CVE-2021-41000 to CVE-2021-41999
144 CVEs with public proof-of-concept exploits.
- CVE-2021-410381 PoCIn versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().
- CVE-2021-410431 PoCUse after free in tcpslice triggers AddressSanitizer, no other confirmed impact.
- CVE-2021-410541 PoCtftpd_file.c in atftp through 0.7.4 has a buffer overflow because buffer-size handling does not properly consider the combination of data,…
- CVE-2021-410611 PoCIn RIOT-OS 2021.01, nonce reuse in 802.15.4 encryption in the ieee820154_security component allows attackers to break encryption by…
- CVE-2021-410721 PoCsquashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A…
- CVE-2021-410733 PoCsloop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using…
- CVE-2021-410741 PoCA CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML…
- CVE-2021-410781 PoCNameko through 2.13.0 can be tricked into performing arbitrary code execution when deserializing the config file.
- CVE-2021-410811 PoCZoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a configuration search.
- CVE-2021-410913 PoCsInsufficiently restricted permissions on data directory in Docker Engine
- CVE-2021-410972 PoCsPrototype pollution in aurelia-path
- CVE-2021-411601 PoCImproper region checks in FreeRDP allow out of bound write to memory
- CVE-2021-411681 PoCHash-Collision Denial-of-Service Vulnerability in snudown
- CVE-2021-411711 PoCBypass bruteforce protection on login form in elabftw
- CVE-2021-411721 PoCSelf-XSS in AS_Redis
- CVE-2021-411742 PoCsXSS vulnerability allowing arbitrary JavaScript execution
- CVE-2021-411821 PoCXSS in the `altField` option of the Datepicker widget
- CVE-2021-411841 PoCXSS in the `of` option of the `.position()` util
- CVE-2021-411921 PoCInsecure default configuration
- CVE-2021-412451 PoCPossible Cross-Site Request Forgery in Combodo iTop
- CVE-2021-412531 PoCPossible heap buffer overflow when using zycore string functions in formatter hooks
- CVE-2021-412541 PoCPrivilege escalation to cluster admin on multi-tenant environments
- CVE-2021-412561 PoCIntent URI permissions manipulation in nextcloud news-android
- CVE-2021-412661 PoCAuthentication bypass issue in the Operator Console
- CVE-2021-412692 PoCsUnauthenticated remote code injection in cron-utils
- CVE-2021-4127716 PoCsKEVGeoJSON URL validation can expose server files and environment variables to unauthorized users
- CVE-2021-412781 PoCBroken encryption in app-functions-sdk “AES” transform in EdgeX Foundry releases prior to Jakarta allows attackers to decrypt messages via…
- CVE-2021-412825 PoCsdiag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set…
- CVE-2021-412852 PoCsBallistix MOD Utility through 2.0.2.5 is vulnerable to privilege escalation in the MODAPI.sys driver component. The vulnerability is…
- CVE-2021-412911 PoCECOA BAS controller - Path Traversal-1
- CVE-2021-412931 PoCECOA BAS controller - Path Traversal-3
- CVE-2021-413141 PoCCertain NETGEAR smart switches are affected by a \n injection in the web UI's password field, which - due to several faulty aspects of the…
- CVE-2021-413182 PoCsIn Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input. which could allow…
- CVE-2021-413221 PoCPoly VVX 400/410 5.3.1 allows low-privileged users to change the Admin password by modifying a POST parameter to 120 during the password…
- CVE-2021-413495 PoCsMicrosoft Exchange Server Spoofing Vulnerability
- CVE-2021-413512 PoCsMicrosoft Edge (Chrome based) Spoofing on IE Mode
- CVE-2021-413791 PoCKEVWindows Installer Elevation of Privilege Vulnerability
- CVE-2021-413818 PoCsPayara Micro Community 5.2021.6 and below allows Directory Traversal.
- CVE-2021-413825 PoCsPlastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface.
- CVE-2021-413901 PoCIn Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV…
- CVE-2021-413911 PoCIn Ericsson ECM before 18.0, it was observed that Security Management Endpoint in User Profile Management Section is vulnerable to stored…
- CVE-2021-414131 PoCok-file-formats master 2021-9-12 is affected by a buffer overflow in ok_jpg_convert_data_unit_grayscale and ok_jpg_convert_YCbCr_to_RGB.
- CVE-2021-414151 PoCSubscription-Manager v1.0 /main.js has a cross-site scripting (XSS) vulnerability in the machineDetail parameter.
- CVE-2021-414191 PoCQVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.
- CVE-2021-414262 PoCsBeeline Smart box 2.0.38 is vulnerable to Cross Site Request Forgery (CSRF) via mgt_end_user.htm.
- CVE-2021-414272 PoCsBeeline Smart Box 2.0.38 is vulnerable to Cross Site Scripting (XSS) via the choose_mac parameter to setup.cgi.
- CVE-2021-414321 PoCA stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands…
- CVE-2021-414561 PoCThere is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1004 in the nhmldmx_send_sample() function szXmlTo parameter…
- CVE-2021-414581 PoCIn GPAC MP4Box v1.1.0, there is a stack buffer overflow at src/utils/error.c:1769 which leads to a denial of service vulnerability.
- CVE-2021-414591 PoCThere is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1008 in the nhmldmx_send_sample() function szXmlFrom parameter…
- CVE-2021-414601 PoCECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.
- CVE-2021-414611 PoCCross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote…
- CVE-2021-414621 PoCCross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote…
- CVE-2021-414631 PoCCross-site scripting (XSS) vulnerability in toos/permissions/dialogs/access/entity/types/group_combination.php in concrete5-legacy 5.6.4.0…
- CVE-2021-414641 PoCCross-site scripting (XSS) vulnerability in concrete/elements/collection_add.php in concrete5-legacy 5.6.4.0 and below allows remote…
- CVE-2021-414651 PoCCross-site scripting (XSS) vulnerability in concrete/elements/collection_theme.php in concrete5-legacy 5.6.4.0 and below allows remote…
- CVE-2021-414671 PoCCross-site scripting (XSS) vulnerability in application/controllers/dropbox.php in JustWriting 1.0.0 and below allow remote attackers to…
- CVE-2021-414711 PoCSQL injection vulnerability in Sourcecodester South Gate Inn Online Reservation System v1 by oretnom23, allows attackers to execute…
- CVE-2021-414721 PoCSQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows attackers to execute arbitrary SQL commands…
- CVE-2021-414871 PoCNOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.
- CVE-2021-414921 PoCMultiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Code in the pos page…
- CVE-2021-414971 PoCNull pointer reference in CMS_Conservative_increment_obj in RaRe-Technologies bounter version 1.01 and 1.10, allows attackers to conduct…
- CVE-2021-415061 PoCXiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI3518_50H10L_S39…
- CVE-2021-415114 PoCsThe username and password field of login in Lodging Reservation Management System V1 can give access to any user by using SQL injection to…
- CVE-2021-415261 PoCA vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow…
- CVE-2021-415561 PoCsqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code…
- CVE-2021-415571 PoCSofico Miles RIA 2020.2 Build 127964T is affected by Stored Cross Site Scripting (XSS). An attacker with access to a user account of the…
- CVE-2021-415691 PoCSAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the appstart.sas file,…
- CVE-2021-415791 PoCLCDS LAquis SCADA through 4.3.1.1085 is vulnerable to a control bypass and path traversal. If an attacker can get a victim to load a…
- CVE-2021-416121 PoCAn issue was discovered in the ALU unit of the OpenRISC mor1kx processor. The carry flag is not being updated correctly for the subtract…
- CVE-2021-416171 PoCsshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because…
- CVE-2021-416341 PoCA user enumeration vulnerability in MELAG FTP Server 2.2.0.4 allows an attacker to identify valid FTP usernames.
- CVE-2021-416351 PoCWhen installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations…
- CVE-2021-416361 PoCMELAG FTP Server 2.2.0.4 allows an attacker to use the CWD command to break out of the FTP servers root directory and operate on the…
- CVE-2021-416371 PoCWeak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which…
- CVE-2021-416381 PoCThe authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to access local files…
- CVE-2021-416391 PoCMELAG FTP Server 2.2.0.4 stores unencrpyted passwords of FTP users in a local configuration file.
- CVE-2021-416411 PoCDeno <=1.14.0 file sandbox does not handle symbolic links correctly. When running Deno with specific write access, the Deno.symlink method…
- CVE-2021-416432 PoCsRemote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field.
- CVE-2021-416442 PoCsRemote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that…
- CVE-2021-416452 PoCsRemote Code Execution (RCE) vulnerability exists in Sourcecodester Budget and Expense Tracker System 1.0 that allows a remote malicious…
- CVE-2021-416462 PoCsRemote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file…
- CVE-2021-416473 PoCsAn un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App…
- CVE-2021-416484 PoCsAn un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a…
- CVE-2021-416493 PoCsAn un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter.…
- CVE-2021-416511 PoCA blind SQL injection vulnerability exists in the Raymart DG / Ahmed Helal Hotel-mgmt-system. A malicious attacker can retrieve sensitive…
- CVE-2021-416533 PoCsThe PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code…
- CVE-2021-416541 PoCSQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue…
- CVE-2021-416571 PoCSmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a…
- CVE-2021-416581 PoCCross Site Scripting (XSS) in Sourcecodester Student Quarterly Grading System by oretnom23, allows attackers to execute arbitrary code via…
- CVE-2021-416591 PoCSQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the…
- CVE-2021-416601 PoCSQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to execute arbitrary…
- CVE-2021-416721 PoCPEEL Shopping CMS 9.4.0 is vulnerable to authenticated SQL injection in utilisateurs.php. A user that belongs to the administrator group…
- CVE-2021-416742 PoCsAn SQL Injection vulnerability exists in Sourcecodester E-Negosyo System 1.0 via the user_email parameter in /admin/login.php.
- CVE-2021-416751 PoCA Remote Code Execution (RCE) vulnerabilty exists in Sourcecodester E-Negosyo System 1.0 in /admin/produts/controller.php via the doInsert…
- CVE-2021-416771 PoCA SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can…
- CVE-2021-416781 PoCA SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can…
- CVE-2021-416791 PoCA SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can…
- CVE-2021-416911 PoCA SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]"…
- CVE-2021-416941 PoCAn Incorrect Access Control vulnerability exists in Premiumdatingscript 4.2.7.7 via the password change procedure in requests\user.php.
- CVE-2021-416951 PoCAn SQL Injection vulnerability exists in Premiumdatingscript 4.2.7.7 via the ip parameter in connect.php. .
- CVE-2021-416961 PoCAn authentication bypass (account takeover) vulnerability exists in Premiumdatingscript 4.2.7.7 due to a weak password reset mechanism in…
- CVE-2021-416971 PoCA reflected Cross Site Scripting (XSS) vulnerability exists in Premiumdatingscript 4.2.7.7 via the aerror_description parameter in…
- CVE-2021-417151 PoClibsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379.
- CVE-2021-417161 PoCMaharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP…
- CVE-2021-417291 PoCBaiCloud-cms v2.5.7 is affected by an arbitrary file deletion vulnerability, which allows an attacker to delete arbitrary files on the…
- CVE-2021-417321 PoCAn issue was discovered in zeek version 4.1.0. There is a HTTP request splitting vulnerability that will invalidate any ZEEK HTTP based…
- CVE-2021-417491 PoCIn the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Side Template…
- CVE-2021-417651 PoCA SQL injection issue in pages/edit_fields/9_ajax/add_keyword.php of ResourceSpace 9.5 and 9.6 < rev 18274 allows remote unauthenticated…
- CVE-2021-41773184 PoCsKEVPath traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
- CVE-2021-417841 PoCFoxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and…
- CVE-2021-417941 PoCogs_fqdn_parse in Open5GS 1.0.0 through 2.3.3 inappropriately trusts a client-supplied length value, leading to a buffer overflow. The…
- CVE-2021-418053 PoCsHashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with…
- CVE-2021-418231 PoCThe Web Application Firewall (WAF) in Kemp LoadMaster 7.2.54.1 allows certain uses of onmouseover to bypass an XSS protection mechanism.
- CVE-2021-418251 PoCVerint Workforce Optimization (WFO) 15.2.5.1033 allows HTML injection via the /wfo/control/signin username parameter.
- CVE-2021-418262 PoCsPlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect.
- CVE-2021-418271 PoCZoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials are in the source…
- CVE-2021-418281 PoCZoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml.
- CVE-2021-418291 PoCZoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain encryption key.
- CVE-2021-418434 PoCsAn authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker to read data from…
- CVE-2021-418471 PoCAn issue was discovered in 3xLogic Infinias Access Control through 6.7.10708.0, affecting physical security. Users with login credentials…
- CVE-2021-418481 PoCAn issue was discovered in Luna Simo PPR1.180610.011/202001031830. It mishandles software updates such that local third-party apps can…
- CVE-2021-418491 PoCAn issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Information (PII) in…
- CVE-2021-418501 PoCAn issue was discovered in Luna Simo PPR1.180610.011/202001031830. A pre-installed app with a package name of com.skyroam.silverhelper…
- CVE-2021-418671 PoCAn information disclosure vulnerability in OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to retrieve the full list of…
- CVE-2021-418681 PoCOnionShare 2.3 before 2.4 allows remote unauthenticated attackers to upload files on a non-public node when using the --receive…
- CVE-2021-418784 PoCsA reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enables a remote…
- CVE-2021-419161 PoCA Cross-Site Request Forgery (CSRF) vulnerability in webTareas version 2.4 and earlier allows a remote attacker to create a new…
- CVE-2021-419171 PoCwebTareas version 2.4 and earlier allows an authenticated user to store arbitrary web script or HTML by creating or editing a client name…
- CVE-2021-419181 PoCwebTareas version 2.4 and earlier allows an authenticated user to inject arbitrary web script or HTML due to incorrect sanitization of…
- CVE-2021-419191 PoCwebTareas version 2.4 and earlier allows an authenticated user to arbitrarily upload potentially dangerous files without restrictions.…
- CVE-2021-419201 PoCwebTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint…
- CVE-2021-419281 PoCSQL injection in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) 1.0 by oretnom23, allows attackers to execute arbitrary code…
- CVE-2021-419291 PoCCross Site Scripting (XSS) in Sourcecodester The Electric Billing Management System 1.0 by oretnom23, allows attackers to execute…
- CVE-2021-419301 PoCCross site scripting (XSS) vulnerability in Sourcecodester Online Covid Vaccination Scheduler System v1 by oretnom23, allows attackers to…
- CVE-2021-419311 PoCThe Company's Recruitment Management System in id=2 of the parameter from view_vacancy app on-page appears to be vulnerable to SQL…
- CVE-2021-419451 PoCEncode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using…
- CVE-2021-419461 PoCIn FiberHome VDSL2 Modem HG150-Ub_V3.0, a stored cross-site scripting (XSS) vulnerability in Parental Control --> Access Time Restriction…
- CVE-2021-419471 PoCA SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode.
- CVE-2021-419501 PoCA directory traversal issue in ResourceSpace 9.6 before 9.6 rev 18277 allows remote unauthenticated attackers to delete arbitrary files on…
- CVE-2021-419512 PoCsResourceSpace before 9.6 rev 18290 is affected by a reflected Cross-Site Scripting vulnerability in plugins/wordpress_sso/pages/index.php…
- CVE-2021-419621 PoCCross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Owner fullname parameter…
- CVE-2021-419651 PoCA SQL injection vulnerability exists in ChurchCRM version 2.0.0 to 4.4.5 that allows an authenticated attacker to issue an arbitrary SQL…
- CVE-2021-419871 PoCIn the SCEP Server of RouterOS in certain Mikrotik products, an attacker can trigger a heap-based buffer overflow that leads to remote…