2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-43939HIGH8.8Elcomplus SmartPTT is vulnerable when a low-authenticated user can access higher level administration authorization by i...
CVE-2021-43934CRITICAL9.8Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate upload requests, enabling...
CVE-2021-43932MEDIUM6.1Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed up...
CVE-2021-43930MEDIUM4.9Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabli...
CVE-2021-41945CRITICAL9.1Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions usi...
CVE-2021-41921CRITICAL9.8novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks a...
CVE-2021-33436HIGH7.3NoMachine for Windows prior to version 6.15.1 and 7.5.2 suffer from local privilege escalation due to the lack of safe D...
CVE-2021-3523HIGH7.5A flaw was found in 3Scale APICast in versions prior to 2.11.0, where it incorrectly identified connections for reuse. T...
CVE-2021-25266LOW3.9An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from...
CVE-2021-38939MEDIUM5.3IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could be read by an user wi...
CVE-2021-38919HIGH7.5IBM QRadar SIEM 7.3, 7.4, and 7.5 in some senarios may reveal authorized service tokens to other QRadar users. IBM X-For...
CVE-2021-38878HIGH7.5IBM QRadar 7.3, 7.4, and 7.5 could allow a malicious actor to impersonate an actor due to key exchange without entity au...
CVE-2021-38874MEDIUM4.3IBM QRadar SIEM 7.3, 7.4, and 7.5 allows for users to access information across tenant and domain boundaries in some sit...
CVE-2021-38869CRITICAL9.8IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle t...
CVE-2021-34602HIGH8.8In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticate...
CVE-2021-34601CRITICAL9.8In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials. Bender charge controller CC61...
CVE-2021-34592HIGH8.8In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticate...
CVE-2021-34591HIGH7.8In Bender/ebee Charge Controllers in multiple versions are prone to Local privilege Escalation. An authenticated attacke...
CVE-2021-34590MEDIUM5.4In Bender/ebee Charge Controllers in multiple versions are prone to Cross-site Scripting. An authenticated attacker coul...
CVE-2021-34589HIGH7.5In Bender/ebee Charge Controllers in multiple versions are prone to an RFID leak. The RFID of the last charge event can ...
CVE-2021-34588HIGH8.6In Bender/ebee Charge Controllers in multiple versions are prone to unprotected data export. Backup export is protected ...
CVE-2021-34587MEDIUM5.3In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash. The URL is used as inpu...
CVE-2021-29776MEDIUM4.3IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information from another user's ...
CVE-2021-46424CRITICAL9.1Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to de...
CVE-2021-46423MEDIUM5.3Telesquare TLR-2005KSH 1.0.0 is affected by an unauthenticated file download vulnerability that allows a remote attacker...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now