2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-2002MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are ...
CVE-2021-2001MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af...
CVE-2021-2000LOW2.4Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 12.1.0....
CVE-2021-1999MEDIUM5Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: RAS subsystems). The support...
CVE-2021-1998LOW3.8Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af...
CVE-2021-1997HIGH8.1Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (compon...
CVE-2021-1996LOW2.4Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported ver...
CVE-2021-1995MEDIUM6.5Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported ver...
CVE-2021-1994CRITICAL9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported ver...
CVE-2021-1993MEDIUM4.8Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12....
CVE-2021-3110CRITICAL9.8The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller...
CVE-2021-23326HIGH8.8This affects the package @graphql-tools/git-loader before 6.2.6. The use of exec and execSync in packages/loaders/git/sr...
CVE-2021-3137MEDIUM5.4XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.
CVE-2021-21263MEDIUM5.3Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding ex...
CVE-2021-20190HIGH8.1A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets...
CVE-2021-3184MEDIUM6.1MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button.
CVE-2021-25325MEDIUM6.1MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could ...
CVE-2021-25324MEDIUM6.1MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.
CVE-2021-25323CRITICAL9.1The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the p...
CVE-2021-22498HIGH8.1XML External Entity Injection vulnerability in Micro Focus Application Lifecycle Management (Previously known as Quality...
CVE-2021-3183HIGH7.5Files.com Fat Client 3.3.6 allows authentication bypass because the client continues to have access after a logout and a...
CVE-2021-3182HIGH8D-Link DCS-5220 devices have a buffer overflow. NOTE: This vulnerability only affects products that are no longer suppor...
CVE-2021-3181MEDIUM6.5rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending ...
CVE-2021-22852HIGH8.8HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (o...
CVE-2021-22851CRITICAL9.8HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (d...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now