CVE-2021-31000 to CVE-2021-31999
112 CVEs with public proof-of-concept exploits.
- CVE-2021-311523 PoCsMultilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can enable remote access,…
- CVE-2021-311593 PoCsZoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in…
- CVE-2021-311621 PoCIn the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the element panics.
- CVE-2021-3116618 PoCsKEVHTTP Protocol Stack Remote Code Execution Vulnerability
- CVE-2021-311691 PoCWindows Container Manager Service Elevation of Privilege Vulnerability
- CVE-2021-311812 PoCsMicrosoft SharePoint Remote Code Execution Vulnerability
- CVE-2021-311841 PoCMicrosoft Windows Infrared Data Association (IrDA) Information Disclosure Vulnerability
- CVE-2021-311951 PoCMicrosoft Exchange Server Remote Code Execution Vulnerability
- CVE-2021-312076 PoCsKEVMicrosoft Exchange Server Security Feature Bypass Vulnerability
- CVE-2021-312291 PoCAn issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd() performs incorrect memory handling while parsing…
- CVE-2021-312391 PoCAn issue found in SQLite SQLite3 v.3.35.4 that allows a remote attacker to cause a denial of service via the appendvfs.c function.
- CVE-2021-312401 PoCAn issue found in libming v.0.4.8 allows a local attacker to execute arbitrary code via the parseSWF_IMPORTASSETS function in the parser.c…
- CVE-2021-312451 PoComr-admin.py in openmptcprouter-vps-admin 0.57.3 and earlier compares the user provided password with the original password in a length…
- CVE-2021-312492 PoCsA CRLF injection vulnerability was found on BF-430, BF-431, and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack…
- CVE-2021-312502 PoCsMultiple storage XSS vulnerabilities were discovered on BF-430, BF-431 and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due…
- CVE-2021-312512 PoCsAn authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows…
- CVE-2021-312521 PoCAn open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices from CHIYU…
- CVE-2021-312541 PoCBuffer overflow in the tenc_box_read function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary…
- CVE-2021-312551 PoCBuffer overflow in the abst_box_read function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary…
- CVE-2021-312561 PoCMemory leak in the stbl_GetSampleInfos function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.
- CVE-2021-312571 PoCThe HintFile function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the…
- CVE-2021-312581 PoCThe gf_isom_set_extraction_slc function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a…
- CVE-2021-312591 PoCThe gf_isom_cenc_get_default_info_internal function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference)…
- CVE-2021-312601 PoCThe MergeTrack function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the…
- CVE-2021-312611 PoCThe gf_hinter_track_new function in GPAC 1.0.1 allows attackers to read memory via a crafted file in the MP4Box command.
- CVE-2021-312621 PoCThe AV1_DuplicateConfig function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file…
- CVE-2021-312801 PoCAn issue was discovered in tp5cms through 2017-05-25. admin.php/system/set.html has XSS via the keywords parameter.
- CVE-2021-313151 PoCTelegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the blit function of…
- CVE-2021-313162 PoCsThe unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.
- CVE-2021-313171 PoCTelegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the VDasher constructor of…
- CVE-2021-313181 PoCTelegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the…
- CVE-2021-313191 PoCTelegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the…
- CVE-2021-313201 PoCTelegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the…
- CVE-2021-313211 PoCTelegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the gray_split_cubic…
- CVE-2021-313221 PoCTelegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the…
- CVE-2021-313231 PoCTelegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the…
- CVE-2021-313242 PoCsThe unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code…
- CVE-2021-313261 PoCD-Link DIR-816 A2 1.10 B05 allows unauthenticated attackers to arbitrarily reset the device via a crafted tokenid parameter to…
- CVE-2021-313272 PoCsStored XSS in Remote Clinic v2.0 in /medicines due to Medicine Name Field.
- CVE-2021-313292 PoCsCross Site Scripting (XSS) in Remote Clinic v2.0 via the "Chat" and "Personal Address" field on staff/register.php
- CVE-2021-314402 PoCsThis vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An attacker must first…
- CVE-2021-315354 PoCsLookupCol.c in X.Org X through X11R7.7 and libX11 before 1.7.1 might allow remote attackers to execute arbitrary code. The libX11…
- CVE-2021-315372 PoCsSIS SIS-REWE Go before 7.7 SP17 allows XSS: rewe/prod/web/index.php (affected parameters are config, version, win, db, pwd, and user) and…
- CVE-2021-315381 PoCLANCOM R&S Unified Firewall (UF) devices running LCOS FX 10.5 allow Relative Path Traversal.
- CVE-2021-315811 PoCAkkadian Provisioning Manager Engine (PME) Shell Escape via 'vi' editor interface
- CVE-2021-315832 PoCsSipwise C5 NGCP WWW Admin version 3.6.7 up to and including platform version NGCP CE 3.0 has multiple authenticated stored and reflected…
- CVE-2021-315841 PoCSipwise C5 NGCP www_csc version 3.6.4 up to and including platform NGCP CE mr3.8.13 allows call/click2dial CSRF attacks for actions with…
- CVE-2021-315894 PoCsA cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version…
- CVE-2021-315991 PoCAn issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. A reports (.prpt)…
- CVE-2021-316001 PoCAn issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a…
- CVE-2021-316011 PoCAn issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a…
- CVE-2021-316026 PoCsAn issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model…
- CVE-2021-316041 PoCfurlongm openvpn-monitor through 1.1.3 allows CSRF to disconnect an arbitrary client.
- CVE-2021-316072 PoCsIn SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exists in the snapper module that allows for local privilege…
- CVE-2021-316161 PoCInsufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.1.0 allow a stack buffer overflow via crafted…
- CVE-2021-316241 PoCBuffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318), and AC9 V3.0 V15.03.06.42_multi, allows attackers to execute…
- CVE-2021-316271 PoCBuffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318), and AC9 V3.0 V15.03.06.42_multi, allows attackers to execute…
- CVE-2021-3163018 PoCsCommand Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component…
- CVE-2021-316412 PoCsAn unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-430, BF-431,…
- CVE-2021-316423 PoCsA denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass,…
- CVE-2021-316432 PoCsAn XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a…
- CVE-2021-316451 PoCAn issue was discovered in glFTPd 2.11a that allows remote attackers to cause a denial of service via exceeding the connection limit.
- CVE-2021-316501 PoCA SQL injection vulnerability in Sourcecodester Online Grading System 1.0 allows remote attackers to execute arbitrary SQL commands via…
- CVE-2021-316551 PoCCross Site Scripting (XSS) vulnerability in TRENDnet TV-IP110WN V1.2.2.64 V1.2.2.65 V1.2.2.68 via the profile parameter. in a GET request…
- CVE-2021-316581 PoCTP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is affected by an Array index error. The interface that provides the…
- CVE-2021-316591 PoCTP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is vulnerable to Cross Site Request Forgery (CSRF). All configuration…
- CVE-2021-316732 PoCsA Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remote attackers to…
- CVE-2021-316741 PoCCyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute…
- CVE-2021-316762 PoCsA reflected XSS was discovered in PESCMS-V2.3.3. When combined with CSRF in the same file, they can cause bigger destruction.
- CVE-2021-316771 PoCAn issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can modify admin and other members' passwords.
- CVE-2021-316783 PoCsAn issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can delete import information about a user's company.
- CVE-2021-316792 PoCsAn issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that allows attackers to delete admin and other members' account…
- CVE-2021-316801 PoCDeserialization of Untrusted Data vulnerability in yolo 5 allows attackers to execute arbitrary code via crafted yaml file.
- CVE-2021-316811 PoCDeserialization of Untrusted Data vulnerability in yolo 3 allows attackers to execute arbitrary code via crafted yaml file.
- CVE-2021-316823 PoCsThe login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS…
- CVE-2021-316841 PoCA vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of…
- CVE-2021-316981 PoCQuectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shell metacharacters…
- CVE-2021-317021 PoCFrontier ichris through 5.18 mishandles making a DNS request for the hostname in the HTTP Host header, as demonstrated by submitting…
- CVE-2021-317031 PoCFrontier ichris through 5.18 allows users to upload malicious executable files that might later be downloaded and run by any client user.
- CVE-2021-317212 PoCsChevereto before 3.17.1 allows Cross Site Scripting (XSS) via an image title at the image upload stage.
- CVE-2021-317272 PoCsIncorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 where IOCTL's 0x80002014, 0x80002018 expose…
- CVE-2021-317282 PoCsIncorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 allows a non-privileged process to open a handle to…
- CVE-2021-317371 PoCemlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/data.php.
- CVE-2021-317381 PoCAdiscon LogAnalyzer 4.1.10 and 4.1.11 allow login.php XSS.
- CVE-2021-317552 PoCsKEVAn issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in…
- CVE-2021-317561 PoCAn issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in…
- CVE-2021-317571 PoCAn issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in…
- CVE-2021-317582 PoCsAn issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in…
- CVE-2021-317604 PoCsWebmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's running process…
- CVE-2021-317615 PoCsWebmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process…
- CVE-2021-317625 PoCsWebmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get…
- CVE-2021-317691 PoCMyQ Server in MyQ X Smart before 8.2 allows remote code execution by unprivileged users because administrative session data can be read in…
- CVE-2021-317771 PoCThe dce (aka Dynamic Content Element) extension 2.2.0 through 2.6.x before 2.6.2, and 2.7.x before 2.7.1, for TYPO3 allows SQL Injection…
- CVE-2021-317951 PoCThe PowerVR GPU kernel driver in pvrsrvkm.ko through 2021-04-24 for the Linux kernel, as used on Alcatel 1S phones, allows attackers to…
- CVE-2021-317961 PoCAn inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Disclosure. An…
- CVE-2021-317991 PoCIn RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in…
- CVE-2021-318003 PoCsMultiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver…
- CVE-2021-318022 PoCsNETGEAR R7000 1.0.11.116 devices have a heap-based Buffer Overflow that is exploitable from the local network without authentication. The…
- CVE-2021-3180512 PoCsForced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
- CVE-2021-318131 PoCZoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted…
- CVE-2021-318151 PoCGAEN (aka Google/Apple Exposure Notifications) through 2021-04-27 on Android allows attackers to obtain sensitive information, such as a…
- CVE-2021-318261 PoCShibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature. The flaw…
- CVE-2021-318562 PoCsA SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL commands via the…
- CVE-2021-318622 PoCsSysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication.
- CVE-2021-318671 PoCPimcore Customer Data Framework 'SegmentAssignmentController.php' Blind SQL Injection
- CVE-2021-318691 PoCPimcore AdminBundle 'specificID' SQL Injection
- CVE-2021-318741 PoCZoho ManageEngine ADSelfService Plus before 6104, in rare situations, allows attackers to obtain sensitive information about the…
- CVE-2021-319321 PoCNokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all…
- CVE-2021-319332 PoCsA remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file…
- CVE-2021-319502 PoCsMicrosoft SharePoint Server Spoofing Vulnerability
- CVE-2021-319552 PoCsKEVWindows Kernel Information Disclosure Vulnerability
- CVE-2021-319568 PoCsKEVWindows NTFS Elevation of Privilege Vulnerability