CVE-2021-27000 to CVE-2021-27999
127 CVEs with public proof-of-concept exploits.
- CVE-2021-2706519 PoCsKEVMicrosoft Exchange Server Remote Code Execution Vulnerability
- CVE-2021-270941 PoCWindows Early Launch Antimalware Driver Security Feature Bypass Vulnerability
- CVE-2021-271131 PoCAn issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the…
- CVE-2021-271141 PoCAn issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/addassignment route, a very long…
- CVE-2021-271161 PoCAn issue was discovered in file profile.go in function MemProf in beego through 2.0.2, allows attackers to launch symlink attacks locally.
- CVE-2021-271171 PoCAn issue was discovered in file profile.go in function GetCPUProfile in beego through 2.0.2, allows attackers to launch symlink attacks…
- CVE-2021-271243 PoCsSQL injection in the expertise parameter in search_result.php in Doctor Appointment System v1.0 allows an authenticated patient user to…
- CVE-2021-271292 PoCsCASAP Automated Enrollment System version 1.0 contains a cross-site scripting (XSS) vulnerability through the Students > Edit > ROUTE…
- CVE-2021-271301 PoCOnline Reviewer System 1.0 contains a SQL injection vulnerability through authentication bypass, which may lead to a reverse shell upload.
- CVE-2021-271321 PoCSerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the…
- CVE-2021-271351 PoCxterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fault) via a crafted…
- CVE-2021-271371 PoCKEVAn issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an…
- CVE-2021-271841 PoCPelco Digital Sentry Server 7.18.72.11464 has an XML External Entity vulnerability (exploitable via the DTD parameter entities technique),…
- CVE-2021-271903 PoCsA Stored Cross Site Scripting(XSS) Vulnerability was discovered in PEEL SHOPPING 9.3.0 and 9.4.0, which are publicly available. The user…
- CVE-2021-271971 PoCDSUtility.dll in Pelco Digital Sentry Server before 7.19.67 has an arbitrary file write vulnerability. The AppendToTextFile method doesn't…
- CVE-2021-271981 PoCAn issue was discovered in Visualware MyConnection Server before v11.1a. Unauthenticated Remote Code Execution can occur via Arbitrary…
- CVE-2021-272001 PoCIn WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter…
- CVE-2021-272011 PoCEndian Firewall Community (aka EFW) 3.3.2 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in a…
- CVE-2021-272041 PoCTelegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure.
- CVE-2021-272051 PoCTelegram before 7.4 (212543) Stable on macOS stores the local copy of self-destructed messages in a sandbox path, leading to sensitive…
- CVE-2021-272151 PoCAn issue was discovered in genua genugate before 9.0 Z p19, 9.1.x through 9.6.x before 9.6 p7, and 10.x before 10.1 p4. The Web Interfaces…
- CVE-2021-272161 PoCExim 4 before 4.94.2 has Execution with Unnecessary Privileges. By leveraging a delete_pid_file race condition, a local user can delete…
- CVE-2021-272171 PoCAn issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not correctly validate…
- CVE-2021-272191 PoCAn issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit…
- CVE-2021-272242 PoCsThe WPG plugin before 3.1.0.0 for IrfanView 4.57 has a user-mode write access violation starting at WPG+0x0000000000012ec6, which might…
- CVE-2021-272301 PoCExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leverage…
- CVE-2021-272311 PoCHestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to create a subdomain…
- CVE-2021-272321 PoCThe RTSPLive555.dll ActiveX control in Pelco Digital Sentry Server 7.18.72.11464 has a SetCameraConnectionParameter stack-based buffer…
- CVE-2021-272371 PoCThe admin panel in BlackCat CMS 1.3.6 allows stored XSS (by an admin) via the Display Name field to backend/preferences/ajax_save.php.
- CVE-2021-272462 PoCsThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 AC1750…
- CVE-2021-272491 PoCThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2020 v1.01rc001…
- CVE-2021-272502 PoCsThis vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DAP-2020…
- CVE-2021-272851 PoCAn issue was discovered in Inspur ClusterEngine v4.0 that allows attackers to gain escalated Local privileges and execute arbitrary…
- CVE-2021-272891 PoCA replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor…
- CVE-2021-272901 PoCssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs…
- CVE-2021-273083 PoCsA cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to inject JavaScript…
- CVE-2021-273092 PoCsClansphere CMS 2011.4 allows unauthenticated reflected XSS via "module" parameter.
- CVE-2021-273102 PoCsClansphere CMS 2011.4 allows unauthenticated reflected XSS via "language" parameter.
- CVE-2021-273121 PoCServer Side Request Forgery (SSRF) vulnerability in Gleez Cms 1.2.0, allows remote attackers to execute arbitrary code and obtain…
- CVE-2021-273142 PoCsSQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via…
- CVE-2021-273152 PoCsBlind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries…
- CVE-2021-273162 PoCsBlind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries…
- CVE-2021-273171 PoCCross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web…
- CVE-2021-273181 PoCCross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web…
- CVE-2021-273192 PoCsBlind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries…
- CVE-2021-273202 PoCsBlind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries…
- CVE-2021-273283 PoCsYeastar NeoGate TG400 91.3.0.3 devices are affected by Directory Traversal. An authenticated user can decrypt firmware and can read…
- CVE-2021-273303 PoCsTriconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read authentication…
- CVE-2021-273351 PoCKollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a…
- CVE-2021-273381 PoCFaraday Edge before 3.7 allows XSS via the network/create/ page and its network name parameter.
- CVE-2021-273422 PoCsAn authentication brute-force protection mechanism bypass in telnetd in D-Link Router model DIR-842 firmware version 3.0.2 allows a remote…
- CVE-2021-273451 PoCA null pointer dereference was discovered in ucompthread in stream.c in Irzip 0.631 which allows attackers to cause a denial of service…
- CVE-2021-273471 PoCUse after free in lzma_decompress_buf function in stream.c in Irzip 0.631 allows attackers to cause Denial of Service (DoS) via a crafted…
- CVE-2021-273522 PoCsAn open redirect vulnerability in Ilch CMS version 2.1.42 allows attackers to redirect users to an attacker's site after a successful login.
- CVE-2021-273581 PoCThe snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a…
- CVE-2021-273621 PoCThe WPG plugin before 3.1.0.0 for IrfanView 4.57 has a Read Access Violation on Control Flow starting at WPG!ReadWPG_W+0x0000000000000133,…
- CVE-2021-273631 PoCAn issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the…
- CVE-2021-273641 PoCAn issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an…
- CVE-2021-273652 PoCsAn issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or…
- CVE-2021-273681 PoCThe Contact page in Monica 2.19.1 allows stored XSS via the First Name field.
- CVE-2021-273691 PoCThe Contact page in Monica 2.19.1 allows stored XSS via the Middle Name field.
- CVE-2021-273703 PoCsThe Contact page in Monica 2.19.1 allows stored XSS via the Last Name field.
- CVE-2021-273711 PoCThe Contact page in Monica 2.19.1 allows stored XSS via the Description field.
- CVE-2021-274031 PoCAskey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow cgi-bin/te_acceso_router.cgi curWebPage XSS.
- CVE-2021-274041 PoCAskey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow injection of a Host HTTP header.
- CVE-2021-274351 PoCARM mbed Integer Overflow or Wraparound
- CVE-2021-275133 PoCsThe module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on…
- CVE-2021-275142 PoCsEyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force…
- CVE-2021-275194 PoCsA cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "srch" parameter.
- CVE-2021-275204 PoCsA cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "author" parameter.
- CVE-2021-275261 PoCA cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "page" parameter.
- CVE-2021-275271 PoCA cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "valueID" parameter.
- CVE-2021-275281 PoCA cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "refID" parameter.
- CVE-2021-275291 PoCA cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "limit" parameter.
- CVE-2021-275301 PoCA cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allow remote attacker to inject javascript via URI in /index.php.
- CVE-2021-275311 PoCA cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "query" parameter.
- CVE-2021-275441 PoCCross Site Scripting (XSS) in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers…
- CVE-2021-275452 PoCsSQL Injection in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to obtain…
- CVE-2021-275491 PoCGenymotion Desktop through 3.2.0 leaks the host's clipboard data to the Android application by default. NOTE: the vendor's position is…
- CVE-2021-275501 PoCPolaris Office v9.102.66 is affected by a divide-by-zero error in PolarisOffice.exe and EngineDLL.dll that may cause a local denial of…
- CVE-2021-275591 PoCThe Contact page in Monica 2.19.1 allows stored XSS via the Nickname field.
- CVE-2021-275611 PoCKEVYealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without…
- CVE-2021-275681 PoCAn issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function,…
- CVE-2021-276481 PoCExternally controlled reference to a resource in another sphere in quarantine functionality in Synology Antivirus Essential before…
- CVE-2021-276517 PoCsIn versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local…
- CVE-2021-276703 PoCsAppspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.
- CVE-2021-276721 PoCSQL Injection in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers to obtain sesnitive…
- CVE-2021-276732 PoCsCross Site Scripting (XSS) in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers to…
- CVE-2021-276951 PoCMultiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or…
- CVE-2021-277051 PoCBuffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a…
- CVE-2021-277061 PoCBuffer Overflow in Tenda G1 and G3 routers with firmware version V15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code…
- CVE-2021-277071 PoCBuffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a…
- CVE-2021-277082 PoCsCommand Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware…
- CVE-2021-277102 PoCsCommand Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware…
- CVE-2021-277222 PoCsAn issue was discovered in Nsasoft US LLC SpotAuditor 5.3.5. The program can be crashed by entering 300 bytes char data into the "Key" or…
- CVE-2021-277991 PoCean_leading_zeroes in backend/upcean.c in Zint Barcode Generator 2.9.1 has a stack-based buffer overflow that is reachable from the C API…
- CVE-2021-278151 PoCNULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows…
- CVE-2021-278221 PoCA persistent cross site scripting (XSS) vulnerability in the Add Categories module of Vehicle Parking Management System 1.0 allows…
- CVE-2021-278251 PoCA directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-static/ URL.
- CVE-2021-278281 PoCSQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the application's…
- CVE-2021-278506 PoCsBypass of the fix for CVE-2019-0195
- CVE-2021-278561 PoCFatPipe software administrative account with no password
- CVE-2021-278581 PoCMissing authorization vulnerability in FatPipe software
- CVE-2021-278763 PoCsKEVAn issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful…
- CVE-2021-278774 PoCsKEVAn issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of…
- CVE-2021-278782 PoCsKEVAn issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful…
- CVE-2021-278851 PoCusersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.
- CVE-2021-278893 PoCsCross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.
- CVE-2021-278903 PoCsSQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
- CVE-2021-279057 PoCsSSRF vulnerability with the Replication handler
- CVE-2021-279091 PoCXSS vulnerability on password reset page
- CVE-2021-279131 PoCUse of a Broken or Risky Cryptographic Algorithm
- CVE-2021-279286 PoCsA remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before…
- CVE-2021-279312 PoCsLumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp. One…
- CVE-2021-279331 PoCpfSense 2.5.0 allows XSS via the services_wol_edit.php Description field.
- CVE-2021-279401 PoCresources/public/js/orchestrator.js in openark orchestrator before 3.2.4 allows XSS via the orchestrator-msg parameter.
- CVE-2021-279462 PoCsSQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3).
- CVE-2021-279561 PoCZoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the…
- CVE-2021-279631 PoCSonLogger before 6.4.1 is affected by user creation with any user permissions profile (e.g., SuperAdmin). An anonymous user can send a…
- CVE-2021-279644 PoCsSonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to…
- CVE-2021-279653 PoCsThe MsIo64.sys driver before 1.1.19.1016 in MSI Dragon Center before 2.0.98.0 has a buffer overflow that allows privilege escalation via a…
- CVE-2021-279691 PoCDolphin CMS 7.4.2 is vulnerable to stored XSS via the Page Builder "width" parameter.
- CVE-2021-279732 PoCsSQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.
- CVE-2021-279831 PoCRemote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.
- CVE-2021-279841 PoCIn Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.
- CVE-2021-279891 PoCAppspace 6.2.4 is vulnerable to stored cross-site scripting (XSS) in multiple parameters within /medianet/sgcontentset.aspx.
- CVE-2021-279901 PoCAppspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the…