CVE-2021-40000 to CVE-2021-40999
170 CVEs with public proof-of-concept exploits.
- CVE-2021-400851 PoCAn issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can…
- CVE-2021-401011 PoCAn issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the…
- CVE-2021-401131 PoCCisco Catalyst PON Series Switches Optical Network Terminal Vulnerabilities
- CVE-2021-401451 PoCgdImageGd2Ptr in gd_gd2.c in the GD Graphics Library (aka LibGD) through 2.3.2 has a double free. NOTE: the vendor's position is "The GD2…
- CVE-2021-401461 PoCA Remote Code Execution (RCE) vulnerability exists in Apache Any23 YAMLExtractor.java
- CVE-2021-401492 PoCsThe web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an…
- CVE-2021-401501 PoCThe web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapped to a publicly…
- CVE-2021-401531 PoCsquashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to…
- CVE-2021-401541 PoCNXP LPC55S69 devices before A3 have a buffer over-read via a crafted wlength value in a GET Descriptor Configuration request during use of…
- CVE-2021-401861 PoCDNN CMS Server-Side Request Forgery (SSRF)
- CVE-2021-402191 PoCBolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject…
- CVE-2021-402222 PoCsRittal CMC PU III Web management Version affected: V3.11.00_2. Version fixed: V3.17.10 is affected by a remote code execution…
- CVE-2021-402231 PoCRittal CMC PU III Web management (version V3.11.00_2) fails to sanitize user input on several parameters of the configuration (User…
- CVE-2021-402472 PoCsSQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL…
- CVE-2021-402721 PoCOP5 Monitor 8.3.1, 8.3.2, and OP5 8.3.3 are vulnerable to Cross Site Scripting (XSS).
- CVE-2021-402791 PoCAn SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/bad.php.
- CVE-2021-402801 PoCAn SQL Injection vulnerablitly exits in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/dl_sendmail.php.
- CVE-2021-402811 PoCAn SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 in dl/dl_print.php when registering ordinary users.
- CVE-2021-402821 PoCAn SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, abd 2021 in dl/dl_download.php. when registering ordinary users.
- CVE-2021-402851 PoChtmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php.
- CVE-2021-402921 PoCA Stored Cross Site Sripting (XSS) vulnerability exists in DzzOffice 2.02.1 via the settingnew parameter.
- CVE-2021-403032 PoCsperfex crm 1.10 is vulnerable to Cross Site Scripting (XSS) via /clients/profile.
- CVE-2021-403092 PoCsA SQL injection vulnerability exists in the Take Attendance functionality of OS4Ed's OpenSIS 8.0. allows an attacker to inject their own…
- CVE-2021-403102 PoCsOpenSIS Community Edition version 8.0 is affected by a cross-site scripting (XSS) vulnerability in the TakeAttendance.php via the…
- CVE-2021-403231 PoCCobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template…
- CVE-2021-403451 PoCAn issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can upload ZIP files. A…
- CVE-2021-403467 PoCsAn integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack,…
- CVE-2021-403523 PoCsOpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of…
- CVE-2021-403531 PoCA SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can…
- CVE-2021-403712 PoCsGridpro Request Management for Windows Azure Pack before 2.0.7912 allows Directory Traversal for remote code execution, as demonstrated by…
- CVE-2021-403731 PoCplaySMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then…
- CVE-2021-403741 PoCA stored cross-site scripting (XSS) vulnerability was identified in Apperta Foundation OpenEyes 3.5.1. Updating a patient's details allows…
- CVE-2021-403751 PoCApperta Foundation OpenEyes 3.5.1 allows remote attackers to view the sensitive information of patients without having the intended level…
- CVE-2021-403782 PoCsAn issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. /cgi-bin/support/killps.cgi deletes all…
- CVE-2021-403791 PoCAn issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. rstp://.../medias2 does not require…
- CVE-2021-403801 PoCAn issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. cameralist.cgi and setcamera.cgi…
- CVE-2021-403811 PoCAn issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. index_MJpeg.cgi allows video access.
- CVE-2021-403821 PoCAn issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. mjpegStreamer.cgi allows video…
- CVE-2021-403881 PoCA privilege escalation vulnerability exists in Advantech SQ Manager Server 1.0.6. A specially-crafted file can be replaced in the system…
- CVE-2021-403891 PoCA privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1.0.2. A specially-crafted file can be…
- CVE-2021-403901 PoCAn authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. A specially-crafted HTTP…
- CVE-2021-403911 PoCAn out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd),…
- CVE-2021-403921 PoCAn information disclosure vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. Network sniffing can lead…
- CVE-2021-403931 PoCAn out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit…
- CVE-2021-403941 PoCAn out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit…
- CVE-2021-403961 PoCA privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7. A specially-crafted file can be…
- CVE-2021-403971 PoCA privilege escalation vulnerability exists in the installation of Advantech WISE-PaaS/OTA Server 3.0.9. A specially-crafted file can be…
- CVE-2021-403981 PoCAn out-of-bounds write vulnerability exists in the parse_raster_data functionality of Accusoft ImageGear 19.10. A specially-crafted…
- CVE-2021-404001 PoCAn out-of-bounds read vulnerability exists in the RS-274X aperture macro outline primitive functionality of Gerbv 2.7.0 and dev (commit…
- CVE-2021-404011 PoCA use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit…
- CVE-2021-404021 PoCAn out-of-bounds read vulnerability exists in the RS-274X aperture macro multiple outline primitives functionality of Gerbv 2.7.0 and dev…
- CVE-2021-404031 PoCAn information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit…
- CVE-2021-404042 PoCsAn authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-404051 PoCA denial of service vulnerability exists in the cgiserver.cgi Upgrade API functionality of Reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-404061 PoCA denial of service vulnerability exists in the cgiserver.cgi session creation functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-404071 PoCKEVAn OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1]…
- CVE-2021-404081 PoCAn OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1]…
- CVE-2021-404091 PoCAn OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1]…
- CVE-2021-404101 PoCAn OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [4]…
- CVE-2021-404111 PoCAn OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [6]…
- CVE-2021-404121 PoCAn OScommand injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [8]…
- CVE-2021-404131 PoCAn incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W…
- CVE-2021-404141 PoCAn incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W…
- CVE-2021-404151 PoCAn incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W…
- CVE-2021-404161 PoCAn incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W…
- CVE-2021-404171 PoCWhen parsing a file that is submitted to the DPDecoder service as a job, the service will use the combination of decoding parameters that…
- CVE-2021-404181 PoCWhen parsing a file that is submitted to the DPDecoder service as a job, the R3D SDK will mistakenly skip over the assignment of a…
- CVE-2021-404191 PoCA firmware update vulnerability exists in the 'factory' binary of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted series of…
- CVE-2021-404201 PoCA use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.1.0.52543. A specially-crafted…
- CVE-2021-404221 PoCAn authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A…
- CVE-2021-404241 PoCAn out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. A specially-crafted…
- CVE-2021-404251 PoCAn out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. A specially-crafted…
- CVE-2021-404261 PoCA heap-based buffer overflow vulnerability exists in the sphere.c start_read() functionality of Sound Exchange libsox 14.4.2 and master…
- CVE-2021-4043815 PoCsKEVmod_proxy SSRF
- CVE-2021-4044446 PoCsKEVMicrosoft MSHTML Remote Code Execution Vulnerability
- CVE-2021-4044912 PoCsKEVWin32k Elevation of Privilege Vulnerability
- CVE-2021-404901 PoCA race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13.
- CVE-2021-404921 PoCA reflected XSS vulnerability exists in multiple pages in version 22 of the Gibbon application that allows for arbitrary execution of…
- CVE-2021-405091 PoCViewCommon.java in JForum2 2.7.0 allows XSS via a user signature.
- CVE-2021-405241 PoCIn Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size,…
- CVE-2021-405312 PoCsSketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opened, without the…
- CVE-2021-405399 PoCsKEVZoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code…
- CVE-2021-405401 PoCulfius_uri_logger in Ulfius HTTP Framework before 2.7.4 omits con_info initialization and a con_info->request NULL check for certain…
- CVE-2021-405422 PoCsOpensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute JavaScript code…
- CVE-2021-405431 PoCOpensis-Classic Version 8.0 is affected by a SQL injection vulnerability due to a lack of sanitization of input data at two parameters…
- CVE-2021-405461 PoCTenda AC6 US_AC6V4.0RTL_V02.03.01.26_cn.bin allows attackers (who have the administrator password) to cause a denial of service (device…
- CVE-2021-405551 PoCCross site scripting (XSS) vulnerability in flatCore-CMS 2.2.15 allows attackers to execute arbitrary code via description field on the…
- CVE-2021-405561 PoCA stack overflow vulnerability exists in the httpd service in ASUS RT-AX56U Router Version 3.0.0.4.386.44266. This vulnerability is caused…
- CVE-2021-405591 PoCA null pointer deference vulnerability exists in gpac through 1.0.1 via the naludmx_parse_nal_avc function in reframe_nalu, which allows a…
- CVE-2021-405671 PoCSegmentation fault vulnerability exists in Gpac through 1.0.1 via the gf_odf_size_descriptor function in desc_private.c when using mp4box,…
- CVE-2021-405681 PoCA buffer overflow vulnerability exists in Gpac through 1.0.1 via a malformed MP4 file in the svc_parse_slice function in av_parsers.c,…
- CVE-2021-405691 PoCThe binary MP4Box in Gpac through 1.0.1 has a double-free vulnerability in the iloc_entry_del funciton in box_code_meta.c, which allows…
- CVE-2021-405701 PoCThe binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the avc_compute_poc function in av_parsers.c, which allows attackers to…
- CVE-2021-405711 PoCThe binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the ilst_box_read function in box_code_apple.c, which allows attackers…
- CVE-2021-405721 PoCThe binary MP4Box in Gpac 1.0.1 has a double-free bug in the av1dmx_finalize function in reframe_av1.c, which allows attackers to cause a…
- CVE-2021-405731 PoCThe binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the gf_list_del function in list.c, which allows attackers to cause a…
- CVE-2021-405741 PoCThe binary MP4Box in Gpac from 0.9.0-preview to 1.0.1 has a double-free vulnerability in the gf_text_get_utf8_line function in…
- CVE-2021-405751 PoCThe binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in the mpgviddmx_process function in reframe_mpgvid.c, which…
- CVE-2021-405761 PoCThe binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in the gf_isom_get_payt_count function in hint_track.c, which…
- CVE-2021-405772 PoCsA Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP and PayPal Free…
- CVE-2021-405781 PoCAuthenticated Blind & Error-based SQL injection vulnerability was discovered in Online Enrollment Management System in PHP and PayPal Free…
- CVE-2021-405951 PoCSQL injection vulnerability in Sourcecodester Online Leave Management System v1 by oretnom23, allows attackers to execute arbitrary SQL…
- CVE-2021-405961 PoCSQL injection vulnerability in Login.php in sourcecodester Online Learning System v2 by oretnom23, allows attackers to execute arbitrary…
- CVE-2021-406061 PoCThe gf_bs_write_data function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.
- CVE-2021-406071 PoCThe schm_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.
- CVE-2021-406081 PoCThe gf_hinter_track_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.
- CVE-2021-406091 PoCThe GetHintFormat function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.
- CVE-2021-406172 PoCsAn SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.
- CVE-2021-406181 PoCAn SQL Injection vulnerability exists in openSIS Classic 8.0 via the 1) ADDR_CONT_USRN, 2) ADDR_CONT_PSWD, 3) SECN_CONT_USRN or 4)…
- CVE-2021-406351 PoCOS4ED openSIS 8.0 is affected by SQL injection in ChooseCpSearch.php, ChooseRequestSearch.php. An attacker can inject a SQL query to…
- CVE-2021-406361 PoCOS4ED openSIS 8.0 is affected by SQL Injection in CheckDuplicateName.php, which can extract information from the database.
- CVE-2021-406371 PoCOS4ED openSIS 8.0 is affected by cross-site scripting (XSS) in EmailCheckOthers.php. An attacker can inject JavaScript code to get the…
- CVE-2021-406391 PoCImproper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via…
- CVE-2021-406441 PoCAn SQL Injection vulnerability exists in oasys oa_system as of 9/7/2021 in resources/mappers/notice-mapper.xml.
- CVE-2021-406451 PoCAn SQL Injection vulnerability exists in glorylion JFinalOA as of 9/7/2021 in the defkey parameter getHaveDoneTaskDataList method of the…
- CVE-2021-406471 PoCIn man2html 1.6g, a specific string being read in from a file will overwrite the size parameter in the top chunk of the heap. This at…
- CVE-2021-406481 PoCIn man2html 1.6g, a filename can be created to overwrite the previous size parameter of the next chunk and the fd, bk, fd_nextsize,…
- CVE-2021-406491 PoCIn Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.
- CVE-2021-406501 PoCIn Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.
- CVE-2021-406514 PoCsOS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose…
- CVE-2021-406551 PoCKEVAn informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by…
- CVE-2021-406561 PoClibsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867.
- CVE-2021-406581 PoCTextpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”.
- CVE-2021-406601 PoCAn issue was discovered in Delight Nashorn Sandbox 0.2.0. There is an ReDoS vulnerability that can be exploited to launching a denial of…
- CVE-2021-406612 PoCsA remote, unauthenticated, directory traversal vulnerability was identified within the web interface used by IND780 Advanced Weighing…
- CVE-2021-406621 PoCA Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user…
- CVE-2021-406631 PoCdeep.assign npm package 0.0.0-alpha.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype…
- CVE-2021-406691 PoCSQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords parameter under the coreframe/app/promote/admin/index.php file.
- CVE-2021-406701 PoCSQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords iparameter under the /coreframe/app/order/admin/card.php file.
- CVE-2021-406741 PoCAn SQL injection vulnerability exists in Wuzhi CMS v4.1.0 via the KeyValue parameter in coreframe/app/order/admin/index.php.
- CVE-2021-408131 PoCA cross-site scripting (XSS) vulnerability in the "Zip content" feature in Element-IT HTTP Commander 3.1.9 allows remote authenticated…
- CVE-2021-408141 PoCThe Customer Photo Gallery addon before 2.9.4 for PrestaShop is vulnerable to SQL injection.
- CVE-2021-408224 PoCsGeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.
- CVE-2021-408261 PoCClementine Music Player through 1.3.1 is vulnerable to a User Mode Write Access Violation, affecting the MP3 file parsing functionality at…
- CVE-2021-408271 PoCClementine Music Player through 1.3.1 (when a GLib 2.0.0 DLL is used) is vulnerable to a Read Access Violation on Block Data Move,…
- CVE-2021-408391 PoCThe rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote…
- CVE-2021-408453 PoCsThe web part of Zenitel AlphaCom XE Audio Server through 11.2.3.10, called AlphaWeb XE, does not restrict file upload in the Custom…
- CVE-2021-408471 PoCThe update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve remote code…
- CVE-2021-408564 PoCsAuerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.
- CVE-2021-408573 PoCsAuerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring.
- CVE-2021-408583 PoCsAuerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin password via the…
- CVE-2021-408596 PoCsBackdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web based management…
- CVE-2021-408651 PoCUnsafe Pre-Authentication Deserialization In Workers
- CVE-2021-408661 PoCCertain NETGEAR smart switches are affected by a remote admin password change by an unauthenticated attacker via the (disabled by default)…
- CVE-2021-408671 PoCCertain NETGEAR smart switches are affected by an authentication hijacking race-condition vulnerability by an unauthenticated attacker who…
- CVE-2021-408684 PoCsIn Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.
- CVE-2021-408709 PoCsKEVAn issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible,…
- CVE-2021-408754 PoCsImproper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat actor can access the…
- CVE-2021-408881 PoCProjectsend version r1295 is affected by Cross Site Scripting (XSS) due to lack of sanitization when echo output data in returnFilesIds()…
- CVE-2021-408891 PoCCMSUno version 1.7.2 is affected by a PHP code execution vulnerability. sauvePass action in {webroot}/uno/central.php file calls to…
- CVE-2021-409033 PoCsA vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings…
- CVE-2021-409041 PoCThe web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed…
- CVE-2021-409051 PoCThe web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp"…
- CVE-2021-409061 PoCCheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an…
- CVE-2021-409071 PoCSQL injection vulnerability in Sourcecodester Storage Unit Rental Management System v1 by oretnom23, allows attackers to execute arbitrary…
- CVE-2021-409082 PoCsSQL injection vulnerability in Login.php in Sourcecodester Purchase Order Management System v1 by oretnom23, allows attackers to execute…
- CVE-2021-409091 PoCCross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tutorial v1 by…
- CVE-2021-409401 PoCMonstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.
- CVE-2021-409431 PoCIn Bento4 1.6.0-638, there is a null pointer reference in the function AP4_DescriptorListInspector::Action function in Ap4Descriptor.h:124…
- CVE-2021-409602 PoCsGalera WebTemplate 1.0 is affected by a directory traversal vulnerability that could reveal information from /etc/passwd and /etc/shadow.
- CVE-2021-409613 PoCsCMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. The $sortby variable is concatenated…
- CVE-2021-409644 PoCsA Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file…
- CVE-2021-409681 PoCCross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to…
- CVE-2021-409691 PoCCross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to…
- CVE-2021-409701 PoCCross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to…
- CVE-2021-409711 PoCCross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to…
- CVE-2021-409721 PoCCross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to…
- CVE-2021-409731 PoCCross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to…
- CVE-2021-409782 PoCsThe mkdocs 1.2.2 built-in dev-server allows directory traversal using the port 8000, enabling remote exploitation to obtain :sensitive…
- CVE-2021-409851 PoCA stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to…