2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-2002MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are ...
CVE-2021-2001MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af...
CVE-2021-1999MEDIUM5Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: RAS subsystems). The support...
CVE-2021-1995MEDIUM6.5Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported ver...
CVE-2021-1993MEDIUM4.8Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12....
CVE-2021-3137MEDIUM5.4XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.
CVE-2021-21263MEDIUM5.3Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding ex...
CVE-2021-3184MEDIUM6.1MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button.
CVE-2021-25325MEDIUM6.1MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could ...
CVE-2021-25324MEDIUM6.1MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.
CVE-2021-3181MEDIUM6.5rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending ...
CVE-2021-3178MEDIUM6.5fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8, when there is an NFS export of a subdirectory of a filesystem, all...
CVE-2021-20619MEDIUM6.1Cross-site scripting vulnerability in GROWI (v4.2 Series) versions prior to v4.2.3 allows remote attackers to inject an ...
CVE-2021-25295MEDIUM6.1OpenCATS through 0.9.5-3 has multiple Cross-site Scripting (XSS) issues.
CVE-2021-21250MEDIUM6.5OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which may lea...
CVE-2021-0221MEDIUM6.5In an EVPN/VXLAN scenario, if an IRB interface with a virtual gateway address (VGA) is configured on a PE, a traffic loo...
CVE-2021-0220MEDIUM6.8The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be e...
CVE-2021-0219MEDIUM6.7A command injection vulnerability in install package validation subsystem of Juniper Networks Junos OS that may allow a ...
CVE-2021-0215MEDIUM6.5On Juniper Networks Junos EX series, QFX Series, MX Series and SRX branch series devices, a memory leak occurs every tim...
CVE-2021-0212MEDIUM5An Information Exposure vulnerability in Juniper Networks Contrail Networking allows a locally authenticated attacker ab...
CVE-2021-0210MEDIUM6.8An Information Exposure vulnerability in J-Web of Juniper Networks Junos OS allows an unauthenticated attacker to elevat...
CVE-2021-0209MEDIUM6.5In Juniper Networks Junos OS Evolved an attacker sending certain valid BGP update packets may cause Junos OS Evolved to ...
CVE-2021-0205MEDIUM5.8When the "Intrusion Detection Service" (IDS) feature is configured on Juniper Networks MX series with a dynamic firewall...
CVE-2021-22171MEDIUM6.5Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a vict...
CVE-2021-22168MEDIUM6.5A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now