CVE-2021-20000 to CVE-2021-20999
69 CVEs with public proof-of-concept exploits.
- CVE-2021-200212 PoCsKEVA vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a…
- CVE-2021-200313 PoCsA Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary…
- CVE-2021-200342 PoCsAn improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete…
- CVE-2021-200384 PoCsKEVA Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote…
- CVE-2021-200392 PoCsImproper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote…
- CVE-2021-200781 PoCManage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in…
- CVE-2021-200801 PoCInsufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800…
- CVE-2021-200811 PoCIncomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to…
- CVE-2021-200832 PoCsImproperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object 2.2.3 allows a…
- CVE-2021-200841 PoCImproperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-sparkle 1.5.2-beta allows a malicious…
- CVE-2021-200851 PoCImproperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in backbone-query-parameters 0.4.0 allows a…
- CVE-2021-200862 PoCsImproperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-bbq 1.2.1 allows a malicious user to…
- CVE-2021-200871 PoCImproperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-deparam 0.5.1 allows a malicious user…
- CVE-2021-200881 PoCImproperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in mootools-more 1.6.0 allows a malicious user…
- CVE-2021-200891 PoCImproperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in purl 2.3.2 allows a malicious user to inject…
- CVE-2021-200903 PoCsKEVA path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version…
- CVE-2021-200911 PoCThe web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly sanitize…
- CVE-2021-200921 PoCThe web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict…
- CVE-2021-200931 PoCA buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this…
- CVE-2021-200941 PoCA denial of service vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this…
- CVE-2021-200961 PoCCross-site request forgery in OpenOversight 0.6.4 allows a remote attacker to perform sensitive application actions by tricking legitimate…
- CVE-2021-201071 PoCThere exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and Flushometers…
- CVE-2021-201141 PoCWhen installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/…
- CVE-2021-201201 PoCThe administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This…
- CVE-2021-201211 PoCThe Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is vulnerable to an authenticated arbitrary file read. An…
- CVE-2021-201221 PoCThe Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is affected by an authenticated command injection vulnerability in…
- CVE-2021-201232 PoCsKEVA local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet…
- CVE-2021-201242 PoCsKEVA local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet…
- CVE-2021-201251 PoCAn arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek…
- CVE-2021-201261 PoCDraytek VigorConnect 1.6.0-B3 lacks cross-site request forgery protections and does not sufficiently verify whether a well-formed, valid,…
- CVE-2021-201271 PoCAn arbitrary file deletion vulnerability exists in the file delete functionality of the Html5Servlet endpoint of Draytek VigorConnect…
- CVE-2021-201281 PoCThe Profile Name field in the floor plan (Network Menu) page in Draytek VigorConnect 1.6.0-B3 was found to be vulnerable to stored XSS, as…
- CVE-2021-201291 PoCAn information disclosure vulnerability exists in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to export system logs.
- CVE-2021-201321 PoCQuagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 use default hard-coded credentials, which can allow a remote…
- CVE-2021-201331 PoCQuagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vulnerability that…
- CVE-2021-201341 PoCQuagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vulnerability that…
- CVE-2021-201361 PoCManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An…
- CVE-2021-201372 PoCsA reflected cross-site scripting vulnerability exists in the url parameter of the /cgi-bin/luci/site_access/ page on the Gryphon Tower…
- CVE-2021-201382 PoCsAn unauthenticated command injection vulnerability exists in multiple parameters in the Gryphon Tower router’s web interface at…
- CVE-2021-201391 PoCAn unauthenticated command injection vulnerability exists in the parameters of operation 3 in the controller_server service on Gryphon…
- CVE-2021-201401 PoCAn unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server service on Gryphon…
- CVE-2021-201411 PoCAn unauthenticated command injection vulnerability exists in the parameters of operation 32 in the controller_server service on Gryphon…
- CVE-2021-201421 PoCAn unauthenticated command injection vulnerability exists in the parameters of operation 41 in the controller_server service on Gryphon…
- CVE-2021-201431 PoCAn unauthenticated command injection vulnerability exists in the parameters of operation 48 in the controller_server service on Gryphon…
- CVE-2021-201441 PoCAn unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server service on Gryphon…
- CVE-2021-201451 PoCGryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN…
- CVE-2021-201501 PoCTrendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. Authentication can be…
- CVE-2021-201551 PoCTrendnet AC2600 TEW-827DRU version 2.08B01 makes use of hardcoded credentials. It is possible to backup and restore device configurations…
- CVE-2021-201571 PoCIt is possible for an unauthenticated, malicious user to force the device to reboot due to a hidden administrative command.
- CVE-2021-201581 PoCTrendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauthenticated,…
- CVE-2021-201591 PoCTrendnet AC2600 TEW-827DRU version 2.08B01 is vulnerable to command injection. The system log functionality of the firmware allows for…
- CVE-2021-201601 PoCTrendnet AC2600 TEW-827DRU version 2.08B01 contains a command injection vulnerability in the smb functionality of the device. The username…
- CVE-2021-201651 PoCTrendnet AC2600 TEW-827DRU version 2.08B01 does not properly implement csrf protections. Most pages lack proper usage of CSRF protections…
- CVE-2021-201671 PoCNetgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable to command…
- CVE-2021-202531 PoCA flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker to elevate the…
- CVE-2021-202801 PoCText-based feedback answers required additional sanitizing to prevent stored XSS and blind SSRF risks in moodle before 3.10.2, 3.9.5,…
- CVE-2021-202851 PoCA flaw was found in upx canPack in p_lx_elf.cpp in UPX 3.96. This flaw allows attackers to cause a denial of service (SEGV or buffer…
- CVE-2021-202941 PoCA flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a crafted file could…
- CVE-2021-203081 PoCInteger overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is…
- CVE-2021-203234 PoCsA POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.
- CVE-2021-205622 PoCsIBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_3 and 6.1.0.0 through 6.1.0.2 vulnerable to cross-site scripting.…
- CVE-2021-206171 PoCImproper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows remote attackers…
- CVE-2021-207171 PoCCross-site scripting vulnerability in EC-CUBE 4.0.0 to 4.0.5 allows a remote attacker to inject a specially crafted script in the specific…
- CVE-2021-207921 PoCCross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.1.14 allows a remote attacker to inject arbitrary script…
- CVE-2021-208378 PoCsMovable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7…
- CVE-2021-209892 PoCsFibaro Home Center Insufficient remote access server authorization
- CVE-2021-209902 PoCsFibaro Home Center Unauthenticated access to shutdown, reboot and reboot to recovery mode
- CVE-2021-209912 PoCsFibaro Home Center Authenticated remote command execution
- CVE-2021-209922 PoCsFibaro Home Center Unencrypted management interface