CVE-2021-37000 to CVE-2021-37999
112 CVEs with public proof-of-concept exploits.
- CVE-2021-371441 PoCCSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user input might…
- CVE-2021-371521 PoCMultiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML…
- CVE-2021-371571 PoCAn issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. $HOME/OGP/Cfg/Config.pm has the root password in cleartext.
- CVE-2021-371581 PoCAn issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. An authenticated attacker could inject OS commands by…
- CVE-2021-372161 PoCQSAN Storage Manager - Reflected Cross-Site Scripting
- CVE-2021-372201 PoCMuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a…
- CVE-2021-372211 PoCA file upload vulnerability exists in Sourcecodester Customer Relationship Management System 1.0 via the account update option & customer…
- CVE-2021-372533 PoCsM-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range or Request-Range…
- CVE-2021-372911 PoCAn SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in…
- CVE-2021-372921 PoCAn Access Control vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 due to an undocumented backdoor…
- CVE-2021-373042 PoCsAn Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive…
- CVE-2021-373051 PoCAn Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive…
- CVE-2021-373151 PoCIncorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote…
- CVE-2021-373161 PoCSQL injection vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to…
- CVE-2021-373171 PoCDirectory Traversal vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers…
- CVE-2021-373221 PoCGCC c++filt v2.26 was discovered to contain a use-after-free vulnerability via the component cplus-dem.c.
- CVE-2021-373301 PoCLaravel Booking System Booking Core 2.0 is vulnerable to Cross Site Scripting (XSS). The Avatar upload in the My Profile section could be…
- CVE-2021-373311 PoCLaravel Booking System Booking Core 2.0 is vulnerable to Incorrect Access Control. On the Verifications page, after uploading an ID Card…
- CVE-2021-373331 PoCLaravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at…
- CVE-2021-373432 PoCsA path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE…
- CVE-2021-373541 PoCXerox Phaser 4622 v35.013.01.000 was discovered to contain a buffer overflow in the function sub_3226AC via the TIMEZONE variable. This…
- CVE-2021-373581 PoCSQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component…
- CVE-2021-373631 PoCAn Insecure Permissions issue exists in Gestionale Open 11.00.00. A low privilege account is able to rename the mysqld.exe file located in…
- CVE-2021-373641 PoCOpenClinic GA 5.194.18 is affected by Insecure Permissions. By default the Authenticated Users group has the modify permission to…
- CVE-2021-373731 PoCCross Site Scripting (XSS) vulnerability in Teradek Slice 1st generation firmware 7.3.x and earlier allows remote attackers to run…
- CVE-2021-373741 PoCCross Site Scripting (XSS) vulnerability in Teradek Clip all firmware versions allows remote attackers to run arbitrary code via the…
- CVE-2021-373751 PoCCross Site Scripting (XSS) vulnerability in Teradek VidiU / VidiU Mini firmware version 3.0.8 and earlier allows remote attackers to run…
- CVE-2021-373761 PoCCross Site Scripting (XSS) vulnerability in Teradek Bond, Bond 2 and Bond Pro firmware version 7.3.x and earlier allows remote attackers…
- CVE-2021-373771 PoCCross Site Scripting (XSS) vulnerability in Teradek Brik firmware version 7.2.x and earlier allows remote attackers to run arbitrary code…
- CVE-2021-373781 PoCCross Site Scripting (XSS) vulnerability in Teradek Cube and Cube Pro firmware version 7.3.x and earlier allows remote attackers to run…
- CVE-2021-373791 PoCCross Site Scripting (XSS) vulnerability in Teradek Sphere all firmware versions allows remote attackers to run arbitrary code via the…
- CVE-2021-373811 PoCSouthsoft GMIS 5.0 is vulnerable to CSRF attacks. Attackers can access other users' private information such as photos through CSRF. For…
- CVE-2021-373881 PoCA buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the…
- CVE-2021-373891 PoCChamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter.
- CVE-2021-373901 PoCA Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature).
- CVE-2021-373912 PoCsA user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through…
- CVE-2021-374151 PoCKEVZoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without…
- CVE-2021-374161 PoCZoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.
- CVE-2021-374191 PoCZoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF.
- CVE-2021-374201 PoCZoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing.
- CVE-2021-374253 PoCsAltova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or…
- CVE-2021-374391 PoCNCH FlexiServer v6.00 suffers from a syslog?file=/.. path traversal vulnerability.
- CVE-2021-374401 PoCNCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/.. substring.
- CVE-2021-374411 PoCNCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/.. substring.
- CVE-2021-374421 PoCNCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/.. to read files.
- CVE-2021-374431 PoCNCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion.
- CVE-2021-374441 PoCNCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to…
- CVE-2021-374451 PoCIn NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/.. for file reading.
- CVE-2021-374461 PoCIn NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentprop?file=/.. for file reading.
- CVE-2021-374471 PoCIn NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentdelete?file=/.. for file deletion.
- CVE-2021-374481 PoCCross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via the Mailbox name (stored).
- CVE-2021-374491 PoCCross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmlist?folder= (reflected).
- CVE-2021-374501 PoCCross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected).
- CVE-2021-374511 PoCCross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected).
- CVE-2021-374521 PoCNCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat…
- CVE-2021-374531 PoCCross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored).
- CVE-2021-374541 PoCCross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).
- CVE-2021-374551 PoCCross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored).
- CVE-2021-374561 PoCCross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored).
- CVE-2021-374571 PoCCross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).
- CVE-2021-374581 PoCCross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).
- CVE-2021-374591 PoCCross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored).
- CVE-2021-374601 PoCCross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /planprop?id= (reflected).
- CVE-2021-374611 PoCCross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /extensionsinstruction?id= (reflected).
- CVE-2021-374621 PoCCross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /ipblacklist?errorip= (reflected).
- CVE-2021-374631 PoCIn NCH Quorum v2.03 and earlier, XSS exists via User Display Name (stored).
- CVE-2021-374641 PoCIn NCH Quorum v2.03 and earlier, XSS exists via Conference Description (stored).
- CVE-2021-374651 PoCIn NCH Quorum v2.03 and earlier, XSS exists via /uploaddoc?id= (reflected).
- CVE-2021-374661 PoCIn NCH Quorum v2.03 and earlier, XSS exists via /conference?id= (reflected).
- CVE-2021-374671 PoCIn NCH Quorum v2.03 and earlier, XSS exists via /conferencebrowseuploadfile?confid= (reflected).
- CVE-2021-374681 PoCNCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files.
- CVE-2021-374691 PoCIn NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/.. path traversal to read files on the filesystem.
- CVE-2021-374701 PoCIn NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user can add or modify…
- CVE-2021-374971 PoCSQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request.
- CVE-2021-375011 PoCBuffer Overflow vulnerability in HDFGroup hdf5-h5dump 1.12.0 through 1.13.0 allows attackers to cause a denial of service via…
- CVE-2021-375191 PoCBuffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file.
- CVE-2021-375291 PoCA double-free vulnerability exists in fig2dev through 3.28a is affected by: via the free_stream function in readpics.c, which could cause…
- CVE-2021-375382 PoCsMultiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to…
- CVE-2021-375734 PoCsA reflected cross-site scripting (XSS) vulnerability in the web server TTiny Java Web Server and Servlet Container (TJWS) <=1.115 allows…
- CVE-2021-375809 PoCsApache ShenYu Admin bypass JWT authentication
- CVE-2021-375894 PoCsVirtua Cobranca before 12R allows SQL Injection on the login page.
- CVE-2021-375934 PoCsPEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQL query in order…
- CVE-2021-375981 PoCWP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.
- CVE-2021-376001 PoCAn integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use system resources…
- CVE-2021-376241 PoCFreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofing
- CVE-2021-376781 PoCArbitrary code execution due to YAML deserialization
- CVE-2021-377041 PoCExposed phpinfo() in PhpFastCache
- CVE-2021-377401 PoCA denial of service vulnerability exists in MDT's firmware for the KNXnet/IP Secure router SCN-IP100.03 and KNX IP interface SCN-IP000.03…
- CVE-2021-377482 PoCsMultiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote…
- CVE-2021-377741 PoCAn issue was discovered in function httpProcDataSrv in TL-WDR7660 2.0.30 that allows attackers to execute arbitrary code.
- CVE-2021-377771 PoCGila CMS 2.2.0 is vulnerable to Insecure Direct Object Reference (IDOR). Thumbnails uploaded by one site owner are visible by another site…
- CVE-2021-377871 PoCThe unprivileged administrative interface in ABO.CMS version 5.8 through v.5.9.3 is affected by a SQL Injection vulnerability via a HTTP…
- CVE-2021-377881 PoCA vulnerability in the web UI of Gurock TestRail v5.3.0.3603 could allow an unauthenticated, remote attacker to affect the integrity of a…
- CVE-2021-377891 PoCstb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service.
- CVE-2021-377911 PoCMyAdmin v1.0 is affected by an incorrect access control vulnerability in viewing personal center in /api/user/userData?userCode=admin.
- CVE-2021-378031 PoCAn SQL Injection vulnerability exists in Sourcecodester Online Covid Vaccination Scheduler System 1.0 via the username in lognin.php .
- CVE-2021-378051 PoCA Stored Cross Site Scripting (XSS) vunerability exists in Sourcecodeste Vehicle Parking Management System affected version 1.0 is via the…
- CVE-2021-378062 PoCsAn SQL Injection vulnerability exists in https://phpgurukul.com Vehicle Parking Management System affected version 1.0. The system is…
- CVE-2021-378071 PoCAn SQL Injection vulneraility exists in https://phpgurukul.com Online Shopping Portal 3.1 via the email parameter on the…
- CVE-2021-378081 PoCSQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcategory, (3)…
- CVE-2021-378231 PoCOpenCart 3.0.3.7 allows users to obtain database information or read server files through SQL injection in the background.
- CVE-2021-378322 PoCsA SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious…
- CVE-2021-378332 PoCsA reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application that allows…
- CVE-2021-378401 PoCaaPanel through 6.8.12 allows Cross-Site WebSocket Hijacking (CSWH) involving OS commands within WebSocket messages at a ws:// URL for…
- CVE-2021-378591 PoCReflected XSS in OAuth Flow
- CVE-2021-378661 PoCSession is not invalidated on server-side when user logged out of Boards
- CVE-2021-379101 PoCASUS GT-AXE11000, RT-AX3000, RT-AX55, RT-AX58U, TUF-AX3000 - Improper Authentication
- CVE-2021-379141 PoCIn Argo Workflows through 3.1.3, if EXPRESSION_TEMPLATES is enabled and untrusted users are allowed to specify input parameters when…
- CVE-2021-379151 PoCAn issue was discovered on the Grandstream HT801 Analog Telephone Adaptor before 1.0.29.8. From the limited configuration shell, it is…
- CVE-2021-379751 PoCKEVUse after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted…
- CVE-2021-379791 PoCheap buffer overflow in WebRTC in Google Chrome prior to 94.0.4606.81 allowed a remote attacker who convinced a user to browse to a…
- CVE-2021-379801 PoCInappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially bypass site…