2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-2002 | MEDIUM | 4.9 | 2.6% | Jan 20, 2021 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are ... |
| CVE-2021-2001 | MEDIUM | 4.9 | 2.2% | Jan 20, 2021 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af... |
| CVE-2021-2000 | LOW | 2.4 | 0.8% | Jan 20, 2021 | Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 12.1.0.... |
| CVE-2021-1999 | MEDIUM | 5 | 0.3% | Jan 20, 2021 | Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: RAS subsystems). The support... |
| CVE-2021-1998 | LOW | 3.8 | 1.6% | Jan 20, 2021 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af... |
| CVE-2021-1997 | HIGH | 8.1 | 1.3% | Jan 20, 2021 | Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (compon... |
| CVE-2021-1996 | LOW | 2.4 | 1.3% | Jan 20, 2021 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported ver... |
| CVE-2021-1995 | MEDIUM | 6.5 | 1.5% | Jan 20, 2021 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported ver... |
| CVE-2021-1994 | CRITICAL | 9.8 | 5.5% | Jan 20, 2021 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported ver... |
| CVE-2021-1993 | MEDIUM | 4.8 | 0.8% | Jan 20, 2021 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.... |
| CVE-2021-3110 | CRITICAL | 9.8 | 20.7% | Jan 20, 2021 | The store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller... |
| CVE-2021-23326 | HIGH | 8.8 | 2.8% | Jan 20, 2021 | This affects the package @graphql-tools/git-loader before 6.2.6. The use of exec and execSync in packages/loaders/git/sr... |
| CVE-2021-3137 | MEDIUM | 5.4 | 0.7% | Jan 20, 2021 | XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section. |
| CVE-2021-21263 | MEDIUM | 5.3 | 1.6% | Jan 19, 2021 | Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding ex... |
| CVE-2021-20190 | HIGH | 8.1 | 7.5% | Jan 19, 2021 | A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets... |
| CVE-2021-3184 | MEDIUM | 6.1 | 0.8% | Jan 19, 2021 | MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button. |
| CVE-2021-25325 | MEDIUM | 6.1 | 0.8% | Jan 19, 2021 | MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could ... |
| CVE-2021-25324 | MEDIUM | 6.1 | 0.8% | Jan 19, 2021 | MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp. |
| CVE-2021-25323 | CRITICAL | 9.1 | 1.3% | Jan 19, 2021 | The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the p... |
| CVE-2021-22498 | HIGH | 8.1 | 1.0% | Jan 19, 2021 | XML External Entity Injection vulnerability in Micro Focus Application Lifecycle Management (Previously known as Quality... |
| CVE-2021-3183 | HIGH | 7.5 | 1.2% | Jan 19, 2021 | Files.com Fat Client 3.3.6 allows authentication bypass because the client continues to have access after a logout and a... |
| CVE-2021-3182 | HIGH | 8 | 0.9% | Jan 19, 2021 | D-Link DCS-5220 devices have a buffer overflow. NOTE: This vulnerability only affects products that are no longer suppor... |
| CVE-2021-3181 | MEDIUM | 6.5 | 2.8% | Jan 19, 2021 | rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending ... |
| CVE-2021-22852 | HIGH | 8.8 | 1.0% | Jan 19, 2021 | HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (o... |
| CVE-2021-22851 | CRITICAL | 9.8 | 1.2% | Jan 19, 2021 | HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (d... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now