2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-26765CRITICAL9.8SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL sta...
CVE-2021-35522CRITICAL9.8A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2, Sigma de...
CVE-2021-37155CRITICAL9.8wolfSSL 4.6.x through 4.7.x before 4.8.0 does not produce a failure outcome when the serial number in an OCSP request di...
CVE-2021-2447CRITICAL9.9Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server). The supported ve...
CVE-2021-2446CRITICAL9.6Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Client). The supported ve...
CVE-2021-2397CRITICAL9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th...
CVE-2021-2394CRITICAL9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th...
CVE-2021-2382CRITICAL9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Security). Supported version...
CVE-2021-2355CRITICAL9.1Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supporte...
CVE-2021-22772CRITICAL9.8A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T200 ((Modbus) SC2-04MOD-0700010...
CVE-2021-22730CRITICAL9.8A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to...
CVE-2021-22729CRITICAL9.8A CWE-259: Use of Hard-coded Password vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8...
CVE-2021-22727CRITICAL9.8A CWE-331: Insufficient Entropy vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4....
CVE-2021-22707CRITICAL9.8A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to...
CVE-2021-2463CRITICAL9.8Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supp...
CVE-2021-2456CRITICAL9.8Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ana...
CVE-2021-20110CRITICAL9.8Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can stati...
CVE-2021-35965CRITICAL9.8The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the so...
CVE-2021-35964CRITICAL9.8The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remot...
CVE-2021-35963CRITICAL9.8The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which a...
CVE-2021-33501CRITICAL9.6Overwolf Client 0.169.0.22 allows XSS, with resultant Remote Code Execution, via an overwolfstore:// URL.
CVE-2021-33027CRITICAL9.8Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce.
CVE-2021-33592CRITICAL9.8NAVER Toolbar before 4.0.30.323 allows remote attackers to execute arbitrary code via a crafted upgrade.xml file. Specia...
CVE-2021-33911CRITICAL9.8Zoho ManageEngine ADManager Plus before 7110 allows remote code execution.
CVE-2021-34458CRITICAL9.9Windows Kernel Remote Code Execution Vulnerability

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now