2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-31786MEDIUM6.5The Bluetooth Classic Audio implementation on Actions ATS2815 and ATS2819 devices does not properly handle a connection ...
CVE-2021-31785MEDIUM6.5The Bluetooth Classic implementation on Actions ATS2815 and ATS2819 chipsets does not properly handle the reception of m...
CVE-2021-31612MEDIUM6.5The Bluetooth Classic implementation on Zhuhai Jieli AC690X devices does not properly handle the reception of an oversiz...
CVE-2021-31611MEDIUM5.7The Bluetooth Classic implementation on Zhuhai Jieli AC690X and AC692X devices does not properly handle an out-of-order ...
CVE-2021-31610MEDIUM6.5The Bluetooth Classic implementation on AB32VG1 devices does not properly handle the reception of continuous unsolicited...
CVE-2021-31609MEDIUM6.5The Bluetooth Classic implementation in Silicon Labs iWRAP 6.3.0 and earlier does not properly handle the reception of a...
CVE-2021-28139HIGH8.8The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly restrict the Feature Page up...
CVE-2021-39279HIGH8.8Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP. This affects WAC-2004 1.7, WAC-100...
CVE-2021-39278MEDIUM6.1Certain MOXA devices allow reflected XSS via the Config Import menu. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T...
CVE-2021-38841HIGH8.8Remote Code Execution can occur in Simple Water Refilling Station Management System 1.0 via the System Logo option on th...
CVE-2021-38840CRITICAL9.8SQL Injection can occur in Simple Water Refilling Station Management System 1.0 via the water_refilling/classes/Login.ph...
CVE-2021-34150MEDIUM6.5The Bluetooth Classic implementation on Bluetrum AB5301A devices with unknown firmware versions does not properly handle...
CVE-2021-34144MEDIUM6.5The Bluetooth Classic implementation in the Zhuhai Jieli AC6366C BT SDK through 0.9.1 does not properly handle the recep...
CVE-2021-33831MEDIUM6.5api/account/register in the TH Wildau COVID-19 Contact Tracing application through 2021-09-01 has Incorrect Access Contr...
CVE-2021-31613MEDIUM6.5The Bluetooth Classic implementation on Zhuhai Jieli AC690X and AC692X devices does not properly handle the reception of...
CVE-2021-28155MEDIUM6.5The Bluetooth Classic implementation on JBL TUNE500BT devices does not properly handle the reception of continuous unsol...
CVE-2021-28136MEDIUM6.5The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of mult...
CVE-2021-28135MEDIUM6.5The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of cont...
CVE-2021-33484HIGH7.5An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. An attacker can download a copy of the in...
CVE-2021-33483MEDIUM5.4An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. The comment posting functionality allows ...
CVE-2021-40540CRITICAL9.8ulfius_uri_logger in Ulfius HTTP Framework before 2.7.4 omits con_info initialization and a con_info->request NULL check...
CVE-2021-40532CRITICAL9.8Telegram Web K Alpha before 0.7.2 mishandles the characters in a document extension.
CVE-2021-40531CRITICAL9.8Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opene...
CVE-2021-40530MEDIUM5.9The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interaction between two cry...
CVE-2021-40529MEDIUM5.9The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now