CVE-2021-32000 to CVE-2021-32999
119 CVEs with public proof-of-concept exploits.
- CVE-2021-320302 PoCsKEVThe administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows…
- CVE-2021-320333 PoCsProtectimus SLIM NFC 70 10.01 devices allow a Time Traveler attack in which attackers can predict TOTP passwords in certain situations.…
- CVE-2021-320512 PoCsHexagon G!nius Auskunftsportal before 5.0.0.0 allows SQL injection via the GiPWorkflow/Service/DownloadPublicFile id parameter.
- CVE-2021-320996 PoCsA SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his…
- CVE-2021-321321 PoCThe abst_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in…
- CVE-2021-321341 PoCThe gf_odf_desc_copy function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in…
- CVE-2021-321351 PoCThe trak_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in…
- CVE-2021-321361 PoCHeap buffer overflow in the print_udta function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary…
- CVE-2021-321371 PoCHeap buffer overflow in the URL_GetProtocolType function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute…
- CVE-2021-321381 PoCThe DumpTrackInfo function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in…
- CVE-2021-321391 PoCThe gf_isom_vp_config_get function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted…
- CVE-2021-321421 PoCBuffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the…
- CVE-2021-321561 PoCA cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
- CVE-2021-321572 PoCsA Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
- CVE-2021-321581 PoCA Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Upload and Download feature.
- CVE-2021-321591 PoCA Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature.
- CVE-2021-321601 PoCA Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the Add Users feature.
- CVE-2021-321611 PoCA Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the File Manager feature.
- CVE-2021-321621 PoCA Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 through the File Manager feature.
- CVE-2021-321724 PoCsMaian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.
- CVE-2021-322021 PoCIn CS-Cart version 4.11.1, it is possible to induce copy-paste XSS by manipulating the "post description" filed in the blog post creation…
- CVE-2021-322381 PoCEpic Games / Psyonix Rocket League <=1.95 is affected by Buffer Overflow. Stack-based buffer overflow occurs when Rocket League handles…
- CVE-2021-322561 PoCAn issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in…
- CVE-2021-322631 PoCok-file-formats through 2021-04-29 has a heap-based buffer overflow in the ok_csv_circular_buffer_read function in ok_csv.c.
- CVE-2021-322651 PoCAn issue was discovered in Bento4 through v1.6.0-637. A global-buffer-overflow exists in the function AP4_MemoryByteStream::WritePartial()…
- CVE-2021-322681 PoCBuffer overflow vulnerability in function gf_fprintf in os_file.c in gpac before 1.0.1 allows attackers to execute arbitrary code. The…
- CVE-2021-322691 PoCAn issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function ilst_item_box_dump located in…
- CVE-2021-322701 PoCAn issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function vwid_box_del located in…
- CVE-2021-322711 PoCAn issue was discovered in gpac through 20200801. A stack-buffer-overflow exists in the function DumpRawUIConfig located in odf_dump.c. It…
- CVE-2021-322721 PoCAn issue was discovered in faad2 before 2.10.0. A heap-buffer-overflow exists in the function stszin located in mp4read.c. It allows an…
- CVE-2021-322731 PoCAn issue was discovered in faad2 through 2.10.0. A stack-buffer-overflow exists in the function ftypin located in mp4read.c. It allows an…
- CVE-2021-322741 PoCAn issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_synthesis_64 located in sbr_qmf.c.…
- CVE-2021-322751 PoCAn issue was discovered in faust through v2.30.5. A NULL pointer dereference exists in the function CosPrim::computeSigOutput() located in…
- CVE-2021-322761 PoCAn issue was discovered in faad2 through 2.10.0. A NULL pointer dereference exists in the function get_sample() located in output.c. It…
- CVE-2021-322771 PoCAn issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_analysis_32 located in sbr_qmf.c.…
- CVE-2021-322781 PoCAn issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function lt_prediction located in lt_predict.c. It…
- CVE-2021-322811 PoCAn issue was discovered in gravity through 0.8.1. A heap-buffer-overflow exists in the function gnode_function_add_upvalue located in…
- CVE-2021-322821 PoCAn issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function ircode_add_check() located in…
- CVE-2021-322831 PoCAn issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function gravity_string_to_value() located in…
- CVE-2021-322841 PoCAn issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function ircode_register_pop_context_protect()…
- CVE-2021-322851 PoCAn issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function list_iterator_next() located in…
- CVE-2021-322861 PoCAn issue was discovered in hcxtools through 6.1.6. A global-buffer-overflow exists in the function pcapngoptionwalk located in…
- CVE-2021-322871 PoCAn issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function…
- CVE-2021-322881 PoCAn issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function…
- CVE-2021-322891 PoCAn issue was discovered in heif through through v3.6.2. A NULL pointer dereference exists in the function convertByteStreamToRBSP()…
- CVE-2021-322921 PoCAn issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the…
- CVE-2021-322941 PoCAn issue was discovered in libgig through 20200507. A heap-buffer-overflow exists in the function RIFF::List::GetSubList located in…
- CVE-2021-322971 PoCAn issue was discovered in LIEF through 0.11.4. A heap-buffer-overflow exists in the function main located in pe_reader.c. It allows an…
- CVE-2021-322981 PoCAn issue was discovered in libiff through 20190123. A global-buffer-overflow exists in the function IFF_errorId located in error.c. It…
- CVE-2021-322991 PoCAn issue was discovered in pbrt through 20200627. A stack-buffer-overflow exists in the function pbrt::ParamSet::ParamSet() located in…
- CVE-2021-323054 PoCsWebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.
- CVE-2021-323992 PoCsnet/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condition for removal of the HCI controller.
- CVE-2021-324021 PoCIntelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of validation and insecure…
- CVE-2021-324033 PoCsIntelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mechanisms for token…
- CVE-2021-324261 PoCIn TrendNet TW100-S4W1CA 2.3.32, it is possible to inject arbitrary JavaScript into the router's web interface via the "echo" command.
- CVE-2021-324341 PoCabcm2ps v8.14.11 was discovered to contain an out-of-bounds read in the function calculate_beam at draw.c.
- CVE-2021-324351 PoCStack-based buffer overflow in the function get_key in parse.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service…
- CVE-2021-324361 PoCAn out-of-bounds read in the function write_title() in subs.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service…
- CVE-2021-324371 PoCThe gf_hinter_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file…
- CVE-2021-324381 PoCThe gf_media_export_filters function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted…
- CVE-2021-324391 PoCBuffer overflow in the stbl_AppendSize function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary…
- CVE-2021-324401 PoCThe Media_RewriteODFrame function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted…
- CVE-2021-324571 PoCTrend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which…
- CVE-2021-324781 PoCThe redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle…
- CVE-2021-324891 PoCAn issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not correctly validate…
- CVE-2021-325271 PoCQSAN Storage Manager - Path Traversal-2
- CVE-2021-325372 PoCsRealtek High definition audio Windows driver crashed
- CVE-2021-325571 PoCapport process_report() arbitrary file write
- CVE-2021-325681 PoCDeserialization of Untrusted Data in zmister2016/mrdoc
- CVE-2021-326041 PoCShare/IncomingWizard.htm in SolarWinds Serv-U before 15.2.3 mishandles the user-supplied SenderEmail parameter, aka "Share URL XSS."
- CVE-2021-326052 PoCszzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a…
- CVE-2021-326123 PoCsThe VeryFitPro (com.veryfit2hr.second) application 3.2.8 for Android does all communication with the backend API over cleartext HTTP. This…
- CVE-2021-326181 PoCOpen Redirect Vulnerability
- CVE-2021-326331 PoCRemote Code Execution via traversal in TAL expressions
- CVE-2021-326401 PoCReDoS in Sec-Websocket-Protocol header
- CVE-2021-326441 PoCCross-site Scripting in Random.php
- CVE-2021-326483 PoCsKEVAccount Takeover in Octobercms
- CVE-2021-326824 PoCsMultiple vulnerabilities leading to RCE
- CVE-2021-326951 PoCMalicious Android app could access Shared Preferences of the Nextcloud Android client
- CVE-2021-327062 PoCs(Authenticated) Remote Code Execution Possible in Web Interface 5.5
- CVE-2021-327081 PoCTime-of-check Time-of-use (TOCTOU) Race Condition in league/flysystem
- CVE-2021-327181 PoCImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in RabbitMQ management UI
- CVE-2021-327191 PoCImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in RabbitMQ federation management plugin
- CVE-2021-327241 PoCcheck-spelling workflow vulnerable to GITHUB_TOKEN leakage via symlink attack
- CVE-2021-327491 PoCPossible RCE vulnerability in mailing action using mailutils (mail-whois)
- CVE-2021-327511 PoCArbitrary code execution via specially crafted environment variables
- CVE-2021-327893 PoCsArbitrary SQL (SQL injection) possible via the Store API component.
- CVE-2021-327901 PoCBlind SQL Injection possible via Authenticated Web-hook Search API Endpoint
- CVE-2021-328041 PoCArbitrary File Creation/Overwrite due to insufficient absolute path sanitization
- CVE-2021-328161 PoCRegular expression Denial of Service in ProtonMail
- CVE-2021-328171 PoCFile disclosure in express-hbs
- CVE-2021-328193 PoCsRemote code execution in squirrelly
- CVE-2021-328202 PoCsFile disclosure in Express Handlebars
- CVE-2021-328211 PoCRegular expression Denial of Service in MooTools
- CVE-2021-328221 PoCFile disclosure in hbs
- CVE-2021-328241 PoCRegular expression Denial of Service in MooTools
- CVE-2021-328251 PoCZipSlip vulnerability in bblfshd
- CVE-2021-328261 PoCRemote code execution in Proxyee-Down
- CVE-2021-328271 PoCArbitrary code execution in MockServer
- CVE-2021-328291 PoCPost-authentication Remote Code Execution (RCE) in ZStack REST API
- CVE-2021-328301 PoCThe @diez/generation npm package is a client for Diez. The locateFont method of @diez/generation has a command injection vulnerability.…
- CVE-2021-328311 PoCCode injection in total.js
- CVE-2021-328331 PoCUnauthenticated file read in Emby Server
- CVE-2021-328341 PoCArbitrary Groovy script evaluation in Eclipse Keti
- CVE-2021-328351 PoCGroovy Sandbox escape in Eclipse Keti
- CVE-2021-328471 PoCMoby HyperKit uninitialized memory use in virtio-sock pci_vtsock_proc_tx
- CVE-2021-328491 PoCArbitrary command execution in Gerapy
- CVE-2021-328501 PoCjQuery MiniColors vulnerable to Cross-site Scripting
- CVE-2021-328511 PoCjQuery MiniColors vulnerable to Cross-site Scripting
- CVE-2021-328531 PoCErxes vulnerable to Cross-site Scripting
- CVE-2021-328541 PoCtextAngular text editor vulnerable to Cross-site Scripting
- CVE-2021-328551 PoCvditor vulnerable to Cross-site Scripting
- CVE-2021-328561 PoCMicroweber vulnerable to Cross-site Scripting
- CVE-2021-328571 PoCCockpit vulnerable to Cross-site Scripting
- CVE-2021-328581 PoCesdoc-publish-html-plugin vulnerable to Cross-site Scripting
- CVE-2021-328591 PoCBaremetrics date range picker vulnerable to Cross-site Scripting
- CVE-2021-328601 PoCiziModal vulnerable to Cross-site Scripting
- CVE-2021-328622 PoCsnbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
- CVE-2021-329242 PoCsInvision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the…