEDIUM6.1Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the main functionality. It accepts in...
CVE-2021-22784MEDIUM5.7A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that cou...
CVE-2021-22773MEDIUM6.5A CWE-620: Unverified Password Change vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8...
CVE-2021-22770MEDIUM6.5A CWE-200: Information Exposure vulnerability exists in Easergy T300 with firmware V2.7.1 and older that exposes sensiti...
CVE-2021-22728MEDIUM6.5A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4....
CVE-2021-22723MEDIUM6.1A CWE-79: Improper Neutralization of Input During Web Page Generation (Cross-siteScripting) through Cross-Site Request F...
CVE-2021-22722MEDIUM5.4A CWE-79: Improper Neutralization of Input During Web Page Generation ('Stored Cross-site Scripting') vulnerability exis...
CVE-2021-22721MEDIUM5.3A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4....
CVE-2021-22706MEDIUM6.1A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in E...
CVE-2021-22145MEDIUM6.5A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the abil...
CVE-2021-20106MEDIUM6.5Nessus Agent versions 8.2.5 and earlier were found to contain a privilege escalation vulnerability which could allow a N...
CVE-2021-1103MEDIUM4.4NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can dereference a NULL ...
CVE-2021-1102MEDIUM5.5NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can lead to floating po...
CVE-2021-1101MEDIUM5.5NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can dereference a NULL ...
CVE-2021-1100MEDIUM5.5NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager kernel mode driver (nvidia.ko), in which a poin...
CVE-2021-2462MEDIUM6.1Vulnerability in the Oracle Commerce Service Center product of Oracle Commerce (component: Commerce Service Center). Sup...
CVE-2021-2460MEDIUM5.4Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. The supported version...
CVE-2021-2457MEDIUM5.3Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Request Management & Workflow). Th...
CVE-2021-2455MEDIUM6.5Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Person Search)...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now