2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-2256 | CRITICAL | 10 | 1.7% | Apr 22, 2021 | Vulnerability in the Oracle Storage Cloud Software Appliance product of Oracle Storage Gateway (component: Management Co... |
| CVE-2021-2253 | CRITICAL | 9.1 | 1.5% | Apr 22, 2021 | Vulnerability in the Oracle Advanced Supply Chain Planning product of Oracle Supply Chain (component: Core). Supported v... |
| CVE-2021-2248 | CRITICAL | 10 | 2.5% | Apr 22, 2021 | Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server). The supported ve... |
| CVE-2021-2244 | CRITICAL | 10 | 1.8% | Apr 22, 2021 | Vulnerability in the Hyperion Analytic Provider Services product of Oracle Hyperion (component: JAPI) and Essbase Analyt... |
| CVE-2021-2221 | CRITICAL | 9.6 | 2.0% | Apr 22, 2021 | Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Client). The supported ve... |
| CVE-2021-2205 | CRITICAL | 9.1 | 1.5% | Apr 22, 2021 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supporte... |
| CVE-2021-2200 | CRITICAL | 9.1 | 1.2% | Apr 22, 2021 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Home page). The suppor... |
| CVE-2021-2177 | CRITICAL | 10 | 2.5% | Apr 22, 2021 | Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Gateway). The supported v... |
| CVE-2021-2136 | CRITICAL | 9.8 | 2.2% | Apr 22, 2021 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th... |
| CVE-2021-2135 | CRITICAL | 9.8 | 8.4% | Apr 22, 2021 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Coherence Container). Suppor... |
| CVE-2021-27389 | CRITICAL | 9.8 | 1.0% | Apr 22, 2021 | A vulnerability has been identified in Opcenter Quality (All versions < V12.2), QMS Automotive (All versions < V12.30). ... |
| CVE-2021-25669 | CRITICAL | 9.8 | 2.1% | Apr 22, 2021 | A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT (All versions <... |
| CVE-2021-25668 | CRITICAL | 9.8 | 1.6% | Apr 22, 2021 | A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT (All versions <... |
| CVE-2021-24240 | CRITICAL | 9.8 | 3.0% | Apr 22, 2021 | The Business Hours Pro WordPress plugin through 5.5.0 allows a remote attacker to upload arbitrary files using its manua... |
| CVE-2021-0268 | CRITICAL | 9.3 | 0.9% | Apr 22, 2021 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') weakness in J-web of Juniper Ne... |
| CVE-2021-0266 | CRITICAL | 9.8 | 0.9% | Apr 22, 2021 | The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacke... |
| CVE-2021-0254 | CRITICAL | 9.8 | 2.6% | Apr 22, 2021 | A buffer size validation vulnerability in the overlayd service of Juniper Networks Junos OS may allow an unauthenticated... |
| CVE-2021-0249 | CRITICAL | 9.8 | 1.8% | Apr 22, 2021 | On SRX Series devices configured with UTM services a buffer overflow vulnerability in the Packet Forwarding Engine (PFE)... |
| CVE-2021-0248 | CRITICAL | 10 | 1.0% | Apr 22, 2021 | This issue is not applicable to NFX NextGen Software. On NFX Series devices the use of Hard-coded Credentials in Juniper... |
| CVE-2021-31572 | CRITICAL | 9.8 | 1.4% | Apr 22, 2021 | The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer. |
| CVE-2021-31571 | CRITICAL | 9.8 | 1.4% | Apr 22, 2021 | The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation. |
| CVE-2021-30476 | CRITICAL | 9.8 | 1.6% | Apr 22, 2021 | HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Va... |
| CVE-2021-3287 | CRITICAL | 9.8 | 51.3% | Apr 22, 2021 | Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the ... |
| CVE-2021-29465 | CRITICAL | 9.8 | 2.0% | Apr 22, 2021 | Discord-Recon is a bot for the Discord chat service. Versions of Discord-Recon 0.0.3 and prior contain a vulnerability i... |
| CVE-2021-21426 | CRITICAL | 9.8 | 1.2% | Apr 21, 2021 | Magento-lts is a long-term support alternative to Magento Community Edition (CE). In magento-lts versions 19.4.12 and pr... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now