2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-40340HIGH7.5Information Exposure vulnerability in Hitachi Energy LinkOne application, due to a misconfiguration in the ASP server ex...
CVE-2021-40339HIGH7.5Configuration vulnerability in Hitachi Energy LinkOne application due to the lack of HTTP Headers, allows an attacker th...
CVE-2021-40338MEDIUM5.3Hitachi Energy LinkOne product, has a vulnerability due to a web server misconfiguration, that enables debug mode and re...
CVE-2021-31567MEDIUM6.8Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <...
CVE-2021-27654HIGH7.8Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.
CVE-2021-26264MEDIUM5.5A specially crafted script could cause the DeltaV Distributed Control System Controllers (All Versions) to restart and c...
CVE-2021-23863MEDIUM6.1HTML code injection vulnerability in Android Application, Bosch Video Security, version 3.2.3. or earlier, when successf...
CVE-2021-23174MEDIUM4.8Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plug...
CVE-2021-22827HIGH8.8A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits ...
CVE-2021-22826HIGH8.8A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits ...
CVE-2021-22825HIGH8A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could allow an attacker ...
CVE-2021-22822MEDIUM6.1A CWE-79 Improper Neutralization of Input During Web Page Generation (�Cross-site Scripting�) vulnerability exists that ...
CVE-2021-22821HIGH8.6A CWE-918 Server-Side Request Forgery (SSRF) vulnerability exists that could cause the station web server to forward req...
CVE-2021-22820CRITICAL9.8A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized ...
CVE-2021-22819MEDIUM4.3A CWE-1021 Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause unintended modific...
CVE-2021-22818HIGH7.5A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to...
CVE-2021-22816HIGH7.5A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a Denial of Servic...
CVE-2021-22815MEDIUM5.3A CWE-200: Information Exposure vulnerability exists which could cause the troubleshooting archive to be accessed. Affec...
CVE-2021-22814MEDIUM6.1A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists whic...
CVE-2021-22813MEDIUM6.1A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that...
CVE-2021-22812MEDIUM6.1A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that...
CVE-2021-22811MEDIUM6.1A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that...
CVE-2021-22810MEDIUM6.1A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that...
CVE-2021-22809MEDIUM5.5A CWE-125:Out-of-Bounds Read vulnerability exists that could cause unintended data disclosure when a malicious *.gd1 con...
CVE-2021-22808HIGH7.8A CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 configur...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now