CVE-2021-33000 to CVE-2021-33999
150 CVEs with public proof-of-concept exploits.
- CVE-2021-330121 PoCRockwell Automation MicroLogix 1100, all versions, allows a remote, unauthenticated attacker sending specially crafted commands to cause…
- CVE-2021-330262 PoCsThe Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code execution or local…
- CVE-2021-330321 PoCA Remote Code Execution (RCE) vulnerability in the WebUI component of the eQ-3 HomeMatic CCU2 firmware up to and including version 2.57.5…
- CVE-2021-330341 PoCIn the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This…
- CVE-2021-330411 PoCvmd through 1.34.0 allows 'div class="markdown-body"' XSS, as demonstrated by Electron remote code execution via…
- CVE-2021-3304422 PoCsKEVThe identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device…
- CVE-2021-3304513 PoCsKEVThe identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device…
- CVE-2021-331041 PoCImproper access control in the Intel(R) OFU software before version 14.1.28 may allow an authenticated user to potentially enable denial…
- CVE-2021-332111 PoCA Directory Traversal vulnerability in the Unzip feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to write…
- CVE-2021-332121 PoCA Cross-site scripting (XSS) vulnerability in the "View in Browser" feature in Elements-IT HTTP Commander 5.3.3 allows remote…
- CVE-2021-332131 PoCAn SSRF vulnerability in the "Upload from URL" feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to retrieve…
- CVE-2021-332141 PoCIn HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive…
- CVE-2021-332161 PoCAn issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via…
- CVE-2021-332212 PoCsAn issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints.
- CVE-2021-332541 PoCAn issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service…
- CVE-2021-332561 PoCA CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an…
- CVE-2021-332591 PoCSeveral web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users'…
- CVE-2021-332651 PoCD-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow…
- CVE-2021-332661 PoCD-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow…
- CVE-2021-332671 PoCD-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow…
- CVE-2021-332681 PoCD-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow…
- CVE-2021-332691 PoCD-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow…
- CVE-2021-332701 PoCD-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow…
- CVE-2021-332711 PoCD-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow…
- CVE-2021-332741 PoCD-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow…
- CVE-2021-332941 PoCIn elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of…
- CVE-2021-332951 PoCCross Site Scripting (XSS) vulnerability in Joplin Desktop App before 1.8.5 allows attackers to execute aribrary code due to improper…
- CVE-2021-333181 PoCAn Input Validation Vulnerability exists in Joel Christner .NET C# packages WatsonWebserver, IpMatcher 1.0.4.1 and below (IpMatcher) and…
- CVE-2021-333511 PoCCross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allows attackers to…
- CVE-2021-333521 PoCAn issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via a phar…
- CVE-2021-333531 PoCDirectory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute…
- CVE-2021-333541 PoCDirectory Traversal vulnerability in htmly before 2.8.1 allows remote attackers to perform arbitrary file deletions via modified file…
- CVE-2021-333571 PoCA vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the "iface" parameter…
- CVE-2021-333611 PoCMemory leak in the afra_box_read function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.
- CVE-2021-333621 PoCStack buffer overflow in the hevc_parse_vps_extension function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or…
- CVE-2021-333641 PoCMemory leak in the def_parent_box_new function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.
- CVE-2021-333661 PoCMemory leak in the gf_isom_oinf_read_entry function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.
- CVE-2021-333711 PoCA stored cross-site scripting (XSS) vulnerability in /nav_bar_action.php of Student Management System v1.0 allows attackers to execute…
- CVE-2021-333934 PoCslfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It might be owned by…
- CVE-2021-333941 PoCCubecart 6.4.2 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious…
- CVE-2021-333961 PoCCross Site Request Forgery (CSRF) vulnerability in baijiacms 4.1.4, allows attackers to change the password or other information of an…
- CVE-2021-334031 PoCAn integer overflow in the transfer function of a smart contract implementation for Lancer Token, an Ethereum ERC20 token, allows the…
- CVE-2021-334371 PoCAn issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There are memory leaks in frozen_cb() in…
- CVE-2021-334381 PoCAn issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow in…
- CVE-2021-334391 PoCAn issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is Integer overflow in…
- CVE-2021-334401 PoCAn issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in…
- CVE-2021-334411 PoCAn issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in…
- CVE-2021-334421 PoCAn issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in…
- CVE-2021-334431 PoCAn issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow in…
- CVE-2021-334441 PoCAn issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in…
- CVE-2021-334451 PoCAn issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in…
- CVE-2021-334461 PoCAn issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in…
- CVE-2021-334471 PoCAn issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in…
- CVE-2021-334481 PoCAn issue was discovered in mjs(mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow at…
- CVE-2021-334491 PoCAn issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in…
- CVE-2021-334512 PoCsAn issue was discovered in lrzip version 0.641. There are memory leaks in fill_buffer() in stream.c.
- CVE-2021-334532 PoCsAn issue was discovered in lrzip version 0.641. There is a use-after-free in ucompthread() in stream.c:1538.
- CVE-2021-334541 PoCAn issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in yasm_expr_get_intnum() in libyasm/expr.c.
- CVE-2021-334551 PoCAn issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in do_directive() in modules/preprocs/nasm/nasm-pp.c.
- CVE-2021-334561 PoCAn issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in hash() in modules/preprocs/nasm/nasm-pp.c.
- CVE-2021-334571 PoCAn issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_mmac_params() in…
- CVE-2021-334581 PoCAn issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in find_cc() in modules/preprocs/nasm/nasm-pp.c.
- CVE-2021-334591 PoCAn issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in nasm_parser_directive() in…
- CVE-2021-334601 PoCAn issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in if_condition() in modules/preprocs/nasm/nasm-pp.c.
- CVE-2021-334611 PoCAn issue was discovered in yasm version 1.3.0. There is a use-after-free in yasm_intnum_destroy() in libyasm/intnum.c.
- CVE-2021-334621 PoCAn issue was discovered in yasm version 1.3.0. There is a use-after-free in expr_traverse_nodes_post() in libyasm/expr.c.
- CVE-2021-334631 PoCAn issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in yasm_expr__copy_except() in libyasm/expr.c.
- CVE-2021-334641 PoCAn issue was discovered in yasm version 1.3.0. There is a heap-buffer-overflow in inc_fopen() in modules/preprocs/nasm/nasm-pp.c.
- CVE-2021-334651 PoCAn issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_mmacro() in modules/preprocs/nasm/nasm-pp.c.
- CVE-2021-334661 PoCAn issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_smacro() in modules/preprocs/nasm/nasm-pp.c.
- CVE-2021-334671 PoCAn issue was discovered in yasm version 1.3.0. There is a use-after-free in pp_getline() in modules/preprocs/nasm/nasm-pp.c.
- CVE-2021-334681 PoCAn issue was discovered in yasm version 1.3.0. There is a use-after-free in error() in modules/preprocs/nasm/nasm-pp.c.
- CVE-2021-334691 PoCCOVID19 Testing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the "Admin name" parameter.
- CVE-2021-334703 PoCsCOVID19 Testing Management System 1.0 is vulnerable to SQL Injection via the admin panel.
- CVE-2021-334772 PoCsrxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of…
- CVE-2021-334802 PoCsAn use-after-free vulnerability was discovered in gocr through 0.53-20200802 in context_correction() in pgm2asc.c.
- CVE-2021-334831 PoCAn issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. The comment posting functionality allows an attacker to add…
- CVE-2021-334841 PoCAn issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. An attacker can download a copy of the installer, decompile…
- CVE-2021-334882 PoCschat in OX App Suite 7.10.5 has Improper Input Validation. A user can be redirected to a rogue OX Chat server via a development-related…
- CVE-2021-334891 PoCOX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file.
- CVE-2021-334901 PoCOX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.
- CVE-2021-334912 PoCsOX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative…
- CVE-2021-334922 PoCsOX App Suite 7.10.5 allows XSS via an OX Chat room name.
- CVE-2021-334932 PoCsThe middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format.
- CVE-2021-334942 PoCsOX App Suite 7.10.5 allows XSS via an OX Chat room title during typing rendering.
- CVE-2021-334952 PoCsOX App Suite 7.10.5 allows XSS via an OX Chat system message.
- CVE-2021-335012 PoCsOverwolf Client 0.169.0.22 allows XSS, with resultant Remote Code Execution, via an overwolfstore:// URL.
- CVE-2021-335031 PoCAn issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the…
- CVE-2021-335141 PoCCertain NETGEAR devices are affected by command injection by an unauthenticated attacker via the vulnerable /sqfs/lib/libsal.so.0.0…
- CVE-2021-335431 PoCUDP Technology/Geutebrück camera devices: Authentication Bypass
- CVE-2021-335442 PoCsUDP Technology/Geutebrück camera devices: command injection leading to RCE
- CVE-2021-335481 PoCUDP Technology/Geutebrück camera devices: Command injection in preserve parameter leading to RCE
- CVE-2021-335492 PoCsUDP Technology/Geutebrück camera devices: Buffer overflow in action parameter leading to RCE
- CVE-2021-335501 PoCUDP Technology/Geutebrück camera devices: Command injection in date parameter leading to RCE
- CVE-2021-335511 PoCUDP Technology/Geutebrück camera devices: Command injection in environment.lang parameter leading to RCE
- CVE-2021-335521 PoCUDP Technology/Geutebrück camera devices: Command injection in date parameter leading to RCE
- CVE-2021-335531 PoCUDP Technology/Geutebrück camera devices: Command injection in command parameter leading to RCE
- CVE-2021-335541 PoCUDP Technology/Geutebrück camera devices: Command injection in appfile.filename parameter leading to RCE
- CVE-2021-335583 PoCsBoa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js,…
- CVE-2021-335611 PoCA stored cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML…
- CVE-2021-335621 PoCA reflected cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or…
- CVE-2021-335644 PoCsAn argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary…
- CVE-2021-335702 PoCsPostbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can result in reading…
- CVE-2021-335901 PoCGattLib 0.3-rc1 has a stack-based buffer over-read in get_device_path_from_mac in dbus/gattlib.c.
- CVE-2021-336171 PoCZoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username…
- CVE-2021-336182 PoCsDolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY…
- CVE-2021-336242 PoCsIn kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and…
- CVE-2021-336782 PoCsA function module of SAP NetWeaver AS ABAP (Reconciliation Framework), versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752,…
- CVE-2021-336902 PoCsServer-Side Request Forgery (SSRF) vulnerability has been detected in the SAP NetWeaver Development Infrastructure Component Build Service…
- CVE-2021-336991 PoCTask Hijacking is a vulnerability that affects the applications running on Android devices due to a misconfiguration in their…
- CVE-2021-337014 PoCsDMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710,…
- CVE-2021-337393 PoCsKEVMicrosoft DWM Core Library Elevation of Privilege Vulnerability
- CVE-2021-337511 PoCWindows Storage Spaces Controller Elevation of Privilege Vulnerability
- CVE-2021-337663 PoCsKEVMicrosoft Exchange Server Information Disclosure Vulnerability
- CVE-2021-337671 PoCOpen Enclave SDK Elevation of Privilege Vulnerability
- CVE-2021-337981 PoCA null pointer dereference was found in libpano13, version libpano13-2.9.20. The flow allows attackers to cause a denial of service and…
- CVE-2021-338071 PoCCartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.
- CVE-2021-338163 PoCsThe website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which…
- CVE-2021-338181 PoCAn issue was discovered in UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67. Attackers can use slowhttptest tool to send incomplete…
- CVE-2021-338201 PoCAn issue was discovered in UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67.Attacker could send a huge amount of TCP SYN packet to make…
- CVE-2021-338221 PoCAn issue was discovered on 4GEE ROUTER HH70VB Version HH70_E1_02.00_22. Attackers can use slowhttptest tool to send incomplete HTTP…
- CVE-2021-338231 PoCAn issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attacker could send a huge amount of TCP SYN packet to make web…
- CVE-2021-338241 PoCAn issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttptest tool to send incomplete HTTP…
- CVE-2021-338291 PoCA cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote…
- CVE-2021-338311 PoCapi/account/register in the TH Wildau COVID-19 Contact Tracing application through 2021-09-01 has Incorrect Access Control. An attacker…
- CVE-2021-338332 PoCsConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or…
- CVE-2021-338391 PoCLuca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because the QR code of a…
- CVE-2021-338511 PoCA cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the…
- CVE-2021-338791 PoCTencent GameLoop before 4.1.21.90 downloaded updates over an insecure HTTP connection. A malicious attacker in an MITM position could…
- CVE-2021-338871 PoCInsufficient verification of data authenticity in Peloton TTR01 up to and including PTV55G allows an attacker with physical access to boot…
- CVE-2021-339043 PoCsIn Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The vendor states…
- CVE-2021-339097 PoCsfs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an…
- CVE-2021-339102 PoCsbasic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving…
- CVE-2021-339251 PoCSQL Injection vulnerability in nitinparashar30 cms-corephp through commit bdabe52ef282846823bda102728a35506d0ec8f9 (May 19, 2021) allows…
- CVE-2021-339281 PoCBuffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of…
- CVE-2021-339291 PoCBuffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial…
- CVE-2021-339301 PoCBuffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a…
- CVE-2021-339381 PoCBuffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial…
- CVE-2021-339451 PoCRICOH Printer series SP products 320DN, SP 325DNw, SP 320SN, SP 320SFN, SP 325SNw, SP 325SFNw, SP 330SN, Aficio SP 3500SF, SP 221S, SP…
- CVE-2021-339591 PoCPlex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.
- CVE-2021-339661 PoCCross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via crafted GET…
- CVE-2021-339701 PoCBuffer Overflow vulnerability in Qihoo 360 Chrome v13.0.2170.0 allows attacker to escalate priveleges.
- CVE-2021-339711 PoCQihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Total Security (http://www.360totalsecurity.com/) is…
- CVE-2021-339721 PoCBuffer Overflow vulnerability in Qihoo 360 Safe Browser v13.0.2170.0 allows attacker to escalate priveleges.
- CVE-2021-339731 PoCBuffer Overflow vulnerability in Qihoo 360 Safe guard v12.1.0.1004, v12.1.0.1005, v13.1.0.1001 allows attacker to escalate priveleges.
- CVE-2021-339741 PoCQihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Chrome (https://browser.360.cn/ee/) is affected by:…
- CVE-2021-339751 PoCBuffer Overflow vulnerability in Qihoo 360 Total Security v10.8.0.1060 and v10.8.0.1213 allows attacker to escalate privileges.
- CVE-2021-339831 PoCBuffer Overflow vulnerability in Dvidelabs flatcc v.0.6.0 allows local attacker to execute arbitrary code via the fltacc execution of the…
- CVE-2021-339881 PoCCross Site Scripting (XSS). vulnerability exists in Microweber CMS 1.2.7 via the Login form, which could let a malicious user execute…
- CVE-2021-339903 PoCsLiferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes…