CVE-2021-3000 to CVE-2021-3999
241 CVEs with public proof-of-concept exploits.
- CVE-2021-30023 PoCsSeo Panel 4.8.0 allows reflected XSS via the seo/seopanel/login.php?sec=forgot email parameter.
- CVE-2021-30031 PoCAgenzia delle Entrate Desktop Telematico 1.0.0 contacts the jws.agenziaentrate.it server over cleartext HTTP, which allows…
- CVE-2021-30041 PoCThe _deposit function in the smart contract implementation for Stable Yield Credit (yCREDIT), an Ethereum token, has certain incorrect…
- CVE-2021-30061 PoCThe breed function in the smart contract implementation for Farm in Seal Finance (Seal), an Ethereum token, lacks access control and thus…
- CVE-2021-30075 PoCsLaminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code…
- CVE-2021-30101 PoCThere are multiple persistent cross-site scripting (XSS) vulnerabilities in the web interface of OpenText Content Server Version 20.3. The…
- CVE-2021-30142 PoCsIn MikroTik RouterOS through 2021-01-04, the hotspot login page is vulnerable to reflected XSS via the target parameter.
- CVE-2021-30171 PoCThe web interface on Intelbras WIN 300 and WRN 342 devices through 2021-01-04 allows remote attackers to discover credentials by reading…
- CVE-2021-30184 PoCsipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the id parameter on…
- CVE-2021-301910 PoCsffay lanproxy 0.1 allows Directory Traversal to read /../conf/config.properties to obtain credentials for a connection to the intranet.
- CVE-2021-30251 PoCInvision Community IPS Community Suite before 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir parameter in a…
- CVE-2021-30361 PoCPAN-OS: Administrator secrets are logged in web server logs when using the PAN-OS XML API incorrectly
- CVE-2021-30602 PoCsPAN-OS: OS Command Injection in Simple Certificate Enrollment Protocol (SCEP)
- CVE-2021-30642 PoCsPAN-OS: Memory Corruption Vulnerability in GlobalProtect Portal and Gateway Interfaces
- CVE-2021-31001 PoCLog4j hot patch package privilege escalation
- CVE-2021-31011 PoCHotdog Container Escape
- CVE-2021-31102 PoCsThe store system in PrestaShop 1.7.7.0 allows time-based boolean SQL injection via the module=productcomments controller=CommentGrade…
- CVE-2021-31112 PoCsThe Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an…
- CVE-2021-31132 PoCsNetsia SEBA+ through 0.16.1 build 70-e669dcd7 allows remote attackers to discover session cookies via a direct…
- CVE-2021-31161 PoCbefore_upstream_connection in AuthPlugin in http/proxy/auth.py in proxy.py before 2.3.1 accepts incorrect Proxy-Authorization header data…
- CVE-2021-31181 PoCEVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has multiple SQL Injection issues in the login form and the password-forgotten form…
- CVE-2021-31201 PoCAn arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote…
- CVE-2021-31225 PoCsCMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML…
- CVE-2021-31241 PoCStored cross-site scripting (XSS) in form field in robust.systems product Custom Global Variables v 1.0.5 allows a remote attacker to…
- CVE-2021-312943 PoCsKEVIgnition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of…
- CVE-2021-31301 PoCWithin the Open-AudIT up to version 3.5.3 application, the web interface hides SSH secrets, Windows passwords, and SNMP strings from users…
- CVE-2021-31371 PoCXWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.
- CVE-2021-31382 PoCsIn Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.
- CVE-2021-31451 PoCIn Ionic Identity Vault before 5, a local root attacker on an Android device can bypass biometric authentication.
- CVE-2021-31512 PoCsi-doit before 1.16.0 is affected by Stored Cross-Site Scripting (XSS) issues that could allow remote authenticated attackers to inject…
- CVE-2021-31521 PoCHome Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks against custom…
- CVE-2021-3156115 PoCsKEVSudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to…
- CVE-2021-31631 PoCA vulnerability in the HTML editor of Slab Quill 4.8.0 allows an attacker to execute arbitrary JavaScript by storing an XSS payload (a…
- CVE-2021-31641 PoCChurchRota 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permission in order to…
- CVE-2021-31651 PoCSmartAgent 3.1.0 allows a ViewOnly attacker to create a SuperUser account via the /#/CampaignManager/users URI.
- CVE-2021-31663 PoCsAn issue was discovered on ASUS DSL-N14U-B1 1.1.2.3_805 devices. An attacker can upload arbitrary file content as a firmware update when…
- CVE-2021-31771 PoCPython 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain…
- CVE-2021-31862 PoCsA Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_multi allows remote…
- CVE-2021-31881 PoCphpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.
- CVE-2021-31951 PoCbitcoind in Bitcoin Core through 0.21.0 can create a new file in an arbitrary directory (e.g., outside the ~/.bitcoin directory) via a…
- CVE-2021-31981 PoCIvanti MobileIron Core clish Restricted Shell Escape via OS Command Injection
- CVE-2021-31992 PoCsDirectory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a…
- CVE-2021-32002 PoCsBuffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job,…
- CVE-2021-32101 PoCcomponents/Modals/HelpTexts/GenericAll/GenericAll.jsx in Bloodhound <= 4.0.1 allows remote attackers to execute arbitrary system commands…
- CVE-2021-32233 PoCsNode-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.
- CVE-2021-32241 PoCA stored cross-site scripting (XSS) vulnerability in cszcms 1.2.9 exists in /admin/pages/new via the content parameter.
- CVE-2021-32361 PoCvim 8.2.2348 is affected by null pointer dereference, allows local attackers to cause a denial of service (DoS) via the ex_buffer_all…
- CVE-2021-32395 PoCsE-Learning System 1.0 suffers from an unauthenticated SQL injection vulnerability, which allows remote attackers to execute arbitrary code…
- CVE-2021-32421 PoCDuxCMS v3.1.3 was discovered to contain a SQL injection vulnerability via the component s/tools/SendTpl/index?keyword=.
- CVE-2021-32431 PoCWfilter ICF 5.0.117 contains a cross-site scripting (XSS) vulnerability. An attacker in the same LAN can craft a packet with a malicious…
- CVE-2021-32461 PoCA heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted…
- CVE-2021-32541 PoCAsus DSL-N14U-B1 1.1.2.3_805 allows remote attackers to cause a Denial of Service (DoS) via a TCP SYN scan using nmap.
- CVE-2021-32561 PoCKuaiFanCMS V5.x contains an arbitrary file read vulnerability in the html_url parameter of the chakanhtml.module.php file.
- CVE-2021-32622 PoCsTripSpark VEO Transportation-2.2.x-XP_BB-20201123-184084 NovusEDU-2.2.x-XP_BB-20201123-184084 allows unsafe data inputs in POST body…
- CVE-2021-32711 PoCPressBooks 5.17.3 contains a cross-site scripting (XSS). Stored XSS can be submitted via the Book Info's Long Description Body, and all…
- CVE-2021-32721 PoCjp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between…
- CVE-2021-32731 PoCNagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component. To exploit this vulnerability,…
- CVE-2021-32753 PoCsUnauthenticated stored cross-site scripting (XSS) exists in multiple TP-Link products including WIFI Routers (Wireless AC routers), Access…
- CVE-2021-32782 PoCsLocal Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection . Using this…
- CVE-2021-32792 PoCssz.chat version 4 allows injection of web scripts and HTML in the message box.
- CVE-2021-32811 PoCIn Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp…
- CVE-2021-32873 PoCsZoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization…
- CVE-2021-32916 PoCsZen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page)…
- CVE-2021-32932 PoCsemlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webroot/file.
- CVE-2021-32942 PoCsCASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php. An attacker can steal a cookie to perform…
- CVE-2021-32973 PoCsOn Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.
- CVE-2021-32981 PoCCollabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the…
- CVE-2021-33051 PoCBeijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability.
- CVE-2021-33101 PoCWestern Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code…
- CVE-2021-33131 PoCPlone CMS until version 5.2.4 has a stored Cross-Site Scripting (XSS) vulnerability in the user fullname property and the file upload…
- CVE-2021-33141 PoCOracle GlassFish Server 3.1.2.18 and below allows /common/logViewer/logViewer.jsf XSS. A malicious user can cause an administrator user to…
- CVE-2021-33173 PoCsKLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of the source…
- CVE-2021-33182 PoCsattach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.
- CVE-2021-33211 PoCInteger Underflow in Zephyr in IEEE 802154 Fragment Reassembly Header Removal
- CVE-2021-33251 PoCMonitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a…
- CVE-2021-33281 PoCAn issue was discovered in Aprelium Abyss Web Server X1 2.12.1 and 2.14. A crafted HTTP request can lead to an out-of-bounds read that…
- CVE-2021-33291 PoCDOS: Incorrect handling of the initial HCI ACL_MTU handshake packet leads to crash of bluetooth host layer
- CVE-2021-33372 PoCsThe Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by…
- CVE-2021-33452 PoCs_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function…
- CVE-2021-33471 PoCAn issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing…
- CVE-2021-33511 PoCOpenPLC runtime V3 through 2016-03-14 allows stored XSS via the Device Name to the web server's Add New Device page.
- CVE-2021-33553 PoCsA stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to…
- CVE-2021-33741 PoCDirectory traversal in RStudio Shiny Server before 1.5.16 allows attackers to read the application source code, involving an encoded slash.
- CVE-2021-33751 PoCActivePresenter 6.1.6 is affected by a memory corruption vulnerability that may result in a denial of service (DoS) or arbitrary code…
- CVE-2021-33761 PoCAn issue was discovered in Cuppa CMS Versions Before 31 Jan 2021 allows authenticated attackers to gain escalated privileges via a crafted…
- CVE-2021-33771 PoCThe npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due…
- CVE-2021-33787 PoCsFortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to…
- CVE-2021-33801 PoCInsecure direct object reference (IDOR) vulnerability in ICREM H8 SSRMS allows attackers to disclose sensitive information via the Print…
- CVE-2021-33941 PoCMillennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder permissions allowing…
- CVE-2021-34022 PoCsAn integer overflow and several buffer overflow reads in libyara/modules/macho/macho.c in YARA v4.0.3 and earlier could allow an attacker…
- CVE-2021-34051 PoCA flaw was found in libebml before 1.4.2. A heap overflow bug exists in the implementation of EbmlString::ReadData and…
- CVE-2021-34101 PoCA flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local…
- CVE-2021-34271 PoCThe Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's…
- CVE-2021-34382 PoCsA potential buffer overflow in the software drivers for certain HP LaserJet products and Samsung product printers could lead to an…
- CVE-2021-34412 PoCsA potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross-Site Scripting…
- CVE-2021-34494 PoCsNULL pointer deref in signature_algorithms processing
- CVE-2021-34501 PoCCA certificate check bypass with X509_V_FLAG_X509_STRICT
- CVE-2021-34561 PoCAn improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute…
- CVE-2021-34851 PoCImproper Input Validation in Bitdefender Endpoint Security Tools for Linux
- CVE-2021-34906 PoCsLinux kernel eBPF bitwise ops ALU32 bounds tracking
- CVE-2021-34921 PoCUbuntu linux kernel shiftfs file system double free vulnerability
- CVE-2021-349324 PoCsKEVThe overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file…
- CVE-2021-34961 PoCA heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file.
- CVE-2021-35081 PoCA flaw was found in PDFResurrect in version 0.22b. There is an infinite loop in get_xref_linear_skipped() in pdf.c via a crafted PDF file.
- CVE-2021-35161 PoCThere's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint…
- CVE-2021-35401 PoCIvanti MobileIron Core clish Restricted Shell Escape via Argument Injection
- CVE-2021-35551 PoCA Buffer Overflow vulnerability in the RSTP server component of Eufy Indoor 2K Indoor Camera allows a local attacker to achieve remote…
- CVE-2021-356052 PoCsKEVIt was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the…
- CVE-2021-35611 PoCAn Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a…
- CVE-2021-35642 PoCsA flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious…
- CVE-2021-35722 PoCsA flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue…
- CVE-2021-35731 PoCA use-after-free in function hci_sock_bound_ioctl() of the Linux kernel HCI subsystem was found in the way user calls ioct HCIUNBLOCKADDR…
- CVE-2021-35741 PoCA vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert command, ASAN detects memory leaks.
- CVE-2021-35751 PoCA heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker…
- CVE-2021-35771 PoCAn unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an…
- CVE-2021-35961 PoCA NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is…
- CVE-2021-36091 PoC.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to…
- CVE-2021-36251 PoCBuffer overflow in Zephyr USB DFU DNLOAD
- CVE-2021-36401 PoCA flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct…
- CVE-2021-36451 PoCPrototype Pollution in viking04/merge
- CVE-2021-36461 PoCCross-site Scripting (XSS) - Reflected in btcpayserver/btcpayserver
- CVE-2021-36531 PoCA flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine…
- CVE-2021-36543 PoCsA vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any…
- CVE-2021-36561 PoCA flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine…
- CVE-2021-36742 PoCsA flaw was found in rizin. The create_section_from_phdr function allocates space for ELF section data by processing the headers. Crafted…
- CVE-2021-36801 PoCMissing Cryptographic Step in star7th/showdoc
- CVE-2021-36831 PoCCross-Site Request Forgery (CSRF) in star7th/showdoc
- CVE-2021-36891 PoCUse of Predictable Algorithm in Random Number Generator in yiisoft/yii2
- CVE-2021-36921 PoCUse of Predictable Algorithm in Random Number Generator in yiisoft/yii2
- CVE-2021-37061 PoCSensitive Cookie Without 'HttpOnly' Flag in pi-hole/adminlte
- CVE-2021-37091 PoCApport file permission bypass through emacs byte compilation errors
- CVE-2021-37101 PoCApport info disclosure via path traversal bug in read_file
- CVE-2021-37154 PoCsA flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled…
- CVE-2021-37281 PoCCross-Site Request Forgery (CSRF) in firefly-iii/firefly-iii
- CVE-2021-37341 PoCImproper Restriction of Rendered UI Layers or Frames in yourls/yourls
- CVE-2021-37451 PoCUnrestricted Upload of File with Dangerous Type in flatcore/flatcore-cms
- CVE-2021-37493 PoCsInefficient Regular Expression Complexity in axios/axios
- CVE-2021-37511 PoCOut-of-bounds Write in bfabiszewski/libmobi
- CVE-2021-37541 PoCA flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user.…
- CVE-2021-37561 PoCHeap-based Buffer Overflow in hoene/libmysofa
- CVE-2021-37571 PoCPrototype Pollution in immerjs/immer
- CVE-2021-37581 PoCServer-Side Request Forgery (SSRF) in bookstackapp/bookstack
- CVE-2021-37651 PoCInefficient Regular Expression Complexity in validatorjs/validator.js
- CVE-2021-37661 PoCPrototype Pollution in vincit/objection.js
- CVE-2021-37671 PoCCross-site Scripting (XSS) - Stored in bookstackapp/bookstack
- CVE-2021-37681 PoCCross-site Scripting (XSS) - Stored in bookstackapp/bookstack
- CVE-2021-37701 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2021-37731 PoCA flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in…
- CVE-2021-37751 PoCCross-Site Request Forgery (CSRF) in star7th/showdoc
- CVE-2021-37761 PoCCross-Site Request Forgery (CSRF) in star7th/showdoc
- CVE-2021-37771 PoCInefficient Regular Expression Complexity in daaku/nodejs-tmpl
- CVE-2021-37781 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2021-37801 PoCCross-site Scripting (XSS) - Stored in chocobozzz/peertube
- CVE-2021-37851 PoCCross-site Scripting (XSS) - Stored in yourls/yourls
- CVE-2021-37941 PoCInefficient Regular Expression Complexity in vuelidate/vuelidate
- CVE-2021-37961 PoCUse After Free in vim/vim
- CVE-2021-37971 PoCUse of Wrong Operator in String Comparison in hestiacp/hestiacp
- CVE-2021-37991 PoCImproper Restriction of Rendered UI Layers or Frames in getgrav/grav-plugin-admin
- CVE-2021-38011 PoCInefficient Regular Expression Complexity in prismjs/prism
- CVE-2021-38021 PoCA vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The…
- CVE-2021-38032 PoCsInefficient Regular Expression Complexity in fb55/nth-check
- CVE-2021-38041 PoCInefficient Regular Expression Complexity in nervjs/taro
- CVE-2021-38051 PoCPrototype Pollution in mariocasciaro/object-path
- CVE-2021-38061 PoCPath Traversal in Pardus Software Center
- CVE-2021-38071 PoCInefficient Regular Expression Complexity in chalk/ansi-regex
- CVE-2021-38101 PoCInefficient Regular Expression Complexity in cdr/code-server
- CVE-2021-38111 PoCCross-site Scripting (XSS) - Reflected in pi-hole/adminlte
- CVE-2021-38121 PoCCross-site Scripting (XSS) - Reflected in pi-hole/adminlte
- CVE-2021-38131 PoCImproper Privilege Management in chatwoot/chatwoot
- CVE-2021-38151 PoCPrototype Pollution in fabiocaccamo/utils.js
- CVE-2021-38173 PoCsSQL Injection in wbce/wbce_cms
- CVE-2021-38181 PoCReliance on Cookies without Validation and Integrity Checking in getgrav/grav
- CVE-2021-38201 PoCInefficient Regular Expression Complexity in pksunkara/inflect
- CVE-2021-38221 PoCInefficient Regular Expression Complexity in josdejong/jsoneditor
- CVE-2021-38251 PoCMissing Authorization Checks in LiderAhenk
- CVE-2021-38281 PoCInefficient Regular Expression Complexity in nltk/nltk
- CVE-2021-38291 PoCOpen Redirect in openwhyd/openwhyd
- CVE-2021-38301 PoCCross-site Scripting (XSS) - Stored in btcpayserver/btcpayserver
- CVE-2021-38313 PoCsCross-site Scripting (XSS) - Reflected in gnuboard/gnuboard5
- CVE-2021-38361 PoCImproper Restriction of XML External Entity Reference in dbeaver/dbeaver
- CVE-2021-38371 PoCImproper Authorization in openwhyd/openwhyd
- CVE-2021-38421 PoCInefficient Regular Expression Complexity in nltk/nltk
- CVE-2021-38451 PoCExternal Control of File Name or Path in netristv/ws-scrcpy
- CVE-2021-38461 PoCUnrestricted Upload of File with Dangerous Type in firefly-iii/firefly-iii
- CVE-2021-38501 PoCAuthentication Bypass by Primary Weakness in adodb/adodb
- CVE-2021-38531 PoCCross-site Scripting (XSS) - Stored in chaskiq/chaskiq
- CVE-2021-38571 PoCCross-site Scripting (XSS) - Stored in chaskiq/chaskiq
- CVE-2021-38581 PoCCross-Site Request Forgery (CSRF) in snipe/snipe-it
- CVE-2021-38621 PoCCross-site Scripting (XSS) - Reflected in icecoder/icecoder
- CVE-2021-38631 PoCCross-site Scripting (XSS) - Generic in snipe/snipe-it
- CVE-2021-38642 PoCsA flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is…
- CVE-2021-38661 PoCCross-site Scripting (XSS) - Stored in zulip/zulip
- CVE-2021-38691 PoCImproper Restriction of XML External Entity Reference in stanfordnlp/corenlp
- CVE-2021-38721 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2021-38741 PoCPath Traversal in bookstackapp/bookstack
- CVE-2021-38751 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2021-38781 PoCImproper Restriction of XML External Entity Reference in stanfordnlp/corenlp
- CVE-2021-38791 PoCCross-site Scripting (XSS) - Stored in snipe/snipe-it
- CVE-2021-38811 PoCOut-of-bounds Read in bfabiszewski/libmobi
- CVE-2021-38821 PoCSensitive Cookie in HTTPS Session Without 'Secure' Attribute in ledgersmb/ledgersmb
- CVE-2021-38881 PoCUse of Out-of-range Pointer Offset in bfabiszewski/libmobi
- CVE-2021-38891 PoCUse of Out-of-range Pointer Offset in bfabiszewski/libmobi
- CVE-2021-38991 PoCThere is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute…
- CVE-2021-39001 PoCCross-Site Request Forgery (CSRF) in firefly-iii/firefly-iii
- CVE-2021-39011 PoCCross-Site Request Forgery (CSRF) in firefly-iii/firefly-iii
- CVE-2021-39031 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2021-39041 PoCCross-site Scripting (XSS) - Stored in getgrav/grav
- CVE-2021-39151 PoCUnrestricted Upload of File with Dangerous Type in bookstackapp/bookstack
- CVE-2021-39161 PoCPath Traversal in bookstackapp/bookstack
- CVE-2021-39181 PoCPrototype Pollution in kriszyp/json-schema
- CVE-2021-39201 PoCCross-site Scripting (XSS) - Stored in getgrav/grav-plugin-admin
- CVE-2021-39271 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2021-39281 PoCUse of Uninitialized Variable in vim/vim
- CVE-2021-39291 PoCA DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and, just…
- CVE-2021-39311 PoCCross-Site Request Forgery (CSRF) in snipe/snipe-it
- CVE-2021-39381 PoCCross-site Scripting (XSS) - Generic in snipe/snipe-it
- CVE-2021-39441 PoCCross-Site Request Forgery (CSRF) in bookstackapp/bookstack
- CVE-2021-39451 PoCCross-site Scripting (XSS) - Stored in django-helpdesk/django-helpdesk
- CVE-2021-39501 PoCCross-site Scripting (XSS) - Stored in django-helpdesk/django-helpdesk
- CVE-2021-39571 PoCCross-Site Request Forgery (CSRF) in kevinpapst/kimai2
- CVE-2021-39581 PoCSQL Injection Vulnerability in Ipack SCADA Software
- CVE-2021-39611 PoCCross-site Scripting (XSS) - Stored in snipe/snipe-it
- CVE-2021-39631 PoCCross-Site Request Forgery (CSRF) in kevinpapst/kimai2
- CVE-2021-39671 PoCImproper Access Control in zulip/zulip
- CVE-2021-39681 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2021-39721 PoCA potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly…
- CVE-2021-39731 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2021-39741 PoCUse After Free in vim/vim
- CVE-2021-39751 PoCA use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple…
- CVE-2021-39761 PoCCross-Site Request Forgery (CSRF) in kevinpapst/kimai2
- CVE-2021-39771 PoCCross-site Scripting (XSS) - Stored in invoiceninja/invoiceninja
- CVE-2021-39801 PoCExposure of Private Personal Information to an Unauthorized Actor in elgg/elgg
- CVE-2021-39831 PoCCross-site Scripting (XSS) - Stored in kevinpapst/kimai2
- CVE-2021-39841 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2021-39851 PoCCross-site Scripting (XSS) - Stored in kevinpapst/kimai2
- CVE-2021-39891 PoCOpen Redirect in star7th/showdoc
- CVE-2021-39901 PoCUse of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in star7th/showdoc
- CVE-2021-39921 PoCImproper Access Control in kevinpapst/kimai2
- CVE-2021-39931 PoCCross-Site Request Forgery (CSRF) in star7th/showdoc
- CVE-2021-39941 PoCCross-site Scripting (XSS) - Stored in django-helpdesk/django-helpdesk
- CVE-2021-39991 PoCA flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the…