CVE-2021-39000 to CVE-2021-39999
162 CVEs with public proof-of-concept exploits.
- CVE-2021-391151 PoCAffected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to…
- CVE-2021-391311 PoCImproper Handling of Unexpected Data Type in ced
- CVE-2021-391412 PoCsXStream is vulnerable to an Arbitrary Code Execution attack
- CVE-2021-391444 PoCsKEVXStream is vulnerable to a Remote Command Execution attack
- CVE-2021-391461 PoCXStream is vulnerable to an Arbitrary Code Execution attack
- CVE-2021-391492 PoCsXStream is vulnerable to an Arbitrary Code Execution attack
- CVE-2021-391501 PoCA Server-Side Forgery Request vulnerability in XStream via PriorityQueue unmarshaling
- CVE-2021-391521 PoCA Server-Side Forgery Request vulnerability in XStream via HashMap unmarshaling
- CVE-2021-391571 PoCImproper Handling of Exceptional Conditions in detect-character-encoding
- CVE-2021-391653 PoCsUnauthenticated SQL Injection
- CVE-2021-391701 PoCImproper Encoding or Escaping of Output in Asset Metadata Component
- CVE-2021-391722 PoCsNew line injection during configuration edition
- CVE-2021-391731 PoCForced reinstall
- CVE-2021-391742 PoCsConfiguration leak
- CVE-2021-391761 PoCMissing Release of Memory after Effective Lifetime in detect-character-encoding
- CVE-2021-392001 PoCInformation Disclosure in wp_die() via JSONP in wordpress
- CVE-2021-392011 PoCAuthenticated cross-site scripting (XSS) in WordPress editor
- CVE-2021-392021 PoCWordPress 5.8 beta: Stored Cross-Site Scripting (XSS) vulnerability in widget
- CVE-2021-392031 PoCPrivate data disclosure/privilege escalation through the block editor in Wordpress
- CVE-2021-392111 PoCDisclosure of GLPI and server information in telemetry endpoint
- CVE-2021-392261 PoCKEVSnapshot authentication bypass in grafana
- CVE-2021-392431 PoCCross-Site Request Forgery (CSRF) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via any CGI endpoint. This affects Nexto…
- CVE-2021-392441 PoCAuthenticated Semi-Blind Command Injection (via Parameter Injection) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via the…
- CVE-2021-392451 PoCHardcoded .htaccess Credentials for getlogs.cgi exist on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices. This affects Nexto NX3003…
- CVE-2021-392462 PoCsTor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits to v2 onion…
- CVE-2021-392491 PoCInvision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows reflected XSS because the filenames of uploaded files…
- CVE-2021-392501 PoCInvision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resultant code execution, because an…
- CVE-2021-392671 PoCPersistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary…
- CVE-2021-392681 PoCPersistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary…
- CVE-2021-392712 PoCsOrbiTeam BSCW Classic before 7.4.3 allows authenticated remote code execution (RCE) during archive extraction via attacker-supplied Python…
- CVE-2021-392731 PoCIn XeroSecurity Sn1per 9.0 (free version), insecure permissions (0777) are set upon application execution, allowing an unprivileged user…
- CVE-2021-392741 PoCIn XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing an unprivileged…
- CVE-2021-392781 PoCCertain MOXA devices allow reflected XSS via the Config Import menu. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell…
- CVE-2021-392821 PoCLive555 through 1.08 has a memory leak in AC3AudioStreamParser for AC3 files.
- CVE-2021-392831 PoCliveMedia/FramedSource.cpp in Live555 through 1.08 allows an assertion failure and application exit via multiple SETUP and PLAY commands.
- CVE-2021-392851 PoCA XSS vulnerability exists in Versa Director Release: 16.1R2 Build: S8. An attacker can use the administration web interface URL to create…
- CVE-2021-392891 PoCCertain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmware before…
- CVE-2021-392901 PoCCertain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware before 4.3.0.113, 4.4.0.111, and…
- CVE-2021-392911 PoCCertain NetModule devices allow credentials via GET parameters to CLI-PHP. These models with firmware before 4.3.0.113, 4.4.0.111, and…
- CVE-2021-392951 PoCIn OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI lan+) interface.
- CVE-2021-392961 PoCIn OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.
- CVE-2021-393071 PoCPDFTron's WebViewer UI 8.0 or below renders dangerous URLs as hyperlinks in supported documents, including JavaScript URLs, allowing the…
- CVE-2021-393124 PoCsTrue Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
- CVE-2021-393164 PoCsZoomSounds <= 6.45 Unauthenticated Directory Traversal and Sensitive Information Dislosure
- CVE-2021-393201 PoCunderConstruction <= 1.18 - Reflected Cross-Site Scripting
- CVE-2021-393222 PoCsEasy Social Icons <= 3.0.8 - Reflected Cross-Site Scripting
- CVE-2021-393274 PoCsBulletProof Security <= 5.1 Sensitive Information Disclosure
- CVE-2021-393411 PoCOptinMonster <= 2.6.4 Unprotected REST-API Endpoints
- CVE-2021-393501 PoCFV Flowplayer Video Player <= 7.5.0.727 - 7.5.2.727 Reflected Cross-Site Scripting
- CVE-2021-393523 PoCsCatch Themes Demo Import <= 1.7 Admin+ Arbitrary File Upload
- CVE-2021-393731 PoCSamsung Drive Manager 2.0.104 on Samsung H3 devices allows attackers to bypass intended access controls on disk management.…
- CVE-2021-393751 PoCPhilips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode…
- CVE-2021-393761 PoCPhilips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the CorCad_F2/executaConsultaEspecifico…
- CVE-2021-393771 PoCA SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker…
- CVE-2021-393781 PoCA SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker…
- CVE-2021-393791 PoCA SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker…
- CVE-2021-393831 PoCDWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java.
- CVE-2021-393911 PoCCross Site Scripting (XSS) vulnerability exists in the admin panel in Beego v2.0.1 via the URI path in an HTTP request, which is activated…
- CVE-2021-394081 PoCCross Site Scripting (XSS) vulnerability exists in Online Student Rate System 1.0 via the page parameter on the index.php file
- CVE-2021-394091 PoCA vulnerability exists in Online Student Rate System v1.0 that allows any user to register as an administrator without needing to be…
- CVE-2021-394111 PoCMultiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the (1) searchdata parameter in…
- CVE-2021-394261 PoCAn issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1…
- CVE-2021-394281 PoCCross Site Scripting (XSS) vulnerability in Users.php in eyoucms 1.5.4 allows remote attackers to run arbitrary code and gain escalated…
- CVE-2021-394321 PoCdiplib v3.0.0 is vulnerable to Double Free.
- CVE-2021-394332 PoCsA local file inclusion (LFI) vulnerability exists in version BIQS IT Biqs-drive v1.83 and below when sending a specific payload as the…
- CVE-2021-394581 PoCTriggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user has to…
- CVE-2021-394591 PoCRemote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute…
- CVE-2021-394731 PoCSaibamen HotelManager v1.2 is vulnerable to Cross Site Scripting (XSS) due to improper sanitization of comment and contact fields.
- CVE-2021-394741 PoCVulnerability in the product Docsis 3.0 UBC1319BA00 Router supported affected version 1319010201r009. The vulnerability allows an attacker…
- CVE-2021-394801 PoCBingrep v0.8.5 was discovered to contain a memory allocation failure which can cause a Denial of Service (DoS).
- CVE-2021-394861 PoCA Stored XSS via Malicious File Upload exists in Gila CMS version 2.2.0. An attacker can use this to steal cookies, passwords or to run…
- CVE-2021-394911 PoCA Cross Site Scripting (XSS) vulnerability exists in Yogesh Ojha reNgine v1.0 via the Scan Engine name file in the Scan Engine deletion…
- CVE-2021-394991 PoCA Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or…
- CVE-2021-395012 PoCsEyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function.
- CVE-2021-395031 PoCPHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConfig() function, an…
- CVE-2021-395091 PoCAn issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the handler function…
- CVE-2021-395101 PoCAn issue was discovered in D-Link DIR816_A1_FW101CNB04 750m11ac wireless router, The HTTP request parameter is used in the handler…
- CVE-2021-395141 PoCAn issue was discovered in libjpeg through 2020021. An uncaught floating point exception in the function ACLosslessScan::ParseMCU()…
- CVE-2021-395151 PoCAn issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function SampleInterleavedLSScan::ParseMCU()…
- CVE-2021-395161 PoCAn issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function HuffmanDecoder::Get() located in…
- CVE-2021-395171 PoCAn issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function…
- CVE-2021-395181 PoCAn issue was discovered in libjpeg through 2020021. LineBuffer::FetchRegion() in linebuffer.cpp has a heap-based buffer overflow.
- CVE-2021-395191 PoCAn issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::PullQData()…
- CVE-2021-395201 PoCAn issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function…
- CVE-2021-395211 PoCAn issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function bit_read_BB() located in…
- CVE-2021-395221 PoCAn issue was discovered in libredwg through v0.10.1.3751. bit_wcs2len() in bits.c has a heap-based buffer overflow.
- CVE-2021-395231 PoCAn issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function check_POLYLINE_handles()…
- CVE-2021-395251 PoCAn issue was discovered in libredwg through v0.10.1.3751. bit_read_fixed() in bits.c has a heap-based buffer overflow.
- CVE-2021-395271 PoCAn issue was discovered in libredwg through v0.10.1.3751. appinfo_private() in decode.c has a heap-based buffer overflow.
- CVE-2021-395281 PoCAn issue was discovered in libredwg through v0.10.1.3751. dwg_free_MATERIAL_private() in dwg.spec has a double free.
- CVE-2021-395301 PoCAn issue was discovered in libredwg through v0.10.1.3751. bit_wcs2nlen() in bits.c has a heap-based buffer overflow.
- CVE-2021-395311 PoCAn issue was discovered in libslax through v0.22.1. slaxLexer() in slaxlexer.c has a stack-based buffer overflow.
- CVE-2021-395321 PoCAn issue was discovered in libslax through v0.22.1. A NULL pointer dereference exists in the function slaxLexer() located in slaxlexer.c.…
- CVE-2021-395331 PoCAn issue was discovered in libslax through v0.22.1. slaxLexer() in slaxlexer.c has a heap-based buffer overflow.
- CVE-2021-395341 PoCAn issue was discovered in libslax through v0.22.1. slaxIsCommentStart() in slaxlexer.c has a heap-based buffer overflow.
- CVE-2021-395351 PoCAn issue was discovered in libxsmm through v1.16.1-93. A NULL pointer dereference exists in JIT code. It allows an attacker to cause…
- CVE-2021-395361 PoCAn issue was discovered in libxsmm through v1.16.1-93. The JIT code has a heap-based buffer overflow.
- CVE-2021-395371 PoCAn issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.
- CVE-2021-395381 PoCAn issue was discovered in pdftools through 20200714. A NULL pointer dereference exists in the function node::ObjNode::Value() located in…
- CVE-2021-395391 PoCAn issue was discovered in pdftools through 20200714. A NULL pointer dereference exists in the function node::BDCNode::~BDCNode() located…
- CVE-2021-395401 PoCAn issue was discovered in pdftools through 20200714. A stack-buffer-overflow exists in the function Analyze::AnalyzePages() located in…
- CVE-2021-395411 PoCAn issue was discovered in pdftools through 20200714. A NULL pointer dereference exists in the function Analyze::AnalyzeXref() located in…
- CVE-2021-395421 PoCAn issue was discovered in pdftools through 20200714. A NULL pointer dereference exists in the function Font::Size() located in font.cpp.…
- CVE-2021-395431 PoCAn issue was discovered in pdftools through 20200714. A NULL pointer dereference exists in the function Analyze::AnalyzeRoot() located in…
- CVE-2021-395441 PoCAn issue was discovered in sela through 20200412. file::WavFile::writeToFile() in wav_file.c has a heap-based buffer overflow.
- CVE-2021-395451 PoCAn issue was discovered in sela through 20200412. A NULL pointer dereference exists in the function rice::RiceDecoder::process() located…
- CVE-2021-395461 PoCAn issue was discovered in sela through 20200412. rice::RiceDecoder::process() in rice_decoder.cpp has a heap-based buffer overflow.
- CVE-2021-395471 PoCAn issue was discovered in sela through 20200412. A NULL pointer dereference exists in the function lpc::SampleGenerator::process()…
- CVE-2021-395481 PoCAn issue was discovered in sela through 20200412. A NULL pointer dereference exists in the function frame::FrameDecoder::process() located…
- CVE-2021-395491 PoCAn issue was discovered in sela through 20200412. A NULL pointer dereference exists in the function file::WavFile::WavFile() located in…
- CVE-2021-395501 PoCAn issue was discovered in sela through 20200412. file::SelaFile::readFromFile() in sela_file.cpp has a heap-based buffer overflow.
- CVE-2021-395511 PoCAn issue was discovered in sela through 20200412. file::SelaFile::readFromFile() in sela_file.c has a heap-based buffer overflow.
- CVE-2021-395521 PoCAn issue was discovered in sela through 20200412. file::WavFile::readFromFile() in wav_file.c has a heap-based buffer overflow.
- CVE-2021-395531 PoCAn issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function grealloc() located in gmem.cc. It…
- CVE-2021-395541 PoCAn issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function Lexer::Lexer() located in…
- CVE-2021-395551 PoCAn issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function InfoOutputDev::type3D0() located…
- CVE-2021-395561 PoCAn issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function InfoOutputDev::type3D1() located…
- CVE-2021-395571 PoCAn issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function copyString() located in gmem.cc.…
- CVE-2021-395581 PoCAn issue was discovered in swftools through 20200710. A stack-buffer-overflow exists in the function…
- CVE-2021-395591 PoCAn issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function GString::~GString() located in…
- CVE-2021-395611 PoCAn issue was discovered in swftools through 20200710. A stack-buffer-overflow exists in the function Gfx::opSetFillColorN() located in…
- CVE-2021-395621 PoCAn issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function FileStream::makeSubStream()…
- CVE-2021-395631 PoCAn issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_DumpActions() located in…
- CVE-2021-395641 PoCAn issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function swf_DumpActions() located in…
- CVE-2021-395691 PoCAn issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function OpAdvance() located in swfaction.c. It…
- CVE-2021-395741 PoCAn issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function pool_read() located in pool.c. It…
- CVE-2021-395751 PoCAn issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function dump_method() located in abc.c. It…
- CVE-2021-395771 PoCAn issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function main() located in swfdump.c. It allows…
- CVE-2021-395791 PoCAn issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function string_hash() located in q.c. It…
- CVE-2021-395821 PoCAn issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function swf_GetPlaceObject() located in…
- CVE-2021-395831 PoCAn issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function pool_lookup_string2() located in…
- CVE-2021-395841 PoCAn issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function namespace_set_hash() located in…
- CVE-2021-395851 PoCAn issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function traits_dump() located in abc.c. It…
- CVE-2021-395871 PoCAn issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_DumpABC() located in abc.c. It…
- CVE-2021-395881 PoCAn issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_ReadABC() located in abc.c. It…
- CVE-2021-395891 PoCAn issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function parse_metadata() located in abc.c.…
- CVE-2021-395901 PoCAn issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function params_dump() located in abc.c. It…
- CVE-2021-395911 PoCAn issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_GetShapeBoundingBox() located…
- CVE-2021-395921 PoCAn issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function pool_lookup_uint() located in…
- CVE-2021-395931 PoCAn issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_FontExtract_DefineFontInfo()…
- CVE-2021-395941 PoCOther An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function updateusage() located in…
- CVE-2021-395951 PoCAn issue was discovered in swftools through 20200710. A stack-buffer-overflow exists in the function rfx_alloc() located in mem.c. It…
- CVE-2021-395961 PoCAn issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function code_parse() located in code.c. It…
- CVE-2021-395971 PoCAn issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function code_dump2() located in code.c. It…
- CVE-2021-395981 PoCAn issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function callcode() located in code.c. It…
- CVE-2021-395991 PoCMultiple Cross Site Scripting (XSS) vulnerabilities exists in CXUUCMS 3.1 in the search and c parameters in (1) public/search.php and in…
- CVE-2021-396083 PoCsRemote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote malicious user…
- CVE-2021-396091 PoCCross Site Scripting (XSS) vulnerability exiss in FlatCore-CMS 2.0.7 via the upload image function.
- CVE-2021-396131 PoCD-Link DVG-3104MS version 1.0.2.0.3, 1.0.2.0.4, and 1.0.2.0.4E contains hard-coded credentials for undocumented user accounts in the…
- CVE-2021-396141 PoCD-Link DVX-2000MS contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. As weak passwords have been…
- CVE-2021-396151 PoCD-Link DSR-500N version 1.02 contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file.If an attacker…
- CVE-2021-396701 PoCIn setStream of WallpaperManager.java, there is a possible way to cause a permanent DoS due to improper input validation. This could lead…
- CVE-2021-396852 PoCsIn various setup methods of the USB gadget subsystem, there is a possible out of bounds write due to an incorrect flag check. This could…
- CVE-2021-396901 PoCIn setDisplayPadding of WallpaperManagerService.java, there is a possible way to cause a persistent DoS due to improper input validation.…
- CVE-2021-396921 PoCIn onCreate of SetupLayoutActivity.java, there is a possible way to setup a work profile bypassing user consent due to a…
- CVE-2021-396961 PoCIn Task.java, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege with…
- CVE-2021-397061 PoCIn onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missing permission…
- CVE-2021-397131 PoCProduct: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel
- CVE-2021-397491 PoCIn WindowManager, there is a possible way to start non-exported and protected activities due to a missing permission check. This could…
- CVE-2021-397931 PoCKEVIn kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could…
- CVE-2021-398632 PoCsAdobe Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution
- CVE-2021-398921 PoCIn all versions of GitLab CE/EE since version 12.0, a lower privileged user can import users from projects that they don't have a…