2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-31786 | MEDIUM | 6.5 | 0.4% | Sep 7, 2021 | The Bluetooth Classic Audio implementation on Actions ATS2815 and ATS2819 devices does not properly handle a connection ... |
| CVE-2021-31785 | MEDIUM | 6.5 | 0.4% | Sep 7, 2021 | The Bluetooth Classic implementation on Actions ATS2815 and ATS2819 chipsets does not properly handle the reception of m... |
| CVE-2021-31612 | MEDIUM | 6.5 | 0.5% | Sep 7, 2021 | The Bluetooth Classic implementation on Zhuhai Jieli AC690X devices does not properly handle the reception of an oversiz... |
| CVE-2021-31611 | MEDIUM | 5.7 | 0.4% | Sep 7, 2021 | The Bluetooth Classic implementation on Zhuhai Jieli AC690X and AC692X devices does not properly handle an out-of-order ... |
| CVE-2021-31610 | MEDIUM | 6.5 | 0.5% | Sep 7, 2021 | The Bluetooth Classic implementation on AB32VG1 devices does not properly handle the reception of continuous unsolicited... |
| CVE-2021-31609 | MEDIUM | 6.5 | 0.4% | Sep 7, 2021 | The Bluetooth Classic implementation in Silicon Labs iWRAP 6.3.0 and earlier does not properly handle the reception of a... |
| CVE-2021-28139 | HIGH | 8.8 | 1.3% | Sep 7, 2021 | The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly restrict the Feature Page up... |
| CVE-2021-39279 | HIGH | 8.8 | 4.6% | Sep 7, 2021 | Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP. This affects WAC-2004 1.7, WAC-100... |
| CVE-2021-39278 | MEDIUM | 6.1 | 0.9% | Sep 7, 2021 | Certain MOXA devices allow reflected XSS via the Config Import menu. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T... |
| CVE-2021-38841 | HIGH | 8.8 | 3.8% | Sep 7, 2021 | Remote Code Execution can occur in Simple Water Refilling Station Management System 1.0 via the System Logo option on th... |
| CVE-2021-38840 | CRITICAL | 9.8 | 2.5% | Sep 7, 2021 | SQL Injection can occur in Simple Water Refilling Station Management System 1.0 via the water_refilling/classes/Login.ph... |
| CVE-2021-34150 | MEDIUM | 6.5 | 0.4% | Sep 7, 2021 | The Bluetooth Classic implementation on Bluetrum AB5301A devices with unknown firmware versions does not properly handle... |
| CVE-2021-34144 | MEDIUM | 6.5 | 0.7% | Sep 7, 2021 | The Bluetooth Classic implementation in the Zhuhai Jieli AC6366C BT SDK through 0.9.1 does not properly handle the recep... |
| CVE-2021-33831 | MEDIUM | 6.5 | 2.0% | Sep 7, 2021 | api/account/register in the TH Wildau COVID-19 Contact Tracing application through 2021-09-01 has Incorrect Access Contr... |
| CVE-2021-31613 | MEDIUM | 6.5 | 0.6% | Sep 7, 2021 | The Bluetooth Classic implementation on Zhuhai Jieli AC690X and AC692X devices does not properly handle the reception of... |
| CVE-2021-28155 | MEDIUM | 6.5 | 0.4% | Sep 7, 2021 | The Bluetooth Classic implementation on JBL TUNE500BT devices does not properly handle the reception of continuous unsol... |
| CVE-2021-28136 | MEDIUM | 6.5 | 0.8% | Sep 7, 2021 | The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of mult... |
| CVE-2021-28135 | MEDIUM | 6.5 | 0.8% | Sep 7, 2021 | The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of cont... |
| CVE-2021-33484 | HIGH | 7.5 | 0.9% | Sep 7, 2021 | An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. An attacker can download a copy of the in... |
| CVE-2021-33483 | MEDIUM | 5.4 | 0.6% | Sep 7, 2021 | An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. The comment posting functionality allows ... |
| CVE-2021-40540 | CRITICAL | 9.8 | 2.5% | Sep 7, 2021 | ulfius_uri_logger in Ulfius HTTP Framework before 2.7.4 omits con_info initialization and a con_info->request NULL check... |
| CVE-2021-40532 | CRITICAL | 9.8 | 1.1% | Sep 6, 2021 | Telegram Web K Alpha before 0.7.2 mishandles the characters in a document extension. |
| CVE-2021-40531 | CRITICAL | 9.8 | 32.8% | Sep 6, 2021 | Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opene... |
| CVE-2021-40530 | MEDIUM | 5.9 | 1.1% | Sep 6, 2021 | The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interaction between two cry... |
| CVE-2021-40529 | MEDIUM | 5.9 | 1.5% | Sep 6, 2021 | The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now