CVE-2021-30000 to CVE-2021-30999
87 CVEs with public proof-of-concept exploits.
- CVE-2021-300001 PoCAn issue was discovered in LATRIX 0.6.0. SQL injection in the txtaccesscode parameter of inandout.php leads to information disclosure and…
- CVE-2021-300031 PoCAn issue was discovered on Nokia G-120W-F 3FE46606AGAB91 devices. There is Stored XSS in the administrative interface via…
- CVE-2021-300051 PoCIn JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.
- CVE-2021-300281 PoCSOOTEWAY Wi-Fi Range Extender v1.5 was discovered to use default credentials (the admin password for the admin account) to access the…
- CVE-2021-300303 PoCsCross Site Scripting (XSS) in Remote Clinic v2.0 via the Full Name field on register-patient.php.
- CVE-2021-300343 PoCsCross Site Scripting (XSS) in Remote Clinic v2.0 via the Symptons field on patients/register-report.php.
- CVE-2021-300393 PoCsCross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-report.php.
- CVE-2021-300423 PoCsCross Site Scripting (XSS) in Remote Clinic v2.0 via the "Clinic Name", "Clinic Address", "Clinic City", or "Clinic Contact" field on…
- CVE-2021-300443 PoCsCross Site Scripting (XSS) in Remote Clinic v2.0 via the First Name or Last Name field on staff/register.php.
- CVE-2021-300461 PoCVIGRA Computer Vision Library Version-1-11-1 contains a segmentation fault vulnerability in the impex.hxx read_image_band() function, in…
- CVE-2021-300472 PoCsVSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.
- CVE-2021-300482 PoCsDirectory Traversal in the fileDownload function in com/java2nb/common/controller/FileController.java in Novel-plus (小说精品屋-plus) 3.5.1…
- CVE-2021-300491 PoCSysAid 20.3.64 b14 is affected by Cross Site Scripting (XSS) via a /KeepAlive.jsp?stamp= URI.
- CVE-2021-300551 PoCA SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the…
- CVE-2021-300561 PoCKnowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in…
- CVE-2021-300571 PoCA stored HTML injection vulnerability exists in Knowage Suite version 7.1. An attacker can inject arbitrary HTML in…
- CVE-2021-300581 PoCKnowage Suite before 7.4 is vulnerable to cross-site scripting (XSS). An attacker can inject arbitrary external script in…
- CVE-2021-300831 PoCAn issue was discovered in Mediat 1.4.1. There is a Reflected XSS vulnerability which allows remote attackers to inject arbitrary web…
- CVE-2021-301081 PoCFeehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability. When the user modifies the HTTP Referer header to any…
- CVE-2021-301091 PoCFroala Editor 3.2.6 is affected by Cross Site Scripting (XSS). Under certain conditions, a base64 crafted string leads to persistent…
- CVE-2021-301111 PoCA stored XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in the event name and description fields. An attack can inject…
- CVE-2021-301121 PoCWeb-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a…
- CVE-2021-301131 PoCA blind XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in event name and description fields. An attacker can inject a…
- CVE-2021-301141 PoCWeb-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create a voucher payment…
- CVE-2021-301161 PoCKEVUnauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6
- CVE-2021-301181 PoCUnauthenticated Remote Code Execution in Kaseya VSA < v9.5.5
- CVE-2021-301231 PoCFFmpeg <=4.3 contains a buffer overflow vulnerability in libavcodec through a crafted file that may lead to remote code execution.
- CVE-2021-301283 PoCsUnsafe deserialization in Apache OFBiz
- CVE-2021-301342 PoCsphp-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST…
- CVE-2021-301401 PoCLiquidFiles 3.4.15 has stored XSS through the "send email" functionality when sending a file via email to an administrator. When a file…
- CVE-2021-301451 PoCA format string vulnerability in mpv through 0.33.0 allows user-assisted remote attackers to achieve code execution via a crafted m3u…
- CVE-2021-301461 PoCSeafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality."
- CVE-2021-301472 PoCsDMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.
- CVE-2021-301492 PoCsComposr 10.0.36 allows upload and execution of PHP files.
- CVE-2021-301502 PoCsComposr 10.0.36 allows XSS in an XML script.
- CVE-2021-301512 PoCsSidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.
- CVE-2021-301571 PoCAn issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as…
- CVE-2021-301751 PoCZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page.
- CVE-2021-301801 PoCApache Dubbo RCE on customers via Condition route poisoning (Unsafe YAML unmarshaling)
- CVE-2021-301811 PoCApache Dubbo RCE on customers via Script route poisoning (Nashorn script injection)
- CVE-2021-302032 PoCsA reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers to execute…
- CVE-2021-302121 PoCKnowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in…
- CVE-2021-302132 PoCsKnowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in…
- CVE-2021-302141 PoCKnowage Suite 7.3 is vulnerable to Stored Client-Side Template Injection in '/knowage/restful-services/signup/update' via the 'name'…
- CVE-2021-302241 PoCCross Site Request Forgery (CSRF) in Rukovoditel v2.8.3 allows attackers to create an admin user with an arbitrary credentials.
- CVE-2021-303271 PoCBuffer overflow in sahara protocol while processing commands leads to overwrite of secure configuration data in Snapdragon Mobile,…
- CVE-2021-303571 PoCSSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supplied, which allows…
- CVE-2021-304617 PoCsA remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied…
- CVE-2021-304651 PoCrunc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be…
- CVE-2021-304801 PoCZoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user…
- CVE-2021-304813 PoCsValve Steam through 2021-04-10, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code…
- CVE-2021-304901 PoCupsMonitor in ViewPower (aka ViewPowerHTML) 1.04-21012 through 1.04-21353 has insecure permissions for the service binary that enable an…
- CVE-2021-304931 PoCMultiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the…
- CVE-2021-304941 PoCMultiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the Razer…
- CVE-2021-304971 PoCIvanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. The…
- CVE-2021-304981 PoCA flaw was found in libcaca. A heap buffer overflow in export.c in function export_tga might lead to memory corruption and other potential…
- CVE-2021-304991 PoCA flaw was found in libcaca. A buffer overflow of export.c in function export_troff might lead to memory corruption and other potential…
- CVE-2021-305001 PoCNull pointer dereference was found in upx PackLinuxElf::canUnpack() in p_lx_elf.cpp,in version UPX 4.0.0. That allow attackers to execute…
- CVE-2021-305011 PoCAn assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to cause a denial of…
- CVE-2021-305511 PoCKEVType confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2021-305611 PoCType Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2021-305737 PoCsUse after free in GPU in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2021-306021 PoCUse after free in WebRTC in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to visit a malicious website to…
- CVE-2021-306251 PoCUse after free in Selection API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who convinced the user the visit a…
- CVE-2021-306325 PoCsKEVOut of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2021-306372 PoCshtmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.
- CVE-2021-306411 PoCUnexpected URL matching with 'MergeSlashes OFF'
- CVE-2021-306573 PoCsKEVA logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina.…
- CVE-2021-307311 PoCThis issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-004 Catalina. An…
- CVE-2021-307341 PoCMultiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS…
- CVE-2021-307351 PoCA malicious application may be able to execute arbitrary code with kernel privileges. This issue is fixed in macOS Big Sur 11.4, Security…
- CVE-2021-307408 PoCsA logic issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and…
- CVE-2021-307688 PoCsA logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, macOS Big Sur 11.5, watchOS 7.6, tvOS 14.7,…
- CVE-2021-307698 PoCsA logic issue was addressed with improved state management. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A malicious attacker…
- CVE-2021-307708 PoCsA logic issue was addressed with improved validation. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. An attacker that has…
- CVE-2021-307738 PoCsAn issue in code signature validation was addressed with improved checks. This issue is fixed in iOS 14.7, tvOS 14.7, watchOS 7.6. A…
- CVE-2021-308073 PoCsKEVA memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS…
- CVE-2021-308092 PoCsA use after free issue was addressed with improved memory management. This issue is fixed in Safari 15, tvOS 15, watchOS 8, iOS 15 and…
- CVE-2021-308531 PoCThis issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6. A malicious application may bypass Gatekeeper…
- CVE-2021-308582 PoCsKEVA use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6.…
- CVE-2021-308603 PoCsKEVAn integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and…
- CVE-2021-308622 PoCsA validation issue was addressed with improved input sanitization. This issue is fixed in iTunes U 3.8.3. Processing a maliciously crafted…
- CVE-2021-308833 PoCsKEVA memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, macOS Monterey…
- CVE-2021-309241 PoCA denial of service issue was addressed with improved state handling. This issue is fixed in macOS Monterey 12.0.1. A remote attacker can…
- CVE-2021-309521 PoCKEVAn integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS…
- CVE-2021-309557 PoCsA race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPadOS…
- CVE-2021-309561 PoCA lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is…