CVE-2021-26000 to CVE-2021-26999
107 CVEs with public proof-of-concept exploits.
- CVE-2021-260721 PoCThe WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the…
- CVE-2021-260782 PoCsThe number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6,…
- CVE-2021-2608446 PoCsKEVIn affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated…
- CVE-2021-260857 PoCsKEVAffected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary…
- CVE-2021-260865 PoCsKEVAffected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal…
- CVE-2021-260881 PoCAn improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO…
- CVE-2021-261021 PoCA relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote…
- CVE-2021-261041 PoCMultiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager 6.2.7 and below, 6.4.5 and below and…
- CVE-2021-261191 PoCSmarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.
- CVE-2021-261201 PoCSmarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.
- CVE-2021-261941 PoCAn issue was discovered in JerryScript 2.4.0. There is a heap-use-after-free in ecma_is_lexical_environment in the ecma-helpers.c file.
- CVE-2021-262001 PoCThe user area for Library System 1.0 is vulnerable to SQL injection where a user can bypass the authentication and login as the admin user.
- CVE-2021-262011 PoCThe Login Panel of CASAP Automated Enrollment System 1.0 is vulnerable to SQL injection authentication bypass. An attacker can obtain…
- CVE-2021-262151 PoCSeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditDocument.php.
- CVE-2021-262161 PoCSeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditFolder.php.
- CVE-2021-262281 PoCSQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL…
- CVE-2021-262363 PoCsFastStone Image Viewer v.<= 7.5 is affected by a Stack-based Buffer Overflow at 0x005BDF49, affecting the CUR file parsing functionality…
- CVE-2021-262471 PoCAs an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully…
- CVE-2021-262581 PoCImproper access control for the Intel(R) Killer(TM) Control Center software before version 2.4.3337.0 may allow an authorized user to…
- CVE-2021-262591 PoCA flaw was found in htmldoc in v1.9.12. Heap buffer overflow in render_table_row(),in ps-pdf.cxx may lead to arbitrary code execution and…
- CVE-2021-262731 PoCThe Agent in NinjaRMM 5.0.909 has Incorrect Access Control.
- CVE-2021-262741 PoCThe Agent in NinjaRMM 5.0.909 has Insecure Permissions.
- CVE-2021-262911 PoCblock repositories using http by default
- CVE-2021-262931 PoCAn issue was discovered in AfterLogic Aurora through 8.5.3 and WebMail Pro through 8.5.3, when DAV is enabled. They allow directory…
- CVE-2021-262942 PoCsAn issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files…
- CVE-2021-2629511 PoCsRCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
- CVE-2021-262961 PoCCross-Site Request Forgery (CSRF) vulnerability in Apache MyFaces
- CVE-2021-263031 PoCPHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the user-profile.php Full Name field.
- CVE-2021-263041 PoCPHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the add-expense.php Item parameter.
- CVE-2021-264112 PoCsKEVInternet Explorer Memory Corruption Vulnerability
- CVE-2021-264151 PoCWindows Installer Elevation of Privilege Vulnerability
- CVE-2021-264192 PoCsScripting Engine Memory Corruption Vulnerability
- CVE-2021-264751 PoCEPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI.
- CVE-2021-265041 PoCDirectory Traversal vulnerability in Foddy node-red-contrib-huemagic version 3.0.0, allows remote attackers to gain sensitive information…
- CVE-2021-265492 PoCsAn XSS issue was discovered in SmartFoxServer 2.17.0. Input passed to the AdminTool console is not properly sanitized before being…
- CVE-2021-265502 PoCsAn issue was discovered in SmartFoxServer 2.17.0. Cleartext password disclosure can occur via /config/server.xml.
- CVE-2021-265511 PoCAn issue was discovered in SmartFoxServer 2.17.0. An attacker can execute arbitrary Python code, and bypass the javashell.py protection…
- CVE-2021-265631 PoCIncorrect authorization vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to…
- CVE-2021-265983 PoCsImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by…
- CVE-2021-265993 PoCsImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.
- CVE-2021-266002 PoCsImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).
- CVE-2021-266011 PoCImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.
- CVE-2021-266903 PoCsmod_session NULL pointer dereference
- CVE-2021-266911 PoCApache HTTP Server mod_session response handling heap overflow
- CVE-2021-266982 PoCsOX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link…
- CVE-2021-267004 PoCsVisual Studio Code npm-script Extension Remote Code Execution Vulnerability
- CVE-2021-267021 PoCEPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI.
- CVE-2021-267051 PoCAn issue was discovered in SquareBox CatDV Server through 9.2. An attacker can invoke sensitive RMI methods such as getConnections without…
- CVE-2021-267084 PoCsA local privilege escalation was discovered in the Linux kernel before 5.10.13. Multiple race conditions in the AF_VSOCK implementation…
- CVE-2021-267091 PoCD-Link DSL-320B-D1 devices through EU_1.25 are prone to multiple Stack-Based Buffer Overflows that allow unauthenticated remote attackers…
- CVE-2021-267101 PoCA cross-site scripting (XSS) issue in the login panel in Redwood Report2Web 4.3.4.5 and 4.5.3 allows remote attackers to inject JavaScript…
- CVE-2021-267141 PoCThe Enterprise License Manager portal in Mitel MiContact Center Enterprise before 9.4 could allow a user to access restricted files and…
- CVE-2021-267161 PoCModules/input/Views/schedule.php in Emoncms through 10.2.7 allows XSS via the node parameter.
- CVE-2021-267221 PoCLinkedIn Oncall through 1.4.0 allows reflected XSS via /query because of mishandling of the "No results found for" message in the search…
- CVE-2021-267233 PoCsJenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS.
- CVE-2021-267511 PoCNeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the endpoint…
- CVE-2021-267521 PoCNeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint…
- CVE-2021-267531 PoCNeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP…
- CVE-2021-267541 PoCwpDataTables before 3.4.1 mishandles order direction for server-side tables, aka admin-ajax.php?action=get_wdtable order[0][dir] SQL…
- CVE-2021-267583 PoCsPrivilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and…
- CVE-2021-267621 PoCSQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the…
- CVE-2021-267641 PoCSQL injection vulnerability in PHPGurukul Student Record System v 4.0 allows remote attackers to execute arbitrary SQL statements, via the…
- CVE-2021-267651 PoCSQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the…
- CVE-2021-267761 PoCCSZ CMS 1.2.9 is affected by a cross-site scripting (XSS) vulnerability in multiple pages through the field name.
- CVE-2021-267952 PoCsA SQL Injection vulnerability in /appliance/shiftmgn.php in TalariaX sendQuick Alert Plus Server Admin 4.3 before 8HF11 allows attackers…
- CVE-2021-267971 PoCAn access control vulnerability in Hame SD1 Wi-Fi firmware <=V.20140224154640 allows an attacker to get system administrator through an…
- CVE-2021-267991 PoCCross Site Scripting (XSS) vulnerability in admin/files/edit in Omeka Classic <=2.7 allows remote attackers to inject arbitrary web script…
- CVE-2021-268051 PoCBuffer Overflow in tsMuxer 2.6.16 allows attackers to cause a Denial of Service (DoS) by running the application with a malicious WAV file.
- CVE-2021-268071 PoCGalaxyClient version 2.0.28.9 loads unsigned DLLs such as zlib1.dll, libgcc_s_dw2-1.dll and libwinpthread-1.dll from PATH, which allows an…
- CVE-2021-268092 PoCsPHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php.
- CVE-2021-268101 PoCD-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parameter can be used in command string…
- CVE-2021-268122 PoCsCross Site Scripting (XSS) in the Jitsi Meet 2.7 through 2.8.3 plugin for Moodle via the "sessionpriv.php" module. This allows attackers…
- CVE-2021-268144 PoCsWazuh API in Wazuh from 4.0.0 to 4.0.3 allows authenticated users to execute arbitrary code with administrative privileges via…
- CVE-2021-268221 PoCTeachers Record Management System 1.0 is affected by a SQL injection vulnerability in 'searchteacher' POST parameter in…
- CVE-2021-268272 PoCsBuffer Overflow in TP-Link WR2041 v1 firmware for the TL-WR2041+ router allows remote attackers to cause a Denial-of-Service (DoS) by…
- CVE-2021-268286 PoCsKEVOpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP…
- CVE-2021-268291 PoCKEVOpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.
- CVE-2021-268301 PoCSQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin. This is…
- CVE-2021-268321 PoCCross Site Scripting (XSS) in the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attackers to execute…
- CVE-2021-268331 PoCCleartext Storage in a File or on Disk in TimelyBills <= 1.7.0 for iOS and versions <= 1.21.115 for Android allows attacker who can…
- CVE-2021-268341 PoCA cross-site scripting (XSS) vulnerability exists in Znote 0.5.2. An attacker can insert payloads, and the code execution will happen…
- CVE-2021-2685561 PoCsKEVMicrosoft Exchange Server Remote Code Execution Vulnerability
- CVE-2021-268575 PoCsKEVMicrosoft Exchange Server Remote Code Execution Vulnerability
- CVE-2021-268583 PoCsKEVMicrosoft Exchange Server Remote Code Execution Vulnerability
- CVE-2021-268631 PoCWindows Win32k Elevation of Privilege Vulnerability
- CVE-2021-268651 PoCWindows Container Execution Agent Elevation of Privilege Vulnerability
- CVE-2021-268683 PoCsWindows Graphics Component Elevation of Privilege Vulnerability
- CVE-2021-268712 PoCsWindows WalletService Elevation of Privilege Vulnerability
- CVE-2021-268821 PoCRemote Access API Elevation of Privilege Vulnerability
- CVE-2021-268871 PoCMicrosoft Windows Folder Redirection Elevation of Privilege Vulnerability
- CVE-2021-269031 PoCLMA ISIDA Retriever 5.2 is vulnerable to XSS via query['text'].
- CVE-2021-269041 PoCLMA ISIDA Retriever 5.2 allows SQL Injection.
- CVE-2021-269102 PoCsFirejail before 0.9.64.4 allows attackers to bypass intended access restrictions because there is a TOCTOU race condition between a stat…
- CVE-2021-269122 PoCsNetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because…
- CVE-2021-269132 PoCsNetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because…
- CVE-2021-269144 PoCsNetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because…
- CVE-2021-269152 PoCsNetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because…
- CVE-2021-269161 PoCIn nopCommerce 4.30, a Reflected XSS issue in the Discount Coupon component allows remote attackers to inject arbitrary web script or HTML…
- CVE-2021-269182 PoCsThe ProBot bot through 2021-02-08 for Discord might allow attackers to interfere with the intended purpose of the "Send an image when a…
- CVE-2021-269191 PoCApache Druid Authenticated users can execute arbitrary code from malicious MySQL database systems.
- CVE-2021-269261 PoCA flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to disclosure of…
- CVE-2021-269271 PoCA flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of…
- CVE-2021-269281 PoCBIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products that use BIRD (which…
- CVE-2021-269292 PoCsAn XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used).…
- CVE-2021-269351 PoCIn WoWonder < 3.1, remote attackers can gain access to the database by exploiting a requests.php?f=search-my-followers SQL Injection…
- CVE-2021-269431 PoCThe UX360CA BIOS through 303 on ASUS laptops allow an attacker (with the ring 0 privilege) to overwrite nearly arbitrary physical memory…
- CVE-2021-269471 PoCCross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject…