CVE-2021-34000 to CVE-2021-34999
80 CVEs with public proof-of-concept exploits.
- CVE-2021-340551 PoCjhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.
- CVE-2021-340661 PoCAn issue was discovered in EdgeGallery/developer before v1.0. There is a "Deserialization of yaml file" vulnerability that can allow…
- CVE-2021-340671 PoCHeap based buffer overflow in tsMuxer 2.6.16 allows attackers to cause a Denial of Service (DoS) by running the application with a crafted…
- CVE-2021-340681 PoCHeap based buffer overflow in tsMuxer 2.6.16 allows attackers to cause a Denial of Service (DoS) by running the application with a crafted…
- CVE-2021-340691 PoCDivide-by-zero bug in tsMuxer 2.6.16 allows attackers to cause a Denial of Service (DoS) by running the application with a crafted file.
- CVE-2021-340701 PoCOut-of-bounds Read in tsMuxer 2.6.16 allows attackers to cause a Denial of Service (DoS) by running the application with a crafted file.
- CVE-2021-340711 PoCHeap based buffer overflow in tsMuxer 2.6.16 allows attackers to cause a Denial of Service (DoS) by running the application with a crafted…
- CVE-2021-340731 PoCA Cross Site Scripting (XSS) vulnerabilty exists in Sourcecodester Gadget Works Online Ordering System in PHP/MySQLi 1.0 via the Category…
- CVE-2021-340761 PoCFile Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges via crafted zip…
- CVE-2021-340851 PoCRead access violation in the III_dequantize_sample function in mpglibDBL/layer3.c in mp3gain through 1.5.2-r2 allows remote attackers to…
- CVE-2021-341102 PoCsWinWaste.NET version 1.0.6183.16475 has incorrect permissions, allowing a local unprivileged user to replace the executable with a…
- CVE-2021-341191 PoCA flaw was discovered in htmodoc 1.9.12 in function parse_paragraph in ps-pdf.cxx ,this flaw possibly allows possible code execution and a…
- CVE-2021-341211 PoCAn Out of Bounds flaw was discovered in htmodoc 1.9.12 in function parse_tree() in toc.cxx, this possibly leads to memory layout…
- CVE-2021-341221 PoCThe function bitstr_tell at bitstr.c in ffjpeg commit 4ab404e has a NULL pointer dereference.
- CVE-2021-341252 PoCsAn issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive information via…
- CVE-2021-341281 PoCLaikeTui 3.5.0 allows remote authenticated users to execute arbitrary PHP code by using index.php?module=system&action=pay to upload a ZIP…
- CVE-2021-341641 PoCPermissions vulnerability in LIZHIFAKA v.2.2.0 allows authenticated attacker to execute arbitrary commands via the set password function…
- CVE-2021-341651 PoCA SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authentication and become Admin.
- CVE-2021-341661 PoCA SQL INJECTION vulnerability in Sourcecodester Simple Food Website 1.0 allows a remote attacker to Bypass Authentication and become Admin.
- CVE-2021-341671 PoCCross Site Request Forgery (CSRF) vulnerability in taoCMS 3.0.2 allows remote attackers to gain escalated privileges via…
- CVE-2021-341701 PoCBandai Namco FromSoftware Dark Souls III allows remote attackers to execute arbitrary code.
- CVE-2021-341731 PoCAn attacker can cause a Denial of Service and kernel panic in v4.2 and earlier versions of Espressif esp32 via a malformed beacon csa…
- CVE-2021-341741 PoCA vulnerability exists in Broadcom BCM4352 and BCM43684 chips. Any wireless router using BCM4352 and BCM43684 will be affected, such as…
- CVE-2021-341872 PoCsmain/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.
- CVE-2021-341901 PoCA stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute…
- CVE-2021-342011 PoCD-Link DIR-2640-US 1.01B04 is vulnerable to Buffer Overflow. There are multiple out-of-bounds vulnerabilities in some processes of D-Link…
- CVE-2021-342021 PoCThere are multiple out-of-bounds vulnerabilities in some processes of D-Link AC2600(DIR-2640) 1.01B04. Ordinary permissions can be…
- CVE-2021-342031 PoCD-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control. Router ac2600 (dir-2640-us), when setting PPPoE, will start quagga…
- CVE-2021-342351 PoCTokheim Profleet DiaLOG 11.005.02 is affected by SQL Injection. The component is the Field__UserLogin parameter on the logon page.
- CVE-2021-342431 PoCA stored cross site scripting (XSS) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to execute arbitrary web…
- CVE-2021-342441 PoCA cross site request forgery (CSRF) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to create new admin accounts…
- CVE-2021-342492 PoCsSQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote attackers to view sensitive information via the id…
- CVE-2021-342572 PoCsMultiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's…
- CVE-2021-343381 PoCMing 0.4.8 has an out-of-bounds buffer overwrite issue in the function getName() in decompiler.c file that causes a direct segmentation…
- CVE-2021-343391 PoCMing 0.4.8 has an out-of-bounds buffer access issue in the function getString() in decompiler.c file that causes a direct segmentation…
- CVE-2021-343401 PoCMing 0.4.8 has an out-of-bounds buffer access issue in the function decompileINCR_DECR() in decompiler.c file that causes a direct…
- CVE-2021-343411 PoCMing 0.4.8 has an out-of-bounds read vulnerability in the function decompileIF() in the decompile.c file that causes a direct segmentation…
- CVE-2021-343421 PoCMing 0.4.8 has an out-of-bounds read vulnerability in the function newVar_N() in decompile.c which causes a huge information leak.
- CVE-2021-343692 PoCsportlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensitive information via…
- CVE-2021-343703 PoCsAccela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are configurable…
- CVE-2021-343714 PoCsNeo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects, e.g., through…
- CVE-2021-344275 PoCsIn Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote…
- CVE-2021-344281 PoCFor Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method,…
- CVE-2021-344294 PoCsFor Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the…
- CVE-2021-344301 PoCEclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the…
- CVE-2021-344351 PoCIn Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with…
- CVE-2021-344702 PoCsMicrosoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2021-3447312 PoCsKEVMicrosoft Exchange Server Remote Code Execution Vulnerability
- CVE-2021-344812 PoCsWindows Print Spooler Remote Code Execution Vulnerability
- CVE-2021-344863 PoCsKEVWindows Event Tracing Elevation of Privilege Vulnerability
- CVE-2021-344961 PoCWindows GDI Information Disclosure Vulnerability
- CVE-2021-345237 PoCsKEVMicrosoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2021-3452732 PoCsKEVWindows Print Spooler Remote Code Execution Vulnerability
- CVE-2021-345431 PoCThe web administration server in Solar-Log 500 before 2.8.2 Build 52 does not require authentication, which allows remote attackers to…
- CVE-2021-345441 PoCAn issue was discovered in Solar-Log 500 before 2.8.2 Build 52 23.04.2013. In /export.html, email.html, and sms.html, cleartext passwords…
- CVE-2021-345461 PoCAn unauthenticated attacker with physical access to a computer with NetSetMan Pro before 5.0 installed, that has the pre-logon profile…
- CVE-2021-345551 PoCOpenDMARC 1.4.1 and 1.4.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a…
- CVE-2021-345581 PoCThe crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the…
- CVE-2021-345932 PoCsCODESYS V2 runtime: unauthenticated invalid requests may result in denial-of-service
- CVE-2021-346002 PoCsTelenot complex: Insecure AES Key Generation
- CVE-2021-346051 PoCXinje XD/E Series PLC Program Tool Zip Slip
- CVE-2021-346061 PoCXINJE XD/E Series PLC Program Tool DLL Hijacking
- CVE-2021-346216 PoCsProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation
- CVE-2021-346221 PoCProfilePress 3.0 - 3.1.3 - Authenticated Privilege Escalation
- CVE-2021-346241 PoCProfilePress 3.0 - 3.1.3 - Arbitrary File Upload in File Uploader Component
- CVE-2021-346301 PoCReflected XSS in GTranslate Pro and GTranslate Enterprise < 2.8.65
- CVE-2021-346401 PoCSecurimage-WP-Fixed <= 3.5.4 Reflected Cross-Site Scripting
- CVE-2021-346431 PoCSkaut bazar <= 1.3.2 Reflected Cross-Site Scripting
- CVE-2021-346463 PoCsBooster for WooCommerce <= 5.4.3 Authentication Bypass
- CVE-2021-346571 PoCTypoFR <= 0.11 Reflected Cross-Site Scripting
- CVE-2021-346751 PoCBasix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports.
- CVE-2021-346761 PoCBasix NEX-Forms through 7.8.7 allows authentication bypass for Excel report generation.
- CVE-2021-346821 PoCReceita Federal IRPF 2021 1.7 allows a man-in-the-middle attack against the update feature.
- CVE-2021-346841 PoCHitachi Vantara Pentaho Business Analytics through 9.1 allows an unauthenticated user to execute arbitrary SQL queries on any Pentaho data…
- CVE-2021-346851 PoCUploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, which allows an…
- CVE-2021-346931 PoCnet/can/bcm.c in the Linux kernel through 5.12.10 allows local users to obtain sensitive information from kernel stack memory because…
- CVE-2021-347301 PoCCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Remote Command Execution and Denial of Service Vulnerability
- CVE-2021-347671 PoCCisco IOS XE Software for Catalyst 9800 Series Wireless Controllers IPv6 Denial of Service Vulnerability
- CVE-2021-348053 PoCsAn issue was discovered in FAUST iServer before 9.0.019.019.7. For each URL request, it accesses the corresponding .fau file on the…
- CVE-2021-348241 PoCIstio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and…