2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-40340 | HIGH | 7.5 | 0.7% | Jan 28, 2022 | Information Exposure vulnerability in Hitachi Energy LinkOne application, due to a misconfiguration in the ASP server ex... |
| CVE-2021-40339 | HIGH | 7.5 | 0.7% | Jan 28, 2022 | Configuration vulnerability in Hitachi Energy LinkOne application due to the lack of HTTP Headers, allows an attacker th... |
| CVE-2021-40338 | MEDIUM | 5.3 | 0.7% | Jan 28, 2022 | Hitachi Energy LinkOne product, has a vulnerability due to a web server misconfiguration, that enables debug mode and re... |
| CVE-2021-31567 | MEDIUM | 6.8 | 1.4% | Jan 28, 2022 | Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <... |
| CVE-2021-27654 | HIGH | 7.8 | 0.6% | Jan 28, 2022 | Forgotten password reset functionality for local accounts can be used to bypass local authentication checks. |
| CVE-2021-26264 | MEDIUM | 5.5 | 0.2% | Jan 28, 2022 | A specially crafted script could cause the DeltaV Distributed Control System Controllers (All Versions) to restart and c... |
| CVE-2021-23863 | MEDIUM | 6.1 | 0.6% | Jan 28, 2022 | HTML code injection vulnerability in Android Application, Bosch Video Security, version 3.2.3. or earlier, when successf... |
| CVE-2021-23174 | MEDIUM | 4.8 | 83.2% | Jan 28, 2022 | Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plug... |
| CVE-2021-22827 | HIGH | 8.8 | 1.2% | Jan 28, 2022 | A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits ... |
| CVE-2021-22826 | HIGH | 8.8 | 1.2% | Jan 28, 2022 | A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits ... |
| CVE-2021-22825 | HIGH | 8 | 0.8% | Jan 28, 2022 | A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could allow an attacker ... |
| CVE-2021-22822 | MEDIUM | 6.1 | 0.6% | Jan 28, 2022 | A CWE-79 Improper Neutralization of Input During Web Page Generation (�Cross-site Scripting�) vulnerability exists that ... |
| CVE-2021-22821 | HIGH | 8.6 | 0.8% | Jan 28, 2022 | A CWE-918 Server-Side Request Forgery (SSRF) vulnerability exists that could cause the station web server to forward req... |
| CVE-2021-22820 | CRITICAL | 9.8 | 1.1% | Jan 28, 2022 | A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized ... |
| CVE-2021-22819 | MEDIUM | 4.3 | 0.7% | Jan 28, 2022 | A CWE-1021 Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause unintended modific... |
| CVE-2021-22818 | HIGH | 7.5 | 1.0% | Jan 28, 2022 | A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to... |
| CVE-2021-22816 | HIGH | 7.5 | 0.9% | Jan 28, 2022 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a Denial of Servic... |
| CVE-2021-22815 | MEDIUM | 5.3 | 0.8% | Jan 28, 2022 | A CWE-200: Information Exposure vulnerability exists which could cause the troubleshooting archive to be accessed. Affec... |
| CVE-2021-22814 | MEDIUM | 6.1 | 0.7% | Jan 28, 2022 | A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists whic... |
| CVE-2021-22813 | MEDIUM | 6.1 | 0.7% | Jan 28, 2022 | A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that... |
| CVE-2021-22812 | MEDIUM | 6.1 | 0.7% | Jan 28, 2022 | A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that... |
| CVE-2021-22811 | MEDIUM | 6.1 | 0.7% | Jan 28, 2022 | A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that... |
| CVE-2021-22810 | MEDIUM | 6.1 | 0.7% | Jan 28, 2022 | A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that... |
| CVE-2021-22809 | MEDIUM | 5.5 | 0.6% | Jan 28, 2022 | A CWE-125:Out-of-Bounds Read vulnerability exists that could cause unintended data disclosure when a malicious *.gd1 con... |
| CVE-2021-22808 | HIGH | 7.8 | 0.9% | Jan 28, 2022 | A CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 configur... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now