CVE-2021-22000 to CVE-2021-22999
45 CVEs with public proof-of-concept exploits.
- CVE-2021-220001 PoCVMware Thinapp version 5.x prior to 5.2.10 contain a DLL hijacking vulnerability due to insecure loading of DLLs. A malicious actor with…
- CVE-2021-2200523 PoCsKEVThe vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port…
- CVE-2021-220061 PoCThe vCenter Server contains a reverse proxy bypass vulnerability due to the way the endpoints handle the URI. A malicious actor with…
- CVE-2021-220153 PoCsThe vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An…
- CVE-2021-220171 PoCKEVRhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with…
- CVE-2021-220532 PoCsApplications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code…
- CVE-2021-220543 PoCsKEVVMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to…
- CVE-2021-221191 PoCSpring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susceptible to a…
- CVE-2021-221221 PoCAn improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may…
- CVE-2021-221232 PoCsAn OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x may allow a…
- CVE-2021-221456 PoCsA memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit…
- CVE-2021-221463 PoCsAll versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the…
- CVE-2021-221752 PoCsKEVWhen requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all…
- CVE-2021-221761 PoCAn issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members…
- CVE-2021-221781 PoCAn issue has been discovered in GitLab affecting all versions starting from 13.2. Gitlab was vulnerable to SRRF attack through the…
- CVE-2021-221881 PoCAn issue has been discovered in GitLab affecting all versions starting with 13.0. Confidential issue titles in Gitlab were readable by an…
- CVE-2021-221923 PoCsAn issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 allowing unauthorized authenticated users to…
- CVE-2021-222011 PoCAn issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file could read files…
- CVE-2021-2220431 PoCsKEVImproper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing…
- CVE-2021-2220540 PoCsKEVAn issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files…
- CVE-2021-222061 PoCAn issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed that allows other…
- CVE-2021-222101 PoCAn issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API,…
- CVE-2021-222148 PoCsWhen requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all…
- CVE-2021-224481 PoCThere is an improper verification vulnerability in smartphones. Successful exploitation of this vulnerability may cause unauthorized read…
- CVE-2021-225023 PoCsKEVRemote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability…
- CVE-2021-225431 PoCImproper memory handling in Linux KVM
- CVE-2021-2255528 PoCsKEVHeap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
- CVE-2021-225572 PoCsCode execution in SLO Generator via YAML Payload
- CVE-2021-225731 PoCIncorrect signature verification on Google-oauth-java-client
- CVE-2021-226002 PoCsKEVDouble Free in net/packet/af_packet.c leading to priviledge escalation
- CVE-2021-226522 PoCsAccess to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow an unauthorized…
- CVE-2021-227071 PoCA CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1),…
- CVE-2021-228721 PoCRevive Adserver before 5.1.0 is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the publicly accessible afr.php…
- CVE-2021-228732 PoCsRevive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php…
- CVE-2021-228801 PoCThe PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS)…
- CVE-2021-228811 PoCThe Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted…
- CVE-2021-228935 PoCsKEVPulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share…
- CVE-2021-228981 PoCcurl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in…
- CVE-2021-229081 PoCA buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to…
- CVE-2021-2291116 PoCsA improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL…
- CVE-2021-229241 PoClibcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to…
- CVE-2021-229413 PoCsKEVImproper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely…
- CVE-2021-229682 PoCsA bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Concrete CMS…
- CVE-2021-2298624 PoCsKEVOn BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before…
- CVE-2021-229911 PoCKEVOn BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before…