CVE-2021-38000 to CVE-2021-38999
79 CVEs with public proof-of-concept exploits.
- CVE-2021-380013 PoCsType confusion in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted…
- CVE-2021-380031 PoCKEVInappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption…
- CVE-2021-380853 PoCsThe Canon TR150 print driver through 3.71.2.10 is vulnerable to a privilege escalation issue. During the add printer process, a local…
- CVE-2021-380901 PoCInteger Overflow vulnerability in function filter16_roberts in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a…
- CVE-2021-380911 PoCInteger Overflow vulnerability in function filter16_sobel in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a…
- CVE-2021-380921 PoCInteger Overflow vulnerability in function filter_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a…
- CVE-2021-380931 PoCInteger Overflow vulnerability in function filter_robert in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a…
- CVE-2021-380941 PoCInteger Overflow vulnerability in function filter_sobel in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a…
- CVE-2021-380951 PoCThe REST API in Planview Spigit 4.5.3 allows remote unauthenticated attackers to query sensitive user accounts data, as demonstrated by an…
- CVE-2021-381121 PoCIn the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler can lead to…
- CVE-2021-381131 PoCIn addBouquet in js/bqe.js in OpenWebif (aka e2openplugin-OpenWebif) through 1.4.7, inserting JavaScript into the Add Bouquet feature of…
- CVE-2021-381361 PoCCorero SecureWatch Managed Services 9.7.2.0020 is affected by a Path Traversal vulnerability via the snap_file parameter in the…
- CVE-2021-381381 PoCOneNav beta 0.9.12 allows XSS via the Add Link feature. NOTE: the vendor's position is that there intentionally is not any XSS protection…
- CVE-2021-381431 PoCAn issue was discovered in Form Tools through 3.0.20. When an administrator creates a customer account, it is possible for the customer to…
- CVE-2021-381441 PoCAn issue was discovered in Form Tools through 3.0.20. A low-privileged user can trigger Reflected XSS when a viewing a form via the…
- CVE-2021-381451 PoCAn issue was discovered in Form Tools through 3.0.20. SQL Injection can occur via the export_group_id field when a low-privileged user…
- CVE-2021-381462 PoCsThe File Download API in Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read arbitrary files via absolute…
- CVE-2021-381472 PoCsWipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing…
- CVE-2021-381491 PoCindex.php/admin/add_user in Chikitsa Patient Management System 2.0.0 allows XSS.
- CVE-2021-381511 PoCindex.php/appointment/todos in Chikitsa Patient Management System 2.0.0 allows XSS.
- CVE-2021-381522 PoCsindex.php/appointment/insert_patient_add_appointment in Chikitsa Patient Management System 2.0.0 allows XSS.
- CVE-2021-381541 PoCCertain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for…
- CVE-2021-381562 PoCsIn Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.
- CVE-2021-381571 PoCLeoStream Connection Broker 9.x before 9.0.34.3 allows Unauthenticated Reflected XSS via the /index.pl user parameter. NOTE: This…
- CVE-2021-381621 PoCSAP Web Dispatcher versions - 7.49, 7.53, 7.77, 7.81, KRNL64NUC - 7.22, 7.22EXT, 7.49, KRNL64UC -7.22, 7.22EXT, 7.49, 7.53, KERNEL - 7.22,…
- CVE-2021-381632 PoCsKEVSAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a…
- CVE-2021-381851 PoCGNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer…
- CVE-2021-382211 PoCbbs-go <= 3.3.0 including Custom Edition is vulnerable to stored XSS.
- CVE-2021-382441 PoCA regular expression denial of service (ReDoS) vulnerability exits in cbioportal 3.6.21 and older via a POST request to…
- CVE-2021-382781 PoCTenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the urls parameter in the saveParentControlInfo function.
- CVE-2021-382831 PoCWipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read application log files containing sensitive…
- CVE-2021-382891 PoCAn issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allows attackers to…
- CVE-2021-382911 PoCFFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c.
- CVE-2021-382942 PoCsShell Command Injection Vulnerability in Nimbus Thrift Server
- CVE-2021-382951 PoCPrivilege escalation vulnerability when using HTML attachments
- CVE-2021-382973 PoCsGo before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module, when…
- CVE-2021-383001 PoCarch/mips/net/bpf_jit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when transforming unprivileged cBPF…
- CVE-2021-383041 PoCImproper input validation in the National Instruments NI-PAL driver in versions 20.0.0 and prior may allow a privileged user to…
- CVE-2021-383149 PoCsGutenberg Template Library & Redux Framework <= 4.2.11 Sensitive Information Disclosure
- CVE-2021-383743 PoCsOX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.
- CVE-2021-383752 PoCsOX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.
- CVE-2021-383762 PoCsOX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.
- CVE-2021-383772 PoCsOX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a…
- CVE-2021-383782 PoCsOX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By response to show a person's name.
- CVE-2021-383801 PoCLive555 through 1.08 mishandles huge requests for the same MP3 stream, leading to recursion and s stack-based buffer over-read. An…
- CVE-2021-383811 PoCLive555 through 1.08 does not handle MPEG-1 or 2 files properly. Sending two successive RTSP SETUP commands for the same track causes a…
- CVE-2021-383821 PoCLive555 through 1.08 does not handle Matroska and Ogg files properly. Sending two successive RTSP SETUP commands for the same track causes…
- CVE-2021-385402 PoCsApache Airflow: Variable Import endpoint missed authentication check
- CVE-2021-385601 PoCIvanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in…
- CVE-2021-385831 PoCopenBaraza HCM 3.1.6 does not properly neutralize user-controllable input, which allows reflected cross-site scripting (XSS) on multiple…
- CVE-2021-386021 PoCPluXML 5.8.7 allows Article Editing stored XSS via Headline or Content.
- CVE-2021-386032 PoCsPluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field.
- CVE-2021-386041 PoCIn librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data,…
- CVE-2021-386191 PoCopenBaraza HCM 3.1.6 does not properly neutralize user-controllable input: an unauthenticated remote attacker can conduct a stored…
- CVE-2021-386391 PoCWin32k Elevation of Privilege Vulnerability
- CVE-2021-386451 PoCKEVOpen Management Infrastructure Elevation of Privilege Vulnerability
- CVE-2021-3864715 PoCsKEVOpen Management Infrastructure (OMI) Remote Code Execution Vulnerability
- CVE-2021-386482 PoCsKEVOpen Management Infrastructure Elevation of Privilege Vulnerability
- CVE-2021-386661 PoCRemote Desktop Client Remote Code Execution Vulnerability
- CVE-2021-386994 PoCsTastyIgniter 3.0.7 allows XSS via /account, /reservation, /admin/dashboard, and /admin/system_logs.
- CVE-2021-387024 PoCsCyberoam NetGenie C0101B1-20141120-NG11VO devices through 2021-08-14 allow tweb/ft.php?u=[XSS] attacks.
- CVE-2021-387031 PoCWireless devices running certain Arcadyan-derived firmware (such as KPN Experia WiFi 1.00.15) do not properly sanitise user input to the…
- CVE-2021-387041 PoCMultiple reflected cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow unauthenticated attackers to introduce arbitrary…
- CVE-2021-387141 PoCIn Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found…
- CVE-2021-387211 PoCFUEL CMS 1.5.0 login.php contains a cross-site request forgery (CSRF) vulnerability
- CVE-2021-387511 PoCA HTTP Host header attack exists in ExponentCMS 2.6 and below in /exponent_constants.php. A modified HTTP header can change links on the…
- CVE-2021-387521 PoCA cross-site scripting (XSS) vulnerability in Online Catering Reservation System using PHP on Sourcecodester allows an attacker to…
- CVE-2021-387531 PoCAn unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain unauthorized…
- CVE-2021-387571 PoCPersistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php.
- CVE-2021-387582 PoCsDirectory traversal vulnerability in Online Catering Reservation System 1.0 exists due to lack of validation in index.php.
- CVE-2021-387591 PoCRaspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain administrator…
- CVE-2021-387721 PoCTenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind function.
- CVE-2021-388191 PoCA SQL injection vulnerability exits on the Simple Image Gallery System 1.0 application through "id" parameter on the album page.
- CVE-2021-388221 PoCA Stored Cross Site Scripting vulnerability via Malicious File Upload exists in multiple pages of IceHrm 30.0.0.OS that allows for…
- CVE-2021-388231 PoCThe IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue. A signout from an admin account does not invalidate an…
- CVE-2021-388332 PoCsSQL injection vulnerability in PHPGurukul Apartment Visitors Management System (AVMS) v. 1.0 allows attackers to execute arbitrary SQL…
- CVE-2021-388341 PoCeasy-mock v1.5.0-v1.6.0 allows remote attackers to bypass the vm2 sandbox and execute arbitrary system commands through special js code.
- CVE-2021-388402 PoCsSQL Injection can occur in Simple Water Refilling Station Management System 1.0 via the water_refilling/classes/Login.php username…
- CVE-2021-388411 PoCRemote Code Execution can occur in Simple Water Refilling Station Management System 1.0 via the System Logo option on the system_info page…