2021 CVE Vulnerabilities

23,464 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-2334LOW3.5Vulnerability in the Oracle Database - Enterprise Edition Data Redaction component of Oracle Database Server. Supported ...
CVE-2021-25701MEDIUM5.5The fUSBHub driver in the PCoIP Software Client prior to version 21.07.0 had an error in object management during the ha...
CVE-2021-25699HIGH7.8The OpenSSL component of the Teradici PCoIP Software Client prior to version 21.07.0 was compiled without the no-autoloa...
CVE-2021-25698HIGH7.8The OpenSSL component of the Teradici PCoIP Standard Agent prior to version 21.07.0 was compiled without the no-autoload...
CVE-2021-25695HIGH7.8The USB vHub in the Teradici PCOIP Software Agent prior to version 21.07.0 would accept commands from any program, which...
CVE-2021-23411MEDIUM6.1Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the main functionality. It accepts in...
CVE-2021-22784MEDIUM5.7A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that cou...
CVE-2021-22777HIGH7.8A CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause code execution by opening a malicious...
CVE-2021-22774HIGH7.5A CWE-759: Use of a One-Way Hash without a Salt vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions p...
CVE-2021-22773MEDIUM6.5A CWE-620: Unverified Password Change vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8...
CVE-2021-22772CRITICAL9.8A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T200 ((Modbus) SC2-04MOD-0700010...
CVE-2021-22771HIGH7.3A CWE-1236: Improper Neutralization of Formula Elements in a CSV File vulnerability exists in Easergy T300 with firmware...
CVE-2021-22770MEDIUM6.5A CWE-200: Information Exposure vulnerability exists in Easergy T300 with firmware V2.7.1 and older that exposes sensiti...
CVE-2021-22730CRITICAL9.8A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to...
CVE-2021-22729CRITICAL9.8A CWE-259: Use of Hard-coded Password vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8...
CVE-2021-22728MEDIUM6.5A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4....
CVE-2021-22727CRITICAL9.8A CWE-331: Insufficient Entropy vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4....
CVE-2021-22726HIGH8.1A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions pri...
CVE-2021-22723MEDIUM6.1A CWE-79: Improper Neutralization of Input During Web Page Generation (Cross-siteScripting) through Cross-Site Request F...
CVE-2021-22722MEDIUM5.4A CWE-79: Improper Neutralization of Input During Web Page Generation ('Stored Cross-site Scripting') vulnerability exis...
CVE-2021-22721MEDIUM5.3A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4....
CVE-2021-22708HIGH7.2A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 al...
CVE-2021-22707CRITICAL9.8A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to...
CVE-2021-22706MEDIUM6.1A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in E...
CVE-2021-22146HIGH7.5All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters....

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now