2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26765 | CRITICAL | 9.8 | 2.9% | Jul 22, 2021 | SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL sta... |
| CVE-2021-35522 | CRITICAL | 9.8 | 3.7% | Jul 22, 2021 | A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2, Sigma de... |
| CVE-2021-37155 | CRITICAL | 9.8 | 1.5% | Jul 21, 2021 | wolfSSL 4.6.x through 4.7.x before 4.8.0 does not produce a failure outcome when the serial number in an OCSP request di... |
| CVE-2021-2447 | CRITICAL | 9.9 | 1.1% | Jul 21, 2021 | Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server). The supported ve... |
| CVE-2021-2446 | CRITICAL | 9.6 | 1.6% | Jul 21, 2021 | Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Client). The supported ve... |
| CVE-2021-2397 | CRITICAL | 9.8 | 1.6% | Jul 21, 2021 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th... |
| CVE-2021-2394 | CRITICAL | 9.8 | 76.6% | Jul 21, 2021 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th... |
| CVE-2021-2382 | CRITICAL | 9.8 | 1.8% | Jul 21, 2021 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Security). Supported version... |
| CVE-2021-2355 | CRITICAL | 9.1 | 1.4% | Jul 21, 2021 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supporte... |
| CVE-2021-22772 | CRITICAL | 9.8 | 1.5% | Jul 21, 2021 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T200 ((Modbus) SC2-04MOD-0700010... |
| CVE-2021-22730 | CRITICAL | 9.8 | 1.4% | Jul 21, 2021 | A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to... |
| CVE-2021-22729 | CRITICAL | 9.8 | 1.7% | Jul 21, 2021 | A CWE-259: Use of Hard-coded Password vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8... |
| CVE-2021-22727 | CRITICAL | 9.8 | 1.4% | Jul 21, 2021 | A CWE-331: Insufficient Entropy vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.... |
| CVE-2021-22707 | CRITICAL | 9.8 | 64.6% | Jul 21, 2021 | A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to... |
| CVE-2021-2463 | CRITICAL | 9.8 | 1.6% | Jul 21, 2021 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supp... |
| CVE-2021-2456 | CRITICAL | 9.8 | 81.4% | Jul 21, 2021 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ana... |
| CVE-2021-20110 | CRITICAL | 9.8 | 7.4% | Jul 19, 2021 | Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can stati... |
| CVE-2021-35965 | CRITICAL | 9.8 | 2.4% | Jul 19, 2021 | The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the so... |
| CVE-2021-35964 | CRITICAL | 9.8 | 1.1% | Jul 19, 2021 | The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remot... |
| CVE-2021-35963 | CRITICAL | 9.8 | 2.4% | Jul 19, 2021 | The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which a... |
| CVE-2021-33501 | CRITICAL | 9.6 | 7.9% | Jul 19, 2021 | Overwolf Client 0.169.0.22 allows XSS, with resultant Remote Code Execution, via an overwolfstore:// URL. |
| CVE-2021-33027 | CRITICAL | 9.8 | 1.3% | Jul 19, 2021 | Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce. |
| CVE-2021-33592 | CRITICAL | 9.8 | 2.1% | Jul 19, 2021 | NAVER Toolbar before 4.0.30.323 allows remote attackers to execute arbitrary code via a crafted upgrade.xml file. Specia... |
| CVE-2021-33911 | CRITICAL | 9.8 | 5.3% | Jul 17, 2021 | Zoho ManageEngine ADManager Plus before 7110 allows remote code execution. |
| CVE-2021-34458 | CRITICAL | 9.9 | 2.5% | Jul 16, 2021 | Windows Kernel Remote Code Execution Vulnerability |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now