CVE-2021-28000 to CVE-2021-28999
99 CVEs with public proof-of-concept exploits.
- CVE-2021-280001 PoCA persistent cross-site scripting vulnerability was discovered in Local Services Search Engine Management System Project 1.0 which allows…
- CVE-2021-280011 PoCA cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to…
- CVE-2021-280021 PoCA persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which allows remote…
- CVE-2021-280061 PoCWeb Based Quiz System 1.0 is affected by cross-site scripting (XSS) in admin.php through the options parameter.
- CVE-2021-280071 PoCWeb Based Quiz System 1.0 is affected by cross-site scripting (XSS) in register.php through the name parameter.
- CVE-2021-280211 PoCBuffer overflow vulnerability in function stbi__extend_receive in stb_image.h in stb 2.26 via a crafted JPEG file.
- CVE-2021-280261 PoCjpeg-xl v0.3.2 is affected by a heap buffer overflow in /lib/jxl/coeff_order.cc ReadPermutation. When decoding a malicous jxl file using…
- CVE-2021-280401 PoCAn issue was discovered in OSSEC 3.6.0. An uncontrolled recursion vulnerability in os_xml.c occurs when a large number of opening and…
- CVE-2021-280601 PoCA Server-Side Request Forgery (SSRF) vulnerability in Group Office 6.4.196 allows a remote attacker to forge GET requests to arbitrary…
- CVE-2021-280701 PoCCross Site Request Forgery (CSRF) vulnerability exist in PopojiCMS 2.0.1 in po-admin/route.php?mod=user&act=multidelete.
- CVE-2021-280792 PoCsJamovi <=1.6.18 is affected by a cross-site scripting (XSS) vulnerability. The column-name is vulnerable to XSS in the ElectronJS…
- CVE-2021-280881 PoCCross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to inject arbitrary…
- CVE-2021-281131 PoCA command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers…
- CVE-2021-281151 PoCThe OUGC Feedback plugin before 1.8.23 for MyBB allows XSS via the comment field of feedback during an edit operation.
- CVE-2021-281281 PoCIn Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password. An attacker who…
- CVE-2021-281301 PoCDr.Web Firewall 12.5.2.4160 on Windows incorrectly restricts applications signed by Dr.Web. A DLL for a custom payload within a legitimate…
- CVE-2021-281321 PoCLUCY Security Awareness Software through 4.7.x allows unauthenticated remote code execution because the Migration Tool (in the Support…
- CVE-2021-281421 PoCCITSmart before 9.1.2.28 mishandles the "filtro de autocomplete."
- CVE-2021-281432 PoCs/jsonrpc on D-Link DIR-841 3.03 and 3.04 devices allows authenticated command injection via ping, ping6, or traceroute (under System Tools).
- CVE-2021-281441 PoCprog.cgi on D-Link DIR-3060 devices before 1.11b04 HF2 allows remote authenticated users to inject arbitrary commands in an admin or root…
- CVE-2021-281492 PoCsHongdian H8922 3.0.5 devices allow Directory Traversal. The /log_download.cgi log export handler does not validate user input and allows a…
- CVE-2021-281501 PoCHongdian H8922 3.0.5 devices allow the unprivileged guest user to read cli.conf (with the administrator password and other sensitive data)…
- CVE-2021-281511 PoCHongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) field to the…
- CVE-2021-281531 PoCAn issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a…
- CVE-2021-281601 PoCWireless-N WiFi Repeater REV 1.0 (28.08.06.1) suffers from a reflected XSS vulnerability due to unsanitized SSID value when the latter is…
- CVE-2021-281611 PoCIn Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be…
- CVE-2021-281622 PoCsIn Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.
- CVE-2021-281647 PoCsIn Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e…
- CVE-2021-281651 PoCIn Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large…
- CVE-2021-281693 PoCsFor Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to…
- CVE-2021-282111 PoCA heap overflow in LzmaUefiDecompressGetInfo function in EDK II.
- CVE-2021-282331 PoCHeap-based Buffer Overflow vulnerability exists in ok-file-formats 1 via the ok_jpg_generate_huffman_table function in ok_jpg.c.
- CVE-2021-282351 PoCAuthentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.
- CVE-2021-282361 PoCLibreDWG v0.12.3 was discovered to contain a NULL pointer dereference via out_dxfb.c.
- CVE-2021-282371 PoCLibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13.
- CVE-2021-282423 PoCsSQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information…
- CVE-2021-282461 PoCCA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. A…
- CVE-2021-282471 PoCCA eHealth Performance Manager through 6.3.2.12 is affected by Cross Site Scripting (XSS). The impact is: An authenticated remote user is…
- CVE-2021-282481 PoCCA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is…
- CVE-2021-282491 PoCCA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. To…
- CVE-2021-282501 PoCCA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a setuid (and/or setgid) file. When a component is…
- CVE-2021-282692 PoCsSoyal Technology 701Client 9.0.1 is vulnerable to Insecure permissions via client.exe binary with Authenticated Users group with Full…
- CVE-2021-282712 PoCsSoyal Technologies SOYAL 701Server 9.0.1 suffers from an elevation of privileges vulnerability which can be used by an authenticated user…
- CVE-2021-282751 PoCA Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exif.c in will cause…
- CVE-2021-282771 PoCA Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overflow via the RemoveUnknownSections…
- CVE-2021-282781 PoCA Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c.
- CVE-2021-282801 PoCCSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitrary web script…
- CVE-2021-282931 PoCSeceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Password feature. The…
- CVE-2021-282941 PoCOnline Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to…
- CVE-2021-282951 PoCOnline Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to…
- CVE-2021-283001 PoCNULL Pointer Dereference in the "isomedia/track.c" module's "MergeTrack()" function of GPAC v0.5.2 allows attackers to execute arbitrary…
- CVE-2021-283021 PoCA stack overflow in pupnp before version 1.14.5 can cause the denial of service through the Parser_parseDocument() function.…
- CVE-2021-283121 PoCWindows NTFS Denial of Service Vulnerability
- CVE-2021-283211 PoCDiagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability
- CVE-2021-283761 PoCChronoForms 7.0.7 allows fname Directory Traversal to read arbitrary files.
- CVE-2021-283772 PoCsChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files.
- CVE-2021-283781 PoCGitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations.
- CVE-2021-283792 PoCsweb/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a…
- CVE-2021-283821 PoCZoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD.
- CVE-2021-284173 PoCsA cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and the "search_name"…
- CVE-2021-284183 PoCsA cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and the "category"…
- CVE-2021-284194 PoCsThe "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads to the ability to…
- CVE-2021-284203 PoCsA cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and the "from_time"…
- CVE-2021-284233 PoCsMultiple SQL Injection vulnerabilities in Teachers Record Management System 1.0 thru 2.1 allow remote authenticated users to execute…
- CVE-2021-284243 PoCsA stored cross-site scripting (XSS) vulnerability in Teachers Record Management System 1.0 allows remote authenticated users to inject…
- CVE-2021-284471 PoCWindows Early Launch Antimalware Driver Security Feature Bypass Vulnerability
- CVE-2021-284591 PoCAzure DevOps Server Spoofing Vulnerability
- CVE-2021-284766 PoCsWindows Hyper-V Remote Code Execution Vulnerability
- CVE-2021-284803 PoCsMicrosoft Exchange Server Remote Code Execution Vulnerability
- CVE-2021-284812 PoCsMicrosoft Exchange Server Remote Code Execution Vulnerability
- CVE-2021-284826 PoCsMicrosoft Exchange Server Remote Code Execution Vulnerability
- CVE-2021-284831 PoCMicrosoft Exchange Server Remote Code Execution Vulnerability
- CVE-2021-285001 PoCAn issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents…
- CVE-2021-285011 PoCAn issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents…
- CVE-2021-285061 PoCAn issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could…
- CVE-2021-285071 PoCAn issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and…
- CVE-2021-285501 PoCKEVAdobe Acrobat Reader use after free vulnerability could lead to arbitrary code execution
- CVE-2021-286631 PoCKEVThe Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading…
- CVE-2021-286801 PoCThe devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let…
- CVE-2021-286841 PoCThe XML parser used in ConeXware PowerArchiver before 20.10.02 allows processing of external entities, which might lead to exfiltration of…
- CVE-2021-287971 PoCStack Buffer Overflow in Surveillance Station
- CVE-2021-287991 PoCKEVImproper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)
- CVE-2021-288072 PoCsPost-Authentication Reflected XSS Vulnerability in Q'center
- CVE-2021-288571 PoCTP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 username and password are sent via the cookie.
- CVE-2021-288581 PoCTP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 does not use SSL by default. Attacker on the local network can monitor traffic and…
- CVE-2021-289031 PoCA stack overflow in libyang <= v1.0.225 can cause a denial of service through function lyxml_parse_mem(). lyxml_parse_elem() function will…
- CVE-2021-289183 PoCsImproper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform…
- CVE-2021-289241 PoCSelf Authenticated XSS in Nagios Network Analyzer before 2.4.2 via the nagiosna/groups/queries page.
- CVE-2021-289252 PoCsSQL injection vulnerability in Nagios Network Analyzer before 2.4.3 via the o[col] parameter to api/checks/read/.
- CVE-2021-289271 PoCThe text-to-speech engine in libretro RetroArch for Windows 1.9.0 passes unsanitized input to PowerShell through platform_win32.c via the…
- CVE-2021-289352 PoCsCMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > My Preferences >…
- CVE-2021-289361 PoCThe Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) Web management administrator password can be changed by sending a specially…
- CVE-2021-289372 PoCsThe /password.html page of the Web management interface of the Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) contains the…
- CVE-2021-289401 PoCBecause of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to add a extra…
- CVE-2021-289661 PoCIn Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir.
- CVE-2021-289691 PoCeMPS 9.0.1.923211 on FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort_by parameter…
- CVE-2021-289701 PoCeMPS 9.0.1.923211 on the Central Management of FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks…
- CVE-2021-289751 PoCWP Mailster 1.6.18.0 allows XSS when a victim opens a mail server's details in the mst_servers page, for a crafted server_host,…
- CVE-2021-289761 PoCRemote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.