CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2021-31610

    Last Modified: 21 Nov 2024

    The Bluetooth Classic implementation on AB32VG1 devices does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (either restart or deadlock the device) by flooding a device with LMP_AU_rand data.

    Published: 7 Sept 2021
    6.5
    Medium

    CVE-2021-31785

    Last Modified: 21 Nov 2024

    The Bluetooth Classic implementation on Actions ATS2815 and ATS2819 chipsets does not properly handle the reception of multiple LMP_host_connection_req packets, allowing attackers in radio range to trigger a denial of service (deadlock) of the device via crafted LMP packets. Manual user intervention is required to restart the device and restore Bluetooth communication.

    Published: 7 Sept 2021
    6.5
    Medium

    CVE-2021-31786

    Last Modified: 21 Nov 2024

    The Bluetooth Classic Audio implementation on Actions ATS2815 and ATS2819 devices does not properly handle a connection attempt from a host with the same BDAddress as the current connected BT host, allowing attackers to trigger a disconnection and deadlock of the device by connecting with a forged BDAddress that matches the original connected host.

    Published: 7 Sept 2021
    5.7
    Medium

    CVE-2021-31611

    Last Modified: 21 Nov 2024

    The Bluetooth Classic implementation on Zhuhai Jieli AC690X and AC692X devices does not properly handle an out-of-order LMP Setup procedure that is followed by a malformed LMP packet, allowing attackers in radio range to deadlock a device via a crafted LMP packet. The user needs to manually reboot the device to restore communication.

    Published: 7 Sept 2021
    6.5
    Medium

    CVE-2021-31613

    Last Modified: 21 Nov 2024

    The Bluetooth Classic implementation on Zhuhai Jieli AC690X and AC692X devices does not properly handle the reception of a truncated LMP packet during the LMP auto rate procedure, allowing attackers in radio range to immediately crash (and restart) a device via a crafted LMP packet.

    Published: 7 Sept 2021
    6.5
    Medium

    CVE-2021-34150

    Last Modified: 21 Nov 2024

    The Bluetooth Classic implementation on Bluetrum AB5301A devices with unknown firmware versions does not properly handle the reception of oversized DM1 LMP packets while no other BT connections are active, allowing attackers in radio range to prevent new BT connections (disabling the AB5301A inquiry and page scan procedures) via a crafted LMP packet. The user needs to manually perform a power cycle (restart) of the device to restore BT connectivity.

    Published: 7 Sept 2021
    6.5
    Medium

    CVE-2021-28155

    Last Modified: 21 Nov 2024

    The Bluetooth Classic implementation on JBL TUNE500BT devices does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service and shutdown a device by flooding the target device with LMP Feature Response data.

    Published: 7 Sept 2021
    6.5
    Medium

    CVE-2021-28135

    Last Modified: 21 Nov 2024

    The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (crash) in ESP32 by flooding the target device with LMP Feature Response data.

    Published: 7 Sept 2021
    6.5
    Medium

    CVE-2021-34144

    Last Modified: 21 Nov 2024

    The Bluetooth Classic implementation in the Zhuhai Jieli AC6366C BT SDK through 0.9.1 does not properly handle the reception of truncated LMP_SCO_Link_Request packets while no other BT connections are active, allowing attackers in radio range to prevent new BT connections (disabling the AB5301A inquiry and page scan procedures) via a crafted LMP packet. The user needs to manually perform a power cycle (restart) of the device to restore BT connectivity.

    Published: 7 Sept 2021
    6.5
    Medium

    CVE-2021-28136

    Last Modified: 21 Nov 2024

    The Bluetooth Classic implementation in Espressif ESP-IDF 4.4 and earlier does not properly handle the reception of multiple LMP IO Capability Request packets during the pairing process, allowing attackers in radio range to trigger memory corruption (and consequently a crash) in ESP32 via a replayed (duplicated) LMP packet.

    Published: 7 Sept 2021
    8.8
    High

    CVE-2021-39279

    Last Modified: 21 Nov 2024

    Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TAP-323-US-CT-T 1.3, TAP-323-JP-CT-T 1.3, WDR-3124A-EU 2.3, WDR-3124A-EU-T 2.3, WDR-3124A-US 2.3, and WDR-3124A-US-T 2.3.

    Published: 7 Sept 2021
    6.1
    Medium

    CVE-2021-39278

    Last Modified: 21 Nov 2024

    Certain MOXA devices allow reflected XSS via the Config Import menu. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TAP-323-US-CT-T 1.3, TAP-323-JP-CT-T 1.3, WDR-3124A-EU 2.3, WDR-3124A-EU-T 2.3, WDR-3124A-US 2.3, and WDR-3124A-US-T 2.3.

    Published: 7 Sept 2021
    8.8
    High

    CVE-2021-38841

    Last Modified: 21 Nov 2024

    Remote Code Execution can occur in Simple Water Refilling Station Management System 1.0 via the System Logo option on the system_info page in classes/SystemSettings.php with an update_settings action.

    Published: 7 Sept 2021
    9.8
    Critical

    CVE-2021-38840

    Last Modified: 21 Nov 2024

    SQL Injection can occur in Simple Water Refilling Station Management System 1.0 via the water_refilling/classes/Login.php username parameter.

    Published: 7 Sept 2021
    6.5
    Medium

    CVE-2021-33831

    Last Modified: 21 Nov 2024

    api/account/register in the TH Wildau COVID-19 Contact Tracing application through 2021-09-01 has Incorrect Access Control. An attacker can interfere with tracing of infection chains by creating 500 random users within 2500 seconds.

    Published: 7 Sept 2021
    7.5
    High

    CVE-2021-33484

    Last Modified: 21 Nov 2024

    An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. An attacker can download a copy of the installer, decompile it, and discover a hardcoded IV used to encrypt the username and userid in the comment POST request. Additionally, the attacker can decrypt the encrypted encryption key (sent as a parameter in the comment form request) by setting this encrypted value as the username, which will appear on the comment page in its decrypted form. Using these two values (combined with the encryption functionality discovered in the decompiled installer), the attacker can encrypt another user's ID and username. These values can be used as part of the comment posting request in order to spoof the user.

    Published: 7 Sept 2021
    5.4
    Medium

    CVE-2021-33483

    Last Modified: 21 Nov 2024

    An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. The comment posting functionality allows an attacker to add an XSS payload to the JSON request that will execute when users visit the page with the comment.

    Published: 7 Sept 2021
    9.8
    Critical

    CVE-2021-40540

    Last Modified: 21 Nov 2024

    ulfius_uri_logger in Ulfius HTTP Framework before 2.7.4 omits con_info initialization and a con_info->request NULL check for certain malformed HTTP requests.

    Published: 7 Sept 2021
    8.8
    High

    CVE-2021-38495

    Last Modified: 21 Nov 2024

    Mozilla developers reported memory safety bugs present in Thunderbird 78.13.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 91.1 and Firefox ESR < 91.1.

    Published: 7 Sept 2021
    6.5
    Medium

    CVE-2021-38492

    Last Modified: 21 Nov 2024

    When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92, Thunderbird < 91.1, Thunderbird < 78.14, Firefox ESR < 78.14, and Firefox ESR < 91.1.

    Published: 7 Sept 2021
    8.8
    High

    CVE-2021-38493

    Last Modified: 21 Nov 2024

    Mozilla developers reported memory safety bugs present in Firefox 91 and Firefox ESR 78.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.14, Thunderbird < 78.14, and Firefox < 92.

    Published: 7 Sept 2021
    5.5
    Medium

    CVE-2021-4150

    Last Modified: 21 Nov 2024

    A use-after-free flaw was found in the add_partition in block/partitions/core.c in the Linux kernel. A local attacker with user privileges could cause a denial of service on the system. The issue results from the lack of code cleanup when device_add call fails when adding a partition to the disk.

    Published: 7 Sept 2021
    5.5
    Medium

    CVE-2022-31624

    Last Modified: 21 Nov 2024

    MariaDB Server before 10.7 is vulnerable to Denial of Service. While executing the plugin/server_audit/server_audit.c method log_statement_ex, the held lock lock_bigbuffer is not released correctly, which allows local users to trigger a denial of service due to the deadlock.

    Published: 7 Sept 2021
    5.5
    Medium

    CVE-2022-31623

    Last Modified: 21 Nov 2024

    MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_compress.cc, when an error occurs (i.e., going to the err label) while executing the method create_worker_threads, the held lock thd->ctrl_mutex is not released correctly, which allows local users to trigger a denial of service due to the deadlock. Note: The vendor argues this is just an improper locking bug and not a vulnerability with adverse effects.

    Published: 7 Sept 2021
    7.8
    High

    CVE-2021-3778

    Last Modified: 21 Nov 2024

    vim is vulnerable to Heap-based Buffer Overflow

    Published: 7 Sept 2021
    7.5
    High

    CVE-2021-41611

    Last Modified: 21 Nov 2024

    An issue was discovered in Squid 5.0.6 through 5.1.x before 5.2. When validating an origin server or peer certificate, Squid may incorrectly classify certain certificates as trusted. This problem allows a remote server to obtain security trust well improperly. This indication of trust may be passed along to clients, allowing access to unsafe or hijacked services.

    Published: 7 Sept 2021
    7.5
    High

    CVE-2020-19131

    Last Modified: 21 Nov 2024

    Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the component "tiffcrop".

    Published: 7 Sept 2021
    5.5
    Medium

    CVE-2022-31622

    Last Modified: 21 Nov 2024

    MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_compress.cc, when an error occurs (pthread_create returns a nonzero value) while executing the method create_worker_threads, the held lock is not released correctly, which allows local users to trigger a denial of service due to the deadlock. Note: The vendor argues this is just an improper locking bug and not a vulnerability with adverse effects.

    Published: 7 Sept 2021
    9.8
    Critical

    CVE-2021-40532

    Last Modified: 21 Nov 2024

    Telegram Web K Alpha before 0.7.2 mishandles the characters in a document extension.

    Published: 6 Sept 2021
    9.8
    Critical

    CVE-2021-40531

    Last Modified: 21 Nov 2024

    Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opened, without the com.apple.quarantine extended attribute. This results in remote code execution, as demonstrated by CommandString in a terminal profile to Terminal.app.

    Published: 6 Sept 2021
    6.3
    Medium

    CVE-2021-24006

    Last Modified: 21 Nov 2024

    An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authenticated attacker with a restricted user profile to access the SD-WAN Orchestrator panel via directly visiting its URL.

    Published: 6 Sept 2021
    5.9
    Medium

    CVE-2021-40529

    Last Modified: 21 Nov 2024

    The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.

    Published: 6 Sept 2021
    5.9
    Medium

    CVE-2021-40530

    Last Modified: 21 Nov 2024

    The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.

    Published: 6 Sept 2021
    4.3
    Medium

    CVE-2020-15939

    Last Modified: 21 Nov 2024

    An improper access control vulnerability (CWE-284) in FortiSandbox versions 3.2.1 and below and 3.1.4 and below may allow an authenticated, unprivileged attacker to download the device configuration file via the recovery URL.

    Published: 6 Sept 2021
    5.2
    Medium

    CVE-2021-36096

    Last Modified: 21 Nov 2024

    Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions; 8.0.x version 8.0.15 and prior versions.

    Published: 6 Sept 2021
    5.3
    Medium

    CVE-2021-36095

    Last Modified: 21 Nov 2024

    Malicious attacker is able to find out valid user logins by using the "lost password" feature. This issue affects: OTRS AG ((OTRS)) Community Edition version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.

    Published: 6 Sept 2021
    5.7
    Medium

    CVE-2021-36094

    Last Modified: 21 Nov 2024

    It's possible to craft a request for appointment edit screen, which could lead to the XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.

    Published: 6 Sept 2021
    5.3
    Medium

    CVE-2021-36093

    Last Modified: 21 Nov 2024

    It's possible to create an email which can be stuck while being processed by PostMaster filters, causing DoS. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions; 8.0.x version 8.0.15 and prior versions.

    Published: 6 Sept 2021
    7.8
    High

    CVE-2021-36744

    Last Modified: 21 Nov 2024

    Trend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an attacker to exploit the system to escalate privileges and create a denial of service.

    Published: 6 Sept 2021
    5.4
    Medium

    CVE-2021-3768

    Last Modified: 21 Nov 2024

    bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 6 Sept 2021
    5.4
    Medium

    CVE-2021-3767

    Last Modified: 21 Nov 2024

    bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    Published: 6 Sept 2021
    9.8
    Critical

    CVE-2021-3766

    Last Modified: 21 Nov 2024

    objection.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

    Published: 6 Sept 2021
    7.8
    High

    CVE-2021-32568

    Last Modified: 21 Nov 2024

    mrdoc is vulnerable to Deserialization of Untrusted Data

    Published: 6 Sept 2021
    5.4
    Medium

    CVE-2021-24611

    Last Modified: 21 Nov 2024

    The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in the page after they are saved, allowing for Cross-Site Scripting issues. Furthermore, it is also lacking any CSRF check, allowing attacker to make a logged in high privilege user save arbitrary setting via a CSRF attack.

    Published: 6 Sept 2021
    5.4
    Medium

    CVE-2021-24603

    Last Modified: 21 Nov 2024

    The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed

    Published: 6 Sept 2021
    5.4
    Medium

    CVE-2021-24601

    Last Modified: 21 Nov 2024

    The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

    Published: 6 Sept 2021
    6.1
    Medium

    CVE-2021-24599

    Last Modified: 21 Nov 2024

    The Email Encoder – Protect Email Addresses WordPress plugin before 2.1.2 has an endpoint that requires no authentication and will render a user supplied value in the HTML response without escaping or sanitizing the data.

    Published: 6 Sept 2021
    5.4
    Medium

    CVE-2021-24591

    Last Modified: 21 Nov 2024

    The Highlight WordPress plugin before 0.9.3 does not sanitise its CustomCSS setting, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

    Published: 6 Sept 2021
    5.4
    Medium

    CVE-2021-24590

    Last Modified: 21 Nov 2024

    The Cookie Notice & Consent Banner for GDPR & CCPA Compliance WordPress plugin before 1.7.2 does not properly sanitize inputs to prevent injection of arbitrary HTML within the plugin's design customization options.

    Published: 6 Sept 2021
    6.1
    Medium

    CVE-2021-24588

    Last Modified: 21 Nov 2024

    The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.

    Published: 6 Sept 2021