CVE-2021-25000 to CVE-2021-25999
229 CVEs with public proof-of-concept exploits.
- CVE-2021-250001 PoCBooster for WooCommerce < 5.4.9 - Reflected Cross-Site Scripting in General Module
- CVE-2021-250011 PoCBooster for WooCommerce < 5.4.9 - Reflected Cross-Site Scripting in Product XML Feeds Module
- CVE-2021-250021 PoCTipsacarrier < 1.5.0.5 - Unauthenticated Orders Disclosure
- CVE-2021-250033 PoCsWPCargo < 6.9.0 - Unauthenticated RCE
- CVE-2021-250041 PoCSEUR Oficial < 1.7.2 - Admin+ Arbitrary File Download
- CVE-2021-250051 PoCSEUR Oficial < 1.7.0 - Admin+ Stored Cross-Site Scripting
- CVE-2021-250061 PoCMOLIE <= 0.5 - Reflected Cross-Site Scripting
- CVE-2021-250071 PoCMOLIE <= 0.5 - Authenticated SQL Injection
- CVE-2021-250082 PoCsCode Snippets < 2.14.3 - Reflected Cross-Site Scripting
- CVE-2021-250091 PoCCorreosExpress <= 2.6.0 - Sensitive Information Disclosure
- CVE-2021-250101 PoCPost Snippets < 3.1.4 - CSRF to Stored Cross-Site Scripting
- CVE-2021-250111 PoCWP Google Map < 1.8.1 - Subscriber+ Arbitrary Post Deletion and Plugin's Settings Update
- CVE-2021-250121 PoCPz-LinkCard <= 2.4.4.4 - Reflected Cross-Site Scripting
- CVE-2021-250131 PoCQubely < 1.7.8 - Subscriber+ Arbitrary Post Deletion
- CVE-2021-250141 PoCIbtana < 1.1.4.9 - Subscriber+ Settings Update to Stored XSS
- CVE-2021-250151 PoCmyCred < 2.4 - Reflected Cross-Site Scripting
- CVE-2021-250162 PoCsChaty < 2.8.3 - Reflected Cross-Site Scripting
- CVE-2021-250171 PoCTutor LMS < 1.9.12 - Reflected Cross-Site Scripting
- CVE-2021-250181 PoCPPOM for WooCommerce < 24.0 - Subscriber+ Settings Update to Stored XSS
- CVE-2021-250191 PoCSEO Plugin by Squirrly SEO < 11.1.12 - Reflected Cross-Site Scripting
- CVE-2021-250201 PoCCAOS < 4.1.9 - Admin+ Arbitrary Folder Deletion via Path Traversal
- CVE-2021-250211 PoCOMGF < 4.5.12 - Admin+ Arbitrary Folder Deletion via Path Traversal
- CVE-2021-250221 PoCUpdraftPlus < 1.16.66 - Reflected Cross-Site Scripting
- CVE-2021-250231 PoCSpeed Booster Pack < 4.3.3.1 - Admin+ SQL Injection
- CVE-2021-250241 PoCEvent Calendar < 1.1.51 - Reflected Cross-Site Scripting
- CVE-2021-250251 PoCEvent Calendar < 1.1.51 - Subscriber+ Event Creation
- CVE-2021-250261 PoCPatreon WordPress < 1.8.2 - Admin+ Stored Cross-Site Scripting
- CVE-2021-250271 PoCPowerPack Addons for Elementor < 2.6.2 - Reflected Cross-Site Scripting
- CVE-2021-250282 PoCsEvent Tickets < 5.2.2 - Open Redirect
- CVE-2021-250291 PoCCluevo < 1.8.1 - Admin+ Stored Cross Site Scripting
- CVE-2021-250301 PoCEvents Made Easy < 2.2.36 - Subscriber+ SQL Injection
- CVE-2021-250311 PoCImage Hover Effects Ultimate < 9.7.1 - Reflected Cross-Site Scripting
- CVE-2021-250323 PoCsPublishPress Capabilities < 2.3.1 - Unauthenticated Arbitrary Options Update to Blog Compromise
- CVE-2021-250332 PoCsNoptin < 1.6.5 - Open Redirect
- CVE-2021-250341 PoCWP User < 7.0 - Reflected Cross-Site Scripting
- CVE-2021-250351 PoCBackup and Staging by WP Time Capsule < 1.22.7 - Reflected Cross-Site Scripting
- CVE-2021-250381 PoCMultisite User Sync/Unsync < 2.1.2 - Reflected Cross-Site Scripting
- CVE-2021-250391 PoCMultisite Content Copier/Updater < 2.1.0 - Reflected Cross-Site Scripting
- CVE-2021-250401 PoCBooking Calendar < 8.9.2 - Reflected Cross-Site Scripting
- CVE-2021-250411 PoCPhoto Gallery by 10Web < 1.5.68 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-250421 PoCWP Visitor Statistics (Real Time Traffic) < 5.5 - Arbitrary IP Address Exclusion to Stored XSS
- CVE-2021-250431 PoCWOOCS < 1.3.7.3 - Reflected Cross-Site Scripting
- CVE-2021-250441 PoCCryptocurrency Pricing list and Ticker <= 1.5 - Reflected Cross-Site Scripting
- CVE-2021-250451 PoCAsgaros Forum < 1.15.15 - Admin+ SQL Injection via forum_id
- CVE-2021-250461 PoCModern Events Calendar Lite < 6.2.0 - Subscriber+ Category Add Leading to Stored XSS
- CVE-2021-250471 PoC10Web Social Photo Feed < 1.4.29 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-250481 PoCKingComposer <= 2.9.6 - Subscriber+ Stored Cross-Site Scripting
- CVE-2021-250491 PoCMobile Events Manager < 1.4.4 - Admin+ Stored Cross-Site Scripting
- CVE-2021-250501 PoCRemove Footer Credit < 1.0.11 - Admin+ Stored Cross-Site Scripting
- CVE-2021-250511 PoCModal Window < 5.2.2 - RFI leading to RCE via CSRF
- CVE-2021-250522 PoCsButton Generator < 2.3.3 - RFI leading to RCE via CSRF
- CVE-2021-250531 PoCWP Coder < 2.5.2 - RFI leading to RCE via CSRF
- CVE-2021-250541 PoCWPcalc <= 2.1 - Authenticated SQL Injection
- CVE-2021-250552 PoCsFeedWordPress < 2022.0123 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-250561 PoCNinja Forms < 3.6.10 - Admin+ Stored Cross-Site Scripting
- CVE-2021-250571 PoCTranslation Exchange <= 1.0.14 - Authenticated Stored Cross-Site Scripting (XSS)
- CVE-2021-250581 PoCThe Buffer Button <= 1.0 - Authenticated Stored Cross Site Scripting (XSS)
- CVE-2021-250591 PoCDownload Plugin < 2.0.0 - Subscriber+ Website Download
- CVE-2021-250601 PoCFive Star Business Profile and Schema < 2.1.7 - Subscriber+ Page Creation & Settings Update to Stored XSS
- CVE-2021-250611 PoCWP Booking System – Booking Calendar < 2.0.15 - Authenticated Reflected Cross-Site Scripting (XSS)
- CVE-2021-250621 PoCOrders Tracking for WooCommerce < 1.1.10 - Reflected Cross-Site Scripting
- CVE-2021-250632 PoCsContact Form 7 Skins < 2.5.1 - Reflected Cross-Site Scripting (XSS)
- CVE-2021-250641 PoCWow Countdowns <= 3.1.2 - Admin+ SQLi
- CVE-2021-250652 PoCsSmash Balloon Social Post Feed < 4.1.1 - Authenticated Reflected Cross-Site Scripting (XSS)
- CVE-2021-250661 PoCNinja Forms < 3.6.10 - Admin+ Stored Cross-Site Scripting via Import
- CVE-2021-250673 PoCsLanding Page Builder < 1.4.9.6 - Authenticated Reflected Cross-Site Scripting (XSS)
- CVE-2021-250681 PoCSync WooCommerce Product feed to Google Shopping <= 1.2.4 - Admin+ SQLi
- CVE-2021-250691 PoCWordPress Download Manager < 3.2.34 - Authenticated SQL Injection to Reflected XSS
- CVE-2021-250701 PoCWP Block and Stop Bad Bots < 6.88 - Unauthenticated SQLi
- CVE-2021-250711 PoCAkismet Privacy Policies <= 2.0.1 - Reflected Cross-Site Scripting
- CVE-2021-250721 PoCNextScripts: Social Networks Auto-Poster < 4.3.25 - Arbitrary Post Deletion via CSRF
- CVE-2021-250731 PoCWP125 < 1.5.5 - Arbitrary Ad Deletion via CSRF
- CVE-2021-250742 PoCsWebP Converter for Media < 4.0.3 - Unauthenticated Open redirect
- CVE-2021-250752 PoCsDuplicate Page or Post < 1.5.1 - Arbitrary Settings Update to Stored XSS
- CVE-2021-250767 PoCsWP User Frontend < 3.5.26 - SQL Injection to Reflected Cross-Site Scripting
- CVE-2021-250771 PoCStore Toolkit for WooCommerce < 2.3.2 - Reflected Cross-Site Scripting
- CVE-2021-250782 PoCsAffiliates Manager < 2.9.0 - Unauthenticated Stored Cross-Site Scripting
- CVE-2021-250792 PoCsContact Form Entries < 1.2.4 - Reflected Cross-Site Scripting
- CVE-2021-250801 PoCContact Form Entries < 1.1.7 - Unauthenticated Stored Cross-Site Scripting
- CVE-2021-250811 PoCWP Google Map < 1.8.4 - Arbitrary Post Deletion and Plugin's Settings Update via CSRF
- CVE-2021-250822 PoCsPopup Builder < 4.0.7 - LFI to RCE
- CVE-2021-250831 PoCRegistrations for the Events Calendar < 2.7.10 - Reflected Cross-Site Scripting
- CVE-2021-250841 PoCAdvanced Cron Manager - Subscriber+ Arbitrary Events/Schedules Creation/Deletion
- CVE-2021-250852 PoCsWOOF - Products Filter for WooCommerce < 1.2.6.3 - Reflected Cross-Site Scripting
- CVE-2021-250861 PoCAdvanced Page Visit Counter < 6.1.2 - Unauthenticated Stored Cross-Site Scripting
- CVE-2021-250871 PoCWordpress Download Manager < 3.2.25 - Sensitive Information Disclosure
- CVE-2021-250881 PoCGoogle XML Sitemaps < 4.1.3 - Admin+ Stored Cross-Site Scripting
- CVE-2021-250891 PoCUpdraftPlus < 1.16.69 - Reflected Cross-Site Scripting
- CVE-2021-250901 PoCGridKit Portfolio < 2.1.0 - Subscriber+ Stored Cross-Site Scripting
- CVE-2021-250911 PoCLink Library < 7.2.9 - Reflected Cross-Site Scripting
- CVE-2021-250931 PoCLink Library < 7.2.8 - Unauthenticated Arbitrary Links Deletion
- CVE-2021-250949 PoCsTatsu < 3.3.12 - Unauthenticated RCE
- CVE-2021-250951 PoCIP2Location Country Blocker < 2.26.5 - Subscriber+ Arbitrary Country Ban
- CVE-2021-250961 PoCIP2Location Country Blocker < 2.26.5 - Ban Bypass
- CVE-2021-250981 PoCEasy Pricing Tables < 3.1.3 - Arbitrary Post Removal via CSRF
- CVE-2021-250992 PoCsGive < 2.17.3 - Unauthenticated Reflected Cross-Site Scripting
- CVE-2021-251001 PoCGive < 2.17.3 - Reflected Cross-Site Scripting via Donation Forms Dashboard
- CVE-2021-251011 PoCAnti-Malware Security and Brute-Force Firewall < 4.20.94 - Admin+ Reflected Cross-Site Scripting
- CVE-2021-251021 PoCAll In One WP Security < 4.4.11 - Authenticated Reflected Cross-Site Scripting
- CVE-2021-251031 PoCGTranslate < 2.9.7 - Reflected Cross-Site Scripting
- CVE-2021-251042 PoCsOcean Extra < 1.9.5 - Reflected Cross-Site Scripting
- CVE-2021-251051 PoCIvory Search < 5.4.1 - Multiple Admin+ Stored Cross-Site Scripting
- CVE-2021-251061 PoCWPLegalPages < 2.7.1 - Subscriber+ Arbitrary Settings Update to Stored XSS
- CVE-2021-251071 PoCForm Store to DB < 1.1.1 - Unauthenticated Stored Cross-Site Scripting
- CVE-2021-251081 PoCIP2Location Country Blocker < 2.26.6 - Arbitrary Country Ban via CSRF
- CVE-2021-251091 PoCFuturio Extra < 1.6.3 - Authenticated SQL Injection
- CVE-2021-251101 PoCFuturio Extra < 1.6.3 - Subscriber+ User Email Address Disclosure
- CVE-2021-251112 PoCsEnglish WordPress Admin < 1.5.2 - Unauthenticated Open Redirect
- CVE-2021-251122 PoCsWHMCS Bridge < 6.4b - Reflected Cross-Site Scripting (XSS)
- CVE-2021-251131 PoCDropdown Menu Widget <= 1.9.7 - Subscriber+ Arbitrary Settings Update to Stored XSS
- CVE-2021-251142 PoCsPaid Memberships Pro < 2.6.7 - Unauthenticated Blind SQL Injection
- CVE-2021-251151 PoCWP Photo Album Plus < 8.0.10 - Stored Cross-Site Scripting (XSS)
- CVE-2021-251161 PoCEnqueue Anything <= 1.0.1 - Subscriber+ Arbitrary Asset/Post Deletion
- CVE-2021-251171 PoCWP Postratings < 1.86.1 - Admin+ Stored Cross-Site Scripting
- CVE-2021-251182 PoCsYoast SEO 16.7-17.2 - Unauthenticated Full Path Disclosure
- CVE-2021-251191 PoCAGIL <= 1.0 - Admin+ Arbitrary File Upload
- CVE-2021-251202 PoCsEasy Social Feed < 6.2.7 - Reflected Cross-Site Scripting
- CVE-2021-251211 PoCRating by BestWebSoft < 1.6 - Rating Denial of Service
- CVE-2021-251552 PoCsA remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba…
- CVE-2021-251562 PoCsA remote arbitrary directory create vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba…
- CVE-2021-251572 PoCsA remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant…
- CVE-2021-251582 PoCsA remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant…
- CVE-2021-251592 PoCsA remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba…
- CVE-2021-251601 PoCA remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba…
- CVE-2021-251613 PoCsA remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba…
- CVE-2021-251624 PoCsA remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s):…
- CVE-2021-252531 PoCAn improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a resource…
- CVE-2021-252731 PoCStored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706.
- CVE-2021-252771 PoCFTAPI 4.0 - 4.10 allows XSS via a crafted filename to the alternative text hover box in the file submission component.
- CVE-2021-252815 PoCsAn issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client.…
- CVE-2021-252826 PoCsAn issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory…
- CVE-2021-252966 PoCsKEVNagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file…
- CVE-2021-252976 PoCsKEVNagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file…
- CVE-2021-252986 PoCsKEVNagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file…
- CVE-2021-252993 PoCsNagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file…
- CVE-2021-253102 PoCsThe administration web interface on Belkin Linksys WRT160NL 1.0.04.002_US_20130619 devices allows remote authenticated attackers to…
- CVE-2021-253141 PoChawk: Insecure file permissions
- CVE-2021-253161 PoCLocal DoS of VM live migration due to use of static tmp files in detach_disks.sh in s390-tools
- CVE-2021-253263 PoCsSkyworth Digital Technology RN510 V.3.1.0.4 is affected by an incorrect access control vulnerability in/cgi-bin/test_version.asp. If Wi-Fi…
- CVE-2021-253272 PoCsSkyworth Digital Technology RN510 V.3.1.0.4 contains a cross-site request forgery (CSRF) vulnerability in /cgi-bin/net-routeadd.asp and…
- CVE-2021-253283 PoCsSkyworth Digital Technology RN510 V.3.1.0.4 RN510 V.3.1.0.4 contains a buffer overflow vulnerability in /cgi-bin/app-staticIP.asp. An…
- CVE-2021-253561 PoCAn improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged application to install…
- CVE-2021-253743 PoCsAn improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and…
- CVE-2021-253901 PoCIntent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.
- CVE-2021-253911 PoCIntent redirection vulnerability in Secure Folder prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.
- CVE-2021-253921 PoCImproper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers to get sensitive…
- CVE-2021-253931 PoCImproper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get permissions to…
- CVE-2021-253971 PoCAn improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of…
- CVE-2021-254101 PoCImproper access control of a component in CallBGProvider prior to SMR JUN-2021 Release 1 allows local attackers to access arbitrary files…
- CVE-2021-254131 PoCImproper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to get permissions to…
- CVE-2021-254141 PoCImproper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to copy or overwrite…
- CVE-2021-254261 PoCImproper component protection vulnerability in SmsViewerActivity of Samsung Message prior to SMR July-2021 Release 1 allows untrusted…
- CVE-2021-254401 PoCImproper access control vulnerability in FactoryCameraFB prior to version 3.4.74 allows untrusted applications to access arbitrary files…
- CVE-2021-254441 PoCAn IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileged process.
- CVE-2021-254611 PoCAn improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer Overflow.
- CVE-2021-254901 PoCA keyblob downgrade attack in keymaster prior to SMR Oct-2021 Release 1 allows attacker to trigger IV reuse vulnerability with privileged…
- CVE-2021-256311 PoCdenylist of executable filename extensions possible to bypass under windows
- CVE-2021-256412 PoCsDubbo Zookeeper does not check serialization id
- CVE-2021-256421 PoCApache Hadoop YARN remote code execution in ZKConfigurationStore of capacity scheduler
- CVE-2021-2564621 PoCsAuthenticated users can override system configurations in their requests which allows them to execute arbitrary code.
- CVE-2021-256793 PoCsThe AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues. These issues impact…
- CVE-2021-256803 PoCsThe AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These issues impact at…
- CVE-2021-256813 PoCsAdTran Personal Phone Manager 10.8.1 software is vulnerable to an issue that allows for exfiltration of data over DNS. This could allow…
- CVE-2021-256821 PoCapport improperly parses /proc/pid/status
- CVE-2021-256831 PoCapport improperly parses /proc/pid/stat
- CVE-2021-256841 PoCapport can be stalled by reading a FIFO
- CVE-2021-257352 PoCsValidating Admission Webhook does not observe some previous fields
- CVE-2021-257414 PoCsSymlink Exchange Can Allow Host Filesystem Access
- CVE-2021-257421 PoCIngress-nginx custom snippets allows retrieval of ingress-nginx serviceaccount token and secrets across all namespaces
- CVE-2021-257431 PoCANSI escape characters in kubectl output are not being filtered
- CVE-2021-257451 PoCIngress-nginx path can be pointed to service account token file
- CVE-2021-257461 PoCIngress-nginx directive injection via annotations
- CVE-2021-257481 PoCIngress-nginx `path` sanitization can be bypassed with newline character
- CVE-2021-257831 PoCTaocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function Article Search.
- CVE-2021-257841 PoCTaocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function Edit Article.
- CVE-2021-257851 PoCTaocms v2.5Beta5 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Management column.
- CVE-2021-257861 PoCAn issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to…
- CVE-2021-257902 PoCsMultiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows…
- CVE-2021-257912 PoCsMultiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows…
- CVE-2021-258291 PoCAn improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. Using this bug,…
- CVE-2021-258301 PoCA file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacker must request the…
- CVE-2021-258311 PoCA file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. An attacker must request the…
- CVE-2021-258321 PoCA heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer…
- CVE-2021-258331 PoCA file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file extension is…
- CVE-2021-258371 PoCCosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. Due to the inconsistency between the…
- CVE-2021-258561 PoCAn issue was discovered in pcmt superMicro-CMS version 3.11, allows attackers to delete files via crafted image file in images.php.
- CVE-2021-258571 PoCAn issue was discovered in pcmt superMicro-CMS version 3.11, allows authenticated attackers to execute arbitrary code via the font_type…
- CVE-2021-258632 PoCsOpen5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account.
- CVE-2021-258642 PoCsnode-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to…
- CVE-2021-258931 PoCMagnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the setText parameter of…
- CVE-2021-258941 PoCMagnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the…
- CVE-2021-258981 PoCAn issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. Passwords are stored in unencrypted source-code text files.…
- CVE-2021-258992 PoCsAn issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. An unauthenticated attacker can send a crafted HTTP request to…
- CVE-2021-259121 PoCPrototype pollution vulnerability in 'dotty' versions 0.0.1 through 0.1.0 allows attackers to cause a denial of service and may lead to…
- CVE-2021-259131 PoCPrototype pollution vulnerability in 'set-or-get' version 1.0.0 through 1.2.10 allows an attacker to cause a denial of service and may…
- CVE-2021-259141 PoCPrototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of service and may…
- CVE-2021-259152 PoCsPrototype pollution vulnerability in 'changeset' versions 0.0.1 through 0.2.5 allows an attacker to cause a denial of service and may lead…
- CVE-2021-259161 PoCPrototype pollution vulnerability in 'patchmerge' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may…
- CVE-2021-259231 PoCIn OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit.…
- CVE-2021-259251 PoCin SiCKRAGE, versions 4.2.0 to 10.0.11.dev1 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated…
- CVE-2021-259271 PoCPrototype pollution vulnerability in 'safe-flat' versions 2.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead…
- CVE-2021-259281 PoCPrototype pollution vulnerability in 'safe-obj' versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of service and may lead…
- CVE-2021-259291 PoCIn OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1…
- CVE-2021-259301 PoCIn OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1…
- CVE-2021-259311 PoCIn OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1…
- CVE-2021-259321 PoCIn OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1…
- CVE-2021-259331 PoCIn OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1…
- CVE-2021-259341 PoCIn OpenNMS Horizon, versions opennms-18.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through…
- CVE-2021-259351 PoCIn OpenNMS Horizon, versions opennms-17.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through…
- CVE-2021-259381 PoCIn ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validation of the .zip file…
- CVE-2021-259391 PoCArangoDB - Blind SSRF when Downloading Foxx Service from URL
- CVE-2021-259411 PoCPrototype pollution vulnerability in 'deep-override' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may…
- CVE-2021-259431 PoCPrototype pollution vulnerability in '101' versions 1.0.0 through 1.6.3 allows an attacker to cause a denial of service and may lead to…
- CVE-2021-259442 PoCsPrototype pollution vulnerability in 'deep-defaults' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may…
- CVE-2021-259451 PoCPrototype pollution vulnerability in 'js-extend' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to…
- CVE-2021-259461 PoCPrototype pollution vulnerability in `nconf-toml` versions 0.0.1 through 0.0.2 allows an attacker to cause a denial of service and may…
- CVE-2021-259471 PoCPrototype pollution vulnerability in 'nestie' versions 0.0.0 through 1.0.0 allows an attacker to cause a denial of service and may lead to…
- CVE-2021-259481 PoCPrototype pollution vulnerability in 'expand-hash' versions 0.1.0 through 1.0.1 allows an attacker to cause a denial of service and may…
- CVE-2021-259491 PoCPrototype pollution vulnerability in 'set-getter' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote…
- CVE-2021-259511 PoCXXE vulnerability in 'XML2Dict' version 0.2.2 allows an attacker to cause a denial of service.
- CVE-2021-259521 PoCPrototype pollution vulnerability in ‘just-safe-set’ versions 1.0.0 through 2.2.1 allows an attacker to cause a denial of service and may…
- CVE-2021-259531 PoCPrototype pollution vulnerability in 'putil-merge' versions1.0.0 through 3.6.6 allows attacker to cause a denial of service and may lead…
- CVE-2021-259881 PoCifme - Stored Cross-Site Scripting (XSS) in Notifications section
- CVE-2021-259891 PoCifme - Stored Cross-Site Scripting (XSS) in Groups section
- CVE-2021-259901 PoCifme - Stored Cross-Site Scripting (XSS) in Contacts section
- CVE-2021-259911 PoCifme - Improper Access Control leads to admin deactivation
- CVE-2021-259921 PoCifme - Insufficient Session Expiration
- CVE-2021-259931 PoCRequarks wiki.js - Stored Cross-Site Scripting (XSS) in markdown editor
- CVE-2021-259941 PoCUserfrosting - Host-Header Injection Leads to Account Takeover