Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
cve-2021-2109 vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv2
CVE-2021-2109
Weblogic Remote Code Execution involving HTTP protocol and JNDI injection gadget...
Oracle Weblogic Server 10.3.6.0.0
Oracle Weblogic Server 12.1.3.0.0
Oracle Weblogic Server 12.2.1.3.0
Oracle Weblogic Server 12.2.1.4.0
Oracle Weblogic Server 14.1.1.0.0
4 Github repositories available
7.5
CVSSv2
CVE-2020-14750
Remote code execution vulnerability in Oracle WebLogic Server. This vulnerability is related to CVE-2020-14882, which was addressed in the October 2020 Critical Patch Update. It is remotely exploitable without authentication, i.e., may be exploited over a network without the...
Oracle Fusion Middleware 10.3.6.0
Oracle Fusion Middleware 12.1.3.0
Oracle Fusion Middleware 12.2.1.3.0
Oracle Fusion Middleware 12.2.1.4.0
Oracle Fusion Middleware 14.1.1.0.0
8 Github repositories available
3 Articles available
7.5
CVSSv2
CVE-2021-1994
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to...
Oracle Enterprise Repository 11.1.1.7.0
Oracle Weblogic Server 10.3.6.0.0
Oracle Weblogic Server 12.1.3.0.0
1 Github repository available
7.5
CVSSv2
CVE-2021-2047
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker...
Oracle Weblogic Server 10.3.6.0.0
Oracle Weblogic Server 12.1.3.0.0
Oracle Weblogic Server 12.2.1.3.0
Oracle Weblogic Server 12.2.1.4.0
Oracle Weblogic Server 14.1.1.0.0
1 Github repository available
7.5
CVSSv2
CVE-2021-2064
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). The supported version that is affected is 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise...
Oracle Weblogic Server 12.1.3.0.0
1 Github repository available
7.5
CVSSv2
CVE-2021-2108
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). The supported version that is affected is 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise...
Oracle Weblogic Server 12.1.3.0.0
1 Github repository available
7.5
CVSSv2
CVE-2021-2075
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with...
Oracle Weblogic Server 10.3.6.0.0
Oracle Weblogic Server 12.1.3.0.0
Oracle Weblogic Server 12.2.1.3.0
Oracle Weblogic Server 12.2.1.4.0
Oracle Weblogic Server 14.1.1.0.0
1 Github repository available
6.8
CVSSv2
CVE-2019-17195
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass....
Connect2id Nimbus Jose\\+jwt
2 Github repositories available
7.5
CVSSv2
CVE-2020-14756
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with...
Oracle Coherence 3.7.1.0
Oracle Coherence 12.1.3.0.0
Oracle Coherence 12.2.1.3.0
Oracle Coherence 12.2.1.4.0
Oracle Coherence 14.1.1.0.0
2 Github repositories available
5
CVSSv2
CVE-2013-2020
Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed executable, which triggers an out-of-bounds read....
Canonical Ubuntu Linux 10.04
Canonical Ubuntu Linux 11.10
Canonical Ubuntu Linux 12.04
Canonical Ubuntu Linux 12.10
Canonical Ubuntu Linux 13.04
Suse Linux Enterprise Server 11.0
Clamav Clamav 0.9
Clamav Clamav 0.90
Clamav Clamav 0.90.1
Clamav Clamav 0.90.1 P0
Clamav Clamav 0.90.2
Clamav Clamav 0.90.2 P0
Clamav Clamav 0.90.3
Clamav Clamav 0.90.3 P0
Clamav Clamav 0.90.3 P1
Clamav Clamav 0.91
Clamav Clamav 0.91.1
Clamav Clamav 0.91.2
Clamav Clamav 0.91.2 P0
Clamav Clamav 0.92
Clamav Clamav 0.92.1
Clamav Clamav 0.92 P0
Clamav Clamav 0.93
Clamav Clamav 0.93.1
Clamav Clamav 0.93.2
Clamav Clamav 0.93.3
Clamav Clamav 0.94
Clamav Clamav 0.94.1
Clamav Clamav 0.94.2
Clamav Clamav 0.95
Clamav Clamav 0.95.1
Clamav Clamav 0.95.2
Clamav Clamav 0.95.3
Clamav Clamav 0.96
Clamav Clamav 0.96.1
Clamav Clamav 0.96.2
Clamav Clamav 0.96.3
Clamav Clamav 0.96.4
Clamav Clamav 0.96.5
Clamav Clamav 0.97
Clamav Clamav 0.97.1
Clamav Clamav 0.97.2
Clamav Clamav 0.97.3
Clamav Clamav 0.97.4
Clamav Clamav 0.97.5
Clamav Clamav
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
XXE
CVE-2021-21973
mass assignment
CVE-2021-1396
CVE-2018-19518
CVE-2020-28599
deserialization
CVE-2021-1230
CVE-2021-26681
1
2
3
4
5
NEXT »