2021 CVE Vulnerabilities
23,464 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-2333 | MEDIUM | 4.9 | 0.9% | Jul 21, 2021 | Vulnerability in the Oracle XML DB component of Oracle Database Server. Supported versions that are affected are 12.1.0.... |
| CVE-2021-2330 | MEDIUM | 4.3 | 0.8% | Jul 21, 2021 | Vulnerability in the Core RDBMS component of Oracle Database Server. The supported version that is affected is 19c. Easi... |
| CVE-2021-2329 | HIGH | 7.2 | 1.0% | Jul 21, 2021 | Vulnerability in the Oracle XML DB component of Oracle Database Server. Supported versions that are affected are 12.1.0.... |
| CVE-2021-2328 | HIGH | 7.2 | 1.0% | Jul 21, 2021 | Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 12.1.0.2,... |
| CVE-2021-2326 | LOW | 2.7 | 0.8% | Jul 21, 2021 | Vulnerability in the Database Vault component of Oracle Database Server. Supported versions that are affected are 12.2.0... |
| CVE-2021-2324 | MEDIUM | 4.6 | 0.5% | Jul 21, 2021 | Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Loa... |
| CVE-2021-2323 | MEDIUM | 5.9 | 1.3% | Jul 21, 2021 | Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Fle... |
| CVE-2021-32751 | HIGH | 7.5 | 2.7% | Jul 20, 2021 | Gradle is a build tool with a focus on build automation. In versions prior to 7.2, start scripts generated by the `appli... |
| CVE-2021-36747 | MEDIUM | 5.4 | 0.6% | Jul 20, 2021 | Blackboard Learn through 9.1 allows XSS by an authenticated user via the Feedback to Learner form. |
| CVE-2021-36746 | MEDIUM | 5.4 | 0.6% | Jul 20, 2021 | Blackboard Learn through 9.1 allows XSS by an authenticated user via the Assignment Instructions HTML editor. |
| CVE-2021-36230 | HIGH | 8.8 | 1.0% | Jul 20, 2021 | HashiCorp Terraform Enterprise releases up to v202106-1 did not properly perform authorization checks on a subset of API... |
| CVE-2021-33910 | MEDIUM | 5.5 | 8.6% | Jul 20, 2021 | basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Val... |
| CVE-2021-33909 | HIGH | 7.8 | 9.8% | Jul 20, 2021 | fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, l... |
| CVE-2021-32763 | MEDIUM | 6.5 | 0.9% | Jul 20, 2021 | OpenProject is open-source, web-based project management software. In versions prior to 11.3.3, the `MessagesController`... |
| CVE-2021-20478 | LOW | 3.3 | 0.2% | Jul 20, 2021 | IBM Cloud Pak System 2.3 could allow a local user in some situations to view the artifacts of another user in self servi... |
| CVE-2021-32767 | MEDIUM | 6.5 | 0.8% | Jul 20, 2021 | TYPO3 is an open source PHP based web content management system. In versions 9.0.0 through 9.5.27, 10.0.0 through 10.4.1... |
| CVE-2021-32669 | MEDIUM | 5.4 | 0.6% | Jul 20, 2021 | TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, ... |
| CVE-2021-3246 | HIGH | 8.8 | 3.3% | Jul 20, 2021 | A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary ... |
| CVE-2021-32668 | MEDIUM | 4.8 | 0.6% | Jul 20, 2021 | TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, ... |
| CVE-2021-32667 | MEDIUM | 5.4 | 0.6% | Jul 20, 2021 | TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, ... |
| CVE-2021-27517 | MEDIUM | 6.1 | 0.8% | Jul 20, 2021 | Foxit PDF SDK For Web through 7.5.0 allows XSS. There is arbitrary JavaScript code execution in the browser if a victim ... |
| CVE-2021-27338 | MEDIUM | 5.4 | 0.7% | Jul 20, 2021 | Faraday Edge before 3.7 allows XSS via the network/create/ page and its network name parameter. |
| CVE-2021-22235 | HIGH | 7.5 | 3.3% | Jul 20, 2021 | Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or ... |
| CVE-2021-32463 | HIGH | 7.8 | 0.4% | Jul 20, 2021 | An incorrect permission assignment denial-of-service vulnerability in Trend Micro Apex One, Apex One as a Service (SaaS)... |
| CVE-2021-27021 | HIGH | 8.8 | 1.3% | Jul 20, 2021 | A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tab... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now