CVE-2021-35000 to CVE-2021-35999
61 CVEs with public proof-of-concept exploits.
- CVE-2021-3504211 PoCsDjango 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a…
- CVE-2021-350451 PoCCross site scripting (XSS) vulnerability in Ice Hrm 29.0.0.OS, allows attackers to execute arbitrary code via the parameters to the /app/…
- CVE-2021-350461 PoCA session fixation vulnerability was discovered in Ice Hrm 29.0.0 OS which allows an attacker to hijack a valid user session via a crafted…
- CVE-2021-350471 PoCPrivileged Command Injection Vulnerability in Fidelis Network and Deception
- CVE-2021-350481 PoCUnauthenticated SQL Injection Vulnerability in Fidelis Network and Deception
- CVE-2021-350491 PoCCommand Injection Vulnerability in Fidelis Network and Deception
- CVE-2021-350501 PoCUser Credentials Stored in a Recoverable Format within Fidelis Network and Deception
- CVE-2021-350611 PoCMultiple cross-site scripting (XSS) vulnerabilities in DRK Odenwaldkreis Testerfassung March-2021 allow remote attackers to inject…
- CVE-2021-350621 PoCA Shell Metacharacter Injection vulnerability in result.php in DRK Odenwaldkreis Testerfassung March-2021 allow an attacker with a valid…
- CVE-2021-350644 PoCsKramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits running of multiple…
- CVE-2021-350651 PoCThe glob-parent package before 6.0.1 for Node.js allows ReDoS (regular expression denial of service) attacks against the enclosure regular…
- CVE-2021-351931 PoCPatterson Application Service in Patterson Eaglesoft 18 through 21 accepts the same certificate authentication across different customers'…
- CVE-2021-351961 PoCManuskript through 0.12.0 allows remote attackers to execute arbitrary code via a crafted settings.pickle file in a project file, because…
- CVE-2021-352115 PoCsKEVServ-U Remote Memory Escape Vulnerability
- CVE-2021-352151 PoCActionPluginBaseView Deserialization of Untrusted Data RCE
- CVE-2021-352502 PoCsDirectory Transversal Vulnerability in Serv-U 15.3
- CVE-2021-352651 PoCA reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject…
- CVE-2021-352961 PoCAn issue in the administrator authentication panel of PTCL HG150-Ub v3.0 allows attackers to bypass authentication via modification of the…
- CVE-2021-353061 PoCAn issue was discovered in Bento4 through v1.6.0-636. A NULL pointer dereference exists in the function AP4_StszAtom::WriteFields located…
- CVE-2021-353071 PoCAn issue was discovered in Bento4 through v1.6.0-636. A NULL pointer dereference exists in the AP4_DescriptorFinder::Test component…
- CVE-2021-353123 PoCsA vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Service.exe" has…
- CVE-2021-353234 PoCsCross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
- CVE-2021-353241 PoCA vulnerability in the Form_Login function of TOTOLINK A720R A720R_Firmware V4.1.5cu.470_B20200911 allows attackers to bypass…
- CVE-2021-353251 PoCA stack overflow in the checkLoginUser function of TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to cause a denial…
- CVE-2021-353261 PoCA vulnerability in TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows attackers to download the configuration file via…
- CVE-2021-353271 PoCA vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the…
- CVE-2021-353362 PoCsTieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control. A vulnerability in the Tieline Web Administrative…
- CVE-2021-353371 PoCSourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any attacker will be able…
- CVE-2021-353441 PoCtsMuxer v2.6.16 was discovered to contain a heap-based buffer overflow via the function BitStreamReader::getCurVal in bitStream.h.
- CVE-2021-353461 PoCtsMuxer v2.6.16 was discovered to contain a heap-based buffer overflow via the function HevcSpsUnit::short_term_ref_pic_set(int) in…
- CVE-2021-353802 PoCsA Directory Traversal vulnerability exists in Solari di Udine TermTalk Server (TTServer) 3.24.0.2, which lets an unauthenticated malicious…
- CVE-2021-353921 PoCRealtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The…
- CVE-2021-353931 PoCRealtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The…
- CVE-2021-353942 PoCsKEVRealtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer'…
- CVE-2021-353952 PoCsKEVRealtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure…
- CVE-2021-354381 PoCphpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of the IP calculator.
- CVE-2021-354482 PoCsEmote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using the Image…
- CVE-2021-354492 PoCsThe Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver…
- CVE-2021-354521 PoCAn Incorrect Access Control vulnerability exists in libde265 v1.0.8 due to a SEGV in slice.cc.
- CVE-2021-354581 PoCOnline Pet Shop We App 1.0 is vulnerable to Union SQL Injection in products.php (aka p=products) via the c or s parameter.
- CVE-2021-354647 PoCsKEVForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages. The…
- CVE-2021-354751 PoCSAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server. The XSS will prompt when editing the…
- CVE-2021-354781 PoCNagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters…
- CVE-2021-354791 PoCNagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log function through the…
- CVE-2021-354871 PoCNokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection attack on the endpoint…
- CVE-2021-354881 PoCThruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title parameter. An attacker…
- CVE-2021-354921 PoCWowza Streaming Engine through 4.8.11+5 could allow an authenticated, remote attacker to exhaust filesystem resources via the…
- CVE-2021-355011 PoCPandoraFMS <=7.54 allows Stored XSS by placing a payload in the name field of a visual console. When a user or an administrator visits the…
- CVE-2021-355031 PoCAfian FileRun 2021.03.26 allows stored XSS via an HTTP X-Forwarded-For header that is mishandled when rendering Activity Logs.
- CVE-2021-355041 PoCAfian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary.
- CVE-2021-355051 PoCAfian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the magick binary.
- CVE-2021-355061 PoCAfian FileRun 2021.03.26 allows XSS when an administrator encounters a crafted document during use of the HTML Editor for a preview or…
- CVE-2021-355081 PoCNMSAccess32.exe in TeraRecon AQNetClient 4.4.13 allows attackers to execute a malicious binary with SYSTEM privileges via a low-privileged…
- CVE-2021-355121 PoCAn SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.
- CVE-2021-355231 PoCSecurepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT…
- CVE-2021-355763 PoCsVulnerability in the Oracle Database Enterprise Edition Unified Audit component of Oracle Database Server. Supported versions that are…
- CVE-2021-355875 PoCsKEVVulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are…
- CVE-2021-356161 PoCVulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: UI Infrastructure). The supported version…
- CVE-2021-359565 PoCsStored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote authenticated…
- CVE-2021-359731 PoCNETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an…
- CVE-2021-359751 PoCAbsolute path traversal vulnerability in the Systematica SMTP Adapter component (up to v2.0.1.101) in Systematica Radius (up to…