2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-34816HIGH7.2An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary cod...
CVE-2021-32745MEDIUM6.1Collabora Online is a collaborative online office suite. A reflected XSS vulnerability was found in Collabora Online pri...
CVE-2021-23410Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-32744HIGH7.5Collabora Online is a collaborative online office suite. In versions prior to 4.2.17-1 and version 6.4.9-5, unauthentica...
CVE-2021-23408MEDIUM4.3This affects the package com.graphhopper:graphhopper-web-bundle before 3.2, from 4.0-pre1 and before 4.0. The URL parser...
CVE-2021-21407MEDIUM6.5Combodo iTop is an open source, web based IT Service Management tool. Prior to version 2.7.4, the CSRF token validation ...
CVE-2021-37159MEDIUM6.4hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking...
CVE-2021-37155CRITICAL9.8wolfSSL 4.6.x through 4.7.x before 4.8.0 does not produce a failure outcome when the serial number in an OCSP request di...
CVE-2021-34619HIGH8.8The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upl...
CVE-2021-34368Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2021-34367Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2021-34366Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2021-34365Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2021-2447CRITICAL9.9Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server). The supported ve...
CVE-2021-2446CRITICAL9.6Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Client). The supported ve...
CVE-2021-2445MEDIUM5.7Vulnerability in the Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). Th...
CVE-2021-2444MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af...
CVE-2021-2443HIGH7.3Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that...
CVE-2021-2442MEDIUM6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that...
CVE-2021-2441MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af...
CVE-2021-2440MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected...
CVE-2021-2439MEDIUM4.3Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: UI and Visualization). Supported version...
CVE-2021-2438MEDIUM4.3Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12....
CVE-2021-2437MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af...
CVE-2021-2436HIGH8.2Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Frame...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now