2021 CVE Vulnerabilities
23,464 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-2334 | LOW | 3.5 | 0.7% | Jul 21, 2021 | Vulnerability in the Oracle Database - Enterprise Edition Data Redaction component of Oracle Database Server. Supported ... |
| CVE-2021-25701 | MEDIUM | 5.5 | 0.2% | Jul 21, 2021 | The fUSBHub driver in the PCoIP Software Client prior to version 21.07.0 had an error in object management during the ha... |
| CVE-2021-25699 | HIGH | 7.8 | 0.4% | Jul 21, 2021 | The OpenSSL component of the Teradici PCoIP Software Client prior to version 21.07.0 was compiled without the no-autoloa... |
| CVE-2021-25698 | HIGH | 7.8 | 0.4% | Jul 21, 2021 | The OpenSSL component of the Teradici PCoIP Standard Agent prior to version 21.07.0 was compiled without the no-autoload... |
| CVE-2021-25695 | HIGH | 7.8 | 0.3% | Jul 21, 2021 | The USB vHub in the Teradici PCOIP Software Agent prior to version 21.07.0 would accept commands from any program, which... |
| CVE-2021-23411 | MEDIUM | 6.1 | 1.2% | Jul 21, 2021 | Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the main functionality. It accepts in... |
| CVE-2021-22784 | MEDIUM | 5.7 | 12.1% | Jul 21, 2021 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that cou... |
| CVE-2021-22777 | HIGH | 7.8 | 0.9% | Jul 21, 2021 | A CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause code execution by opening a malicious... |
| CVE-2021-22774 | HIGH | 7.5 | 0.8% | Jul 21, 2021 | A CWE-759: Use of a One-Way Hash without a Salt vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions p... |
| CVE-2021-22773 | MEDIUM | 6.5 | 0.8% | Jul 21, 2021 | A CWE-620: Unverified Password Change vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8... |
| CVE-2021-22772 | CRITICAL | 9.8 | 1.5% | Jul 21, 2021 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T200 ((Modbus) SC2-04MOD-0700010... |
| CVE-2021-22771 | HIGH | 7.3 | 1.1% | Jul 21, 2021 | A CWE-1236: Improper Neutralization of Formula Elements in a CSV File vulnerability exists in Easergy T300 with firmware... |
| CVE-2021-22770 | MEDIUM | 6.5 | 1.1% | Jul 21, 2021 | A CWE-200: Information Exposure vulnerability exists in Easergy T300 with firmware V2.7.1 and older that exposes sensiti... |
| CVE-2021-22730 | CRITICAL | 9.8 | 1.4% | Jul 21, 2021 | A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to... |
| CVE-2021-22729 | CRITICAL | 9.8 | 1.7% | Jul 21, 2021 | A CWE-259: Use of Hard-coded Password vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8... |
| CVE-2021-22728 | MEDIUM | 6.5 | 1.1% | Jul 21, 2021 | A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.... |
| CVE-2021-22727 | CRITICAL | 9.8 | 1.4% | Jul 21, 2021 | A CWE-331: Insufficient Entropy vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.... |
| CVE-2021-22726 | HIGH | 8.1 | 1.0% | Jul 21, 2021 | A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions pri... |
| CVE-2021-22723 | MEDIUM | 6.1 | 0.8% | Jul 21, 2021 | A CWE-79: Improper Neutralization of Input During Web Page Generation (Cross-siteScripting) through Cross-Site Request F... |
| CVE-2021-22722 | MEDIUM | 5.4 | 0.5% | Jul 21, 2021 | A CWE-79: Improper Neutralization of Input During Web Page Generation ('Stored Cross-site Scripting') vulnerability exis... |
| CVE-2021-22721 | MEDIUM | 5.3 | 1.0% | Jul 21, 2021 | A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.... |
| CVE-2021-22708 | HIGH | 7.2 | 0.7% | Jul 21, 2021 | A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 al... |
| CVE-2021-22707 | CRITICAL | 9.8 | 64.6% | Jul 21, 2021 | A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to... |
| CVE-2021-22706 | MEDIUM | 6.1 | 0.8% | Jul 21, 2021 | A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in E... |
| CVE-2021-22146 | HIGH | 7.5 | 27.8% | Jul 21, 2021 | All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters.... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now