CVE-2021-29000 to CVE-2021-29999
79 CVEs with public proof-of-concept exploits.
- CVE-2021-290022 PoCsA stored cross-site scripting (XSS) vulnerability in Plone CMS 5.2.3 exists in site-controlpanel via the "form.widgets.site_title"…
- CVE-2021-290032 PoCsGenexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacters to…
- CVE-2021-290041 PoCrConfig 3.9.6 is affected by SQL Injection. A user must be authenticated to exploit the vulnerability. If --secure-file-priv in MySQL…
- CVE-2021-290051 PoCInsecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute chmod as root…
- CVE-2021-290062 PoCsrConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on the server.
- CVE-2021-290081 PoCA cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via webmaster-tools.php in the…
- CVE-2021-290091 PoCA cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in the "type" parameter.
- CVE-2021-290101 PoCA cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in the "report_type"…
- CVE-2021-290112 PoCsDMA Softlab Radius Manager 4.4.0 is affected by Cross Site Scripting (XSS) via the description, name, or address field (under admin.php).
- CVE-2021-290122 PoCsDMA Softlab Radius Manager 4.4.0 assigns the same session cookie to every admin session. The cookie is valid when the admin is logged in,…
- CVE-2021-290251 PoCA cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the…
- CVE-2021-290261 PoCA cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the…
- CVE-2021-290271 PoCA cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the…
- CVE-2021-290281 PoCA cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the…
- CVE-2021-290291 PoCA cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the…
- CVE-2021-290301 PoCA cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the…
- CVE-2021-290311 PoCA cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the…
- CVE-2021-290321 PoCA cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the…
- CVE-2021-290331 PoCA cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the…
- CVE-2021-290561 PoCCross Site Scripting (XSS) vulnerability exists in Pixelimity 1.0 via the HTTP POST parameter to admin/setting.php.
- CVE-2021-290591 PoCA vulnerability was discovered in IS-SVG version 2.1.0 to 4.2.2 and below where a Regular Expression Denial of Service (ReDOS) occurs if…
- CVE-2021-290601 PoCA Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Color-String version 1.5.5 and below which occurs when the…
- CVE-2021-290612 PoCsA Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Vfsjfilechooser2 version 0.2.9 and below which occurs when…
- CVE-2021-290631 PoCA Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 through v1.2.1 when the mpmathify function is…
- CVE-2021-291151 PoCAn information disclosure vulnerability
- CVE-2021-291331 PoCLack of verification in haserl, a component of Alpine Linux Configuration Framework, before 0.9.36 allows local users to read the contents…
- CVE-2021-291552 PoCsAn issue was discovered in the Linux kernel through 5.11.x. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on…
- CVE-2021-291564 PoCsForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform…
- CVE-2021-292004 PoCsRCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
- CVE-2021-292031 PoCA security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure…
- CVE-2021-292671 PoCSherlock SherlockIM through 2021-03-29 allows Cross Site Scripting (XSS) by leveraging the api/Files/Attachment URI to attack help-desk…
- CVE-2021-292812 PoCsFile upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin…
- CVE-2021-293022 PoCsTP-Link TL-WR802N(US), Archer_C50v5_US v4_200 <= 2020.06 contains a buffer overflow vulnerability in the httpd process in the body…
- CVE-2021-293231 PoCOpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow via the component /modules/network/wifi/esp/modwifi.c.
- CVE-2021-293241 PoCOpenSource Moddable v10.5.0 was discovered to contain a stack overflow via the component /moddable/xs/sources/xsScript.c.
- CVE-2021-293251 PoCOpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fx_String_prototype_repeat function at…
- CVE-2021-293261 PoCOpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fxIDToString function at…
- CVE-2021-293271 PoCOpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fx_ArrayBuffer function at…
- CVE-2021-293281 PoCOpenSource Moddable v10.5.0 was discovered to contain buffer over-read in the fxDebugThrow function at /moddable/xs/sources/xsDebug.c.
- CVE-2021-293291 PoCOpenSource Moddable v10.5.0 was discovered to contain a stack overflow in the fxBinaryExpressionNodeDistribute function at…
- CVE-2021-293371 PoCMODAPI.sys in MSI Dragon Center 2.0.104.0 allows low-privileged users to access kernel memory and potentially escalate privileges via a…
- CVE-2021-293381 PoCInteger Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when…
- CVE-2021-293431 PoCOvidentia CMS 6.x contains a SQL injection vulnerability in the "id" parameter of index.php. The "checkbox" property into "text" data can…
- CVE-2021-293492 PoCsMahara 20.10 is affected by Cross Site Request Forgery (CSRF) that allows a remote attacker to remove inbox-mail on the server. The…
- CVE-2021-293781 PoCSQL Injection in pear-admin-think version 2.1.2, allows attackers to execute arbitrary code and escalate privileges via crafted GET…
- CVE-2021-293792 PoCsAn issue was discovered on D-Link DIR-802 A1 devices through 1.00b05. Universal Plug and Play (UPnP) is enabled by default on port 1900.…
- CVE-2021-293871 PoCMultiple stored cross-site scripting (XSS) vulnerabilities in Sourcecodester Equipment Inventory System 1.0 allow remote attackers to…
- CVE-2021-293881 PoCA stored cross-site scripting (XSS) vulnerability in SourceCodester Budget Management System 1.0 allows users to inject and store…
- CVE-2021-294252 PoCsPossible limited path traversal vulnerabily in Apache Commons IO
- CVE-2021-294271 PoCRepository content filters do not work in Settings pluginManagement
- CVE-2021-294404 PoCsTwig allowing dangerous PHP functions by default
- CVE-2021-294417 PoCsAuthentication bypass
- CVE-2021-294424 PoCsAuthentication bypass
- CVE-2021-2944730 PoCsWordPress Authenticated XXE attack when installation is running PHP 8
- CVE-2021-294492 PoCsMultiple Privilege Escalation Vulnerabilities Pihole
- CVE-2021-294501 PoCWordPress Authenticated disclosure of password-protected posts and pages
- CVE-2021-294602 PoCsCross-site scripting (XSS) from unsanitized uploaded SVG files
- CVE-2021-294721 PoCMissing argument delimiter can lead to code execution via VCS repository URLs or source download URLs on systems with Mercurial in composer
- CVE-2021-294741 PoCRelative Path Traversal Attack on note creation
- CVE-2021-294761 PoCInsecure Deserialization of untrusted data in rmccue/requests
- CVE-2021-294842 PoCsDOM XSS in Theme Preview
- CVE-2021-294902 PoCsUnauthenticated GET requests through Remote Image endpoints
- CVE-2021-295054 PoCsXStream is vulnerable to a Remote Command Execution attack
- CVE-2021-296223 PoCsArbitrary redirects under /new endpoint
- CVE-2021-296251 PoCXSS in doc_link
- CVE-2021-296271 PoCIn FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 before p0, and 12.2-RELEASE before p6, listening socket accept…
- CVE-2021-296413 PoCsDirectus 8 before 8.8.2 allows remote authenticated users to execute arbitrary code because file-upload permissions include the ability to…
- CVE-2021-296431 PoCPRTG Network Monitor before 21.3.69.1333 allows stored XSS via an unsanitized string imported from a User Object in a connected Active…
- CVE-2021-296571 PoCarch/x86/kvm/svm/nested.c in the Linux kernel before 5.11.12 has a use-after-free in which an AMD KVM guest can bypass access control on…
- CVE-2021-296622 PoCsThe Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginning of an IP…
- CVE-2021-296631 PoCCourseMS (aka Course Registration Management System) 2.1 is affected by cross-site scripting (XSS). When an attacker with access to an…
- CVE-2021-298271 PoCIBM InfoSphere Information Server clickjacking
- CVE-2021-299212 PoCsIn Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some…
- CVE-2021-299221 PoClibrary/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP…
- CVE-2021-299231 PoCGo before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations)…
- CVE-2021-299571 PoCIf a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unprotected part,…
- CVE-2021-299851 PoCA use-after-free vulnerability in media channels could have led to memory corruption and a potentially exploitable crash. This…
- CVE-2021-299952 PoCsA Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute any action as the…
- CVE-2021-299962 PoCsMark Text through 0.16.3 allows attackers arbitrary command execution. This could lead to Remote Code Execution (RCE) by opening .md files…