2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43939 | HIGH | 8.8 | 0.6% | Apr 28, 2022 | Elcomplus SmartPTT is vulnerable when a low-authenticated user can access higher level administration authorization by i... |
| CVE-2021-43934 | CRITICAL | 9.8 | 1.1% | Apr 28, 2022 | Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate upload requests, enabling... |
| CVE-2021-43932 | MEDIUM | 6.1 | 0.6% | Apr 28, 2022 | Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed up... |
| CVE-2021-43930 | MEDIUM | 4.9 | 1.0% | Apr 28, 2022 | Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabli... |
| CVE-2021-41945 | CRITICAL | 9.1 | 2.2% | Apr 28, 2022 | Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions usi... |
| CVE-2021-41921 | CRITICAL | 9.8 | 1.6% | Apr 28, 2022 | novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks a... |
| CVE-2021-33436 | HIGH | 7.3 | 0.3% | Apr 28, 2022 | NoMachine for Windows prior to version 6.15.1 and 7.5.2 suffer from local privilege escalation due to the lack of safe D... |
| CVE-2021-3523 | HIGH | 7.5 | 0.8% | Apr 27, 2022 | A flaw was found in 3Scale APICast in versions prior to 2.11.0, where it incorrectly identified connections for reuse. T... |
| CVE-2021-25266 | LOW | 3.9 | 0.2% | Apr 27, 2022 | An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from... |
| CVE-2021-38939 | MEDIUM | 5.3 | 0.8% | Apr 27, 2022 | IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could be read by an user wi... |
| CVE-2021-38919 | HIGH | 7.5 | 1.0% | Apr 27, 2022 | IBM QRadar SIEM 7.3, 7.4, and 7.5 in some senarios may reveal authorized service tokens to other QRadar users. IBM X-For... |
| CVE-2021-38878 | HIGH | 7.5 | 1.1% | Apr 27, 2022 | IBM QRadar 7.3, 7.4, and 7.5 could allow a malicious actor to impersonate an actor due to key exchange without entity au... |
| CVE-2021-38874 | MEDIUM | 4.3 | 0.7% | Apr 27, 2022 | IBM QRadar SIEM 7.3, 7.4, and 7.5 allows for users to access information across tenant and domain boundaries in some sit... |
| CVE-2021-38869 | CRITICAL | 9.8 | 0.8% | Apr 27, 2022 | IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle t... |
| CVE-2021-34602 | HIGH | 8.8 | 1.3% | Apr 27, 2022 | In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticate... |
| CVE-2021-34601 | CRITICAL | 9.8 | 1.0% | Apr 27, 2022 | In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials. Bender charge controller CC61... |
| CVE-2021-34592 | HIGH | 8.8 | 1.3% | Apr 27, 2022 | In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticate... |
| CVE-2021-34591 | HIGH | 7.8 | 0.2% | Apr 27, 2022 | In Bender/ebee Charge Controllers in multiple versions are prone to Local privilege Escalation. An authenticated attacke... |
| CVE-2021-34590 | MEDIUM | 5.4 | 0.4% | Apr 27, 2022 | In Bender/ebee Charge Controllers in multiple versions are prone to Cross-site Scripting. An authenticated attacker coul... |
| CVE-2021-34589 | HIGH | 7.5 | 0.9% | Apr 27, 2022 | In Bender/ebee Charge Controllers in multiple versions are prone to an RFID leak. The RFID of the last charge event can ... |
| CVE-2021-34588 | HIGH | 8.6 | 0.8% | Apr 27, 2022 | In Bender/ebee Charge Controllers in multiple versions are prone to unprotected data export. Backup export is protected ... |
| CVE-2021-34587 | MEDIUM | 5.3 | 0.9% | Apr 27, 2022 | In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash. The URL is used as inpu... |
| CVE-2021-29776 | MEDIUM | 4.3 | 0.6% | Apr 27, 2022 | IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information from another user's ... |
| CVE-2021-46424 | CRITICAL | 9.1 | 36.8% | Apr 27, 2022 | Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to de... |
| CVE-2021-46423 | MEDIUM | 5.3 | 1.5% | Apr 27, 2022 | Telesquare TLR-2005KSH 1.0.0 is affected by an unauthenticated file download vulnerability that allows a remote attacker... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now