CVE-2021-43000 to CVE-2021-43999
185 CVEs with public proof-of-concept exploits.
- CVE-2021-430001 PoCAmzetta zPortal Windows zClient is affected by Buffer Overflow. IOCTL Handler 0x22001B in the Amzetta zPortal Windows zClient <=…
- CVE-2021-430021 PoCAmzetta zPortal DVM Tools is affected by Buffer Overflow. IOCTL Handler 0x22001B in the Amzetta zPortal DVM Tools <= v3.3.148.148 allow…
- CVE-2021-430031 PoCAmzetta zPortal Windows zClient is affected by Integer Overflow. IOCTL Handler 0x22001B in the Amzetta zPortal Windows zClient <=…
- CVE-2021-430061 PoCAmZetta Amzetta zPortal DVM Tools is affected by Integer Overflow. IOCTL Handler 0x22001B in the Amzetta zPortal DVM Tools <= v3.3.148.148…
- CVE-2021-430084 PoCsImproper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on…
- CVE-2021-430092 PoCsA Cross Site Scripting (XSS) vulnerability exists in OpServices OpMon through 9.11 via the search parameter in the request URL.
- CVE-2021-430321 PoCIn XenForo through 2.2.7, a threat actor with access to the admin panel can create a new Advertisement via the Advertising function, and…
- CVE-2021-430332 PoCsAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to…
- CVE-2021-430342 PoCsAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to execute arbitrary…
- CVE-2021-430352 PoCsAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Two unauthenticated SQL injection vulnerabilities were…
- CVE-2021-430362 PoCsAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak.
- CVE-2021-430372 PoCsAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable to DLL injection…
- CVE-2021-430382 PoCsAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by injecting into…
- CVE-2021-430392 PoCsAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Samba file sharing service allowed anonymous read/write…
- CVE-2021-430402 PoCsAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The privileged vaultServer could be leveraged to create…
- CVE-2021-430412 PoCsAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A crafted HTTP request could induce a format string…
- CVE-2021-430422 PoCsAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A buffer overflow existed in the vaultServer component. This…
- CVE-2021-430432 PoCsAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The apache user could read arbitrary files such as /etc/shadow…
- CVE-2021-430442 PoCsAn issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community.
- CVE-2021-430623 PoCsA improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0,…
- CVE-2021-430651 PoCA incorrect permission assignment for critical resource in Fortinet FortiNAC version 9.2.0, version 9.1.3 and below, version 8.8.9 and…
- CVE-2021-430911 PoCAn SQL Injection vlnerability exits in Yeswiki doryphore 20211012 via the email parameter in the registration form.
- CVE-2021-430971 PoCA Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction.javawhich could let a malicoius user…
- CVE-2021-430981 PoCA File Upload vulnerability exists in bbs v5.3 via QuestionManageAction.java in a getType function.
- CVE-2021-430991 PoCAn Archive Extraction (AKA "Zip Slip) vulnerability exists in bbs 5.3 in the UpgradeNow function in UpgradeManageAction.java, which unzips…
- CVE-2021-431001 PoCA File Upload vulnerability exists in bbs 5.3 is via TopicManageAction.java in a GetType function, which lets a remote malicious user…
- CVE-2021-431011 PoCA File Upload vulnerability exists in bbs 5.3 is via MembershipCardManageAction.java in a GetType function, which lets a remote malicious…
- CVE-2021-431021 PoCA File Upload vulnerability exists in bbs 5.3 is via HelpManageAction.java in a GetType function, which lets a remote malicious user…
- CVE-2021-431031 PoCA File Upload vulnerability exists in bbs 5.3 is via ForumManageAction.java in a GetType function, which lets a remote malicious user…
- CVE-2021-431091 PoCAn SQL Injection vulnerability exits in PuneethReddyHC online-shopping-system as of 11/01/2021 via the p parameter in product.php.
- CVE-2021-431101 PoCAn Access Conrol vulnerability exists in PuneethReddyHC online-shopping-system as of 11/01/2021 in add_products.
- CVE-2021-431131 PoCiTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs…
- CVE-2021-431161 PoCAn Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture…
- CVE-2021-431181 PoCA Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3…
- CVE-2021-431291 PoCA bypass exists for Desire2Learn/D2L Brightspace’s “Disable Right Click” option in the quizzing feature, which allows a quiz-taker to…
- CVE-2021-431302 PoCsAn SQL Injection vulnerability exists in Sourcecodester Customer Relationship Management System (CRM) 1.0 via the username parameter in…
- CVE-2021-431363 PoCsAn authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain a valid access to…
- CVE-2021-431371 PoCCross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in…
- CVE-2021-431403 PoCsSQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.
- CVE-2021-431412 PoCsCross Site Scripting (XSS) vulnerability exists in Sourcecodester Simple Subscription Website 1.0 via the id parameter in plan_application.
- CVE-2021-431421 PoCAn XML External Entity (XXE) vulnerability exists in wuta jox 1.16 in the readObject method in JOXSAXBeanInput.
- CVE-2021-431551 PoCProjectsworlds Online Book Store PHP v1.0 is vulnerable to SQL injection via the "bookisbn" parameter in cart.php.
- CVE-2021-431561 PoCIn ProjectWorlds Online Book Store PHP 1.0 a CSRF vulnerability in admin_delete.php allows a remote attacker to delete any book.
- CVE-2021-431571 PoCProjectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php.
- CVE-2021-431581 PoCIn ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cart_remove.php allows a remote attacker to remove any product in…
- CVE-2021-431642 PoCsA Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 /…
- CVE-2021-432171 PoCWindows Encrypting File System (EFS) Remote Code Execution Vulnerability
- CVE-2021-432241 PoCWindows Common Log File System Driver Information Disclosure Vulnerability
- CVE-2021-432262 PoCsKEVWindows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2021-432291 PoCWindows NTFS Elevation of Privilege Vulnerability
- CVE-2021-432571 PoCLack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an unprivileged attacker to execute code or…
- CVE-2021-432582 PoCsCartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. This requires authenticated…
- CVE-2021-432672 PoCsAn issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC)…
- CVE-2021-432821 PoCAn issue was discovered on Victure WR1200 devices through 1.0.3. The default Wi-Fi WPA2 key is advertised to anyone within Wi-Fi range…
- CVE-2021-432831 PoCAn issue was discovered on Victure WR1200 devices through 1.0.3. A command injection vulnerability was found within the web interface of…
- CVE-2021-432841 PoCAn issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its default value of admin.…
- CVE-2021-432861 PoCAn issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a GoCD server can…
- CVE-2021-432874 PoCsAn issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets…
- CVE-2021-432881 PoCAn issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker in control of a GoCD Agent can plant malicious JavaScript into a…
- CVE-2021-432891 PoCAn issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into…
- CVE-2021-432901 PoCAn issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into…
- CVE-2021-432972 PoCsDubbo Hessian cause RCE when parse error
- CVE-2021-433041 PoCHeap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy…
- CVE-2021-433051 PoCHeap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy…
- CVE-2021-433061 PoCExponential ReDoS in jquery-validation
- CVE-2021-433071 PoCExponential ReDoS in semver-regex
- CVE-2021-433081 PoCExponential ReDoS in markdown-link-extractor
- CVE-2021-433091 PoCReDoS in uri-template-lite URI.expand function
- CVE-2021-433111 PoCA heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32().…
- CVE-2021-433121 PoCA heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address. The issue is being…
- CVE-2021-433131 PoCA heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address. The issue is being…
- CVE-2021-433141 PoCA heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32().…
- CVE-2021-433151 PoCA heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32().…
- CVE-2021-433161 PoCA heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le64().
- CVE-2021-433171 PoCA heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32().…
- CVE-2021-433251 PoCAutomox Agent 33 on Windows incorrectly sets permissions on a temporary directory. NOTE: this issue exists because of a CVE-2021-43326…
- CVE-2021-433263 PoCsAutomox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.
- CVE-2021-433296 PoCsA SQL injection vulnerability in license_update.php in Mumara Classic through 2.93 allows a remote unauthenticated attacker to execute…
- CVE-2021-433341 PoCBuddyBoss Platform through 1.8.0 allows XSS via the Group Name or Group Description field.
- CVE-2021-433392 PoCsIn Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the…
- CVE-2021-433962 PoCsIn iconvdata/iso-2022-jp-3.c in the GNU C Library (aka glibc) 2.34, remote attackers can force iconv() to emit a spurious '\0' character…
- CVE-2021-433971 PoCLiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin.
- CVE-2021-433991 PoCThe Yubico YubiHSM YubiHSM2 library 2021.08, included in the yubihsm-shell project, does not properly validate the length of some…
- CVE-2021-434053 PoCsAn issue was discovered in FusionPBX before 4.5.30. The fax_extension may have risky characters (it is not constrained to be numeric).
- CVE-2021-434081 PoCDuplicate Post WordPress Plugin SQL Injection Vulnerability
- CVE-2021-434091 PoCWPO365 | LOGIN - Wordpress Plugin Persistent Cross-Site Scripting
- CVE-2021-434211 PoCA File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user…
- CVE-2021-434291 PoCA Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release…
- CVE-2021-434461 PoCONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS). The "macros" feature of the document editor allows…
- CVE-2021-434471 PoCONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the document editor allows…
- CVE-2021-434481 PoCONLYOFFICE all versions as of 2021-11-08 is vulnerable to Improper Input Validation. A lack of input validation can allow an attacker to…
- CVE-2021-434491 PoCONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF). The document editor service can be abused to…
- CVE-2021-434511 PoCSQL Injection vulnerability exists in PHPGURUKUL Employee Record Management System 1.2 via the Email POST parameter in /forgetpassword.php.
- CVE-2021-434531 PoCA Heap-based Buffer Overflow vulnerability exists in JerryScript 2.4.0 and prior versions via an out-of-bounds read in…
- CVE-2021-434541 PoCAn Unquoted Service Path vulnerability exists in AnyTXT Searcher 1.2.394 via a specially crafted file in the ATService path. .
- CVE-2021-434551 PoCAn Unquoted Service Path vulnerability exists in FreeLAN 2.2 via a specially crafted file in the FreeLAN Service path.
- CVE-2021-434561 PoCAn Unquoted Service Path vulnerablility exists in Rumble Mail Server 0.51.3135 via via a specially crafted file in the RumbleService…
- CVE-2021-434571 PoCAn Unquoted Service Path vulnerability exists in bVPN 2.5.1 via a specially crafted file in the waselvpnserv service path.
- CVE-2021-434581 PoCAn Unquoted Service Path vulnerability exits in Vembu BDR 4.2.0.1 via a specially crafted file in the (1) hsflowd, (2) VembuBDR360Agent,…
- CVE-2021-434591 PoCA Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the (1) domain and (2) path parameters.
- CVE-2021-434601 PoCAn Unquoted Service Path vulnerability exists in System Explorer 7.0.0 via via a specially crafted file in the SystemExplorerHelpService…
- CVE-2021-434611 PoCCross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the servername parameter.
- CVE-2021-434621 PoCA Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the username parameter.
- CVE-2021-434631 PoCAn Unquoted Service Path vulnerability exists in Ext2Fsd v0.68 via a specially crafted file in the Ext2Srv Service executable service path.
- CVE-2021-434691 PoCVINGA WR-N300U 77.102.1.4853 is affected by a command execution vulnerability in the goahead component.
- CVE-2021-434711 PoCIn Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can remotely shut down…
- CVE-2021-434813 PoCsAn SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstage.php.
- CVE-2021-434831 PoCAn Access Control vulnerability exists in CLARO KAON CG3000 1.00.67 in the router configuration, which could allow a malicious user to…
- CVE-2021-434841 PoCA Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failure to validate the…
- CVE-2021-434921 PoCAlquistManager branch as of commit 280d99f43b11378212652e75f6f3159cde9c1d36 is affected by a directory traversal vulnerability. This…
- CVE-2021-434931 PoCServerManagement master branch as of commit 49491cc6f94980e6be7791d17be947c27071eb56 is affected by a directory traversal vulnerability.…
- CVE-2021-434952 PoCsAlquistManager branch as of commit 280d99f43b11378212652e75f6f3159cde9c1d36 is affected by a directory traversal vulnerability in…
- CVE-2021-434962 PoCsClustering master branch as of commit 53e663e259bcfc8cdecb56c0bb255bd70bfcaa70 is affected by a directory traversal vulnerability. This…
- CVE-2021-434981 PoCAn Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change…
- CVE-2021-435051 PoCMultiple Cross Site Scripting (XSS) vulnerabilities exist in Ssourcecodester Simple Client Management System v1 via (1) Add new Client and…
- CVE-2021-435061 PoCAn SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the password parameter in Login.php.
- CVE-2021-435092 PoCsSQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-service.php.
- CVE-2021-435103 PoCsSQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php.
- CVE-2021-435171 PoCFOSCAM Camera FI9805E with firmware V4.02.R12.00018510.10012.143900.00000 contains a backdoor that opens Telnet port when special command…
- CVE-2021-435301 PoCA Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned from a…
- CVE-2021-435571 PoCPath traversal in request_uri variable
- CVE-2021-435661 PoCAll versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created…
- CVE-2021-435681 PoCThe verify function in the Stark Bank Elixir ECDSA library (ecdsa-elixir) 1.0.0 fails to check that the signature is non-zero, which…
- CVE-2021-435691 PoCThe verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows…
- CVE-2021-435701 PoCThe verify function in the Stark Bank Java ECDSA library (ecdsa-java) 1.0.0 fails to check that the signature is non-zero, which allows…
- CVE-2021-435711 PoCThe verify function in the Stark Bank Node.js ECDSA library (ecdsa-node) 1.1.2 fails to check that the signature is non-zero, which allows…
- CVE-2021-435721 PoCThe verify function in the Stark Bank Python ECDSA library (aka starkbank-escada or ecdsa-python) before 2.0.1 fails to check that the…
- CVE-2021-435741 PoCWebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default URI. NOTE: This…
- CVE-2021-435751 PoCKNX ETS6 through 6.0.0 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project…
- CVE-2021-435792 PoCsA stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML…
- CVE-2021-436092 PoCsAn issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within the…
- CVE-2021-436162 PoCsThe npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json…
- CVE-2021-436175 PoCsLaravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because…
- CVE-2021-436281 PoCProjectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php.
- CVE-2021-436291 PoCProjectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php.
- CVE-2021-436301 PoCProjectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in add_patient.php. As a result, an…
- CVE-2021-436311 PoCProjectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment.php.
- CVE-2021-436371 PoCAmazon WorkSpaces agent is affected by Buffer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow…
- CVE-2021-436381 PoCAmazon Amazon WorkSpaces agent is affected by Integer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537…
- CVE-2021-436502 PoCsWebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process.
- CVE-2021-436571 PoCA Stored Cross-site scripting (XSS) vulnerability via MAster.php in Sourcecodetester Simple Client Management System (SCMS) 1.0 allows…
- CVE-2021-436831 PoCpictshare v1.5 is affected by a Cross Site Scripting (XSS) vulnerability in api/info.php. The exit function will terminate the script and…
- CVE-2021-436911 PoCtripexpress v1.1 is affected by a path manipulation vulnerability in file system/helpers/dompdf/load_font.php. The variable src is coming…
- CVE-2021-437001 PoCAn issue was discovered in ApiManager 1.1. there is sql injection vulnerability that can use in /index.php?act=api&tag=8.
- CVE-2021-437013 PoCsCSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/article_db, via the…
- CVE-2021-437021 PoCASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs…
- CVE-2021-437111 PoCThe downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET…
- CVE-2021-437121 PoCStored XSS in Add New Employee Form in Sourcecodester Employee Daily Task Management System 1.0 Allows Remote Attacker to Inject/Store…
- CVE-2021-437221 PoCD-Link DIR-645 1.03 A1 is vulnerable to Buffer Overflow. The hnap_main function in the cgibin handler uses sprintf to format the…
- CVE-2021-437241 PoCA Cross Site Scripting (XSS) vulnerability exits in Subrion CMS through 4.2.1 in the Create Page functionality of the admin Account via a…
- CVE-2021-437251 PoCThere is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remote attackers to…
- CVE-2021-437281 PoCPix-Link MiNi Router 28K.MiniRouter.20190211 was discovered to contain a stored cross-site scripting (XSS) vulnerability due to an…
- CVE-2021-437291 PoCPix-Link MiNi Router 28K.MiniRouter.20190211 was discovered to contain a stored cross-site scripting (XSS) vulnerability due to an…
- CVE-2021-437343 PoCskkFileview v4.0.0 has arbitrary file read through a directory traversal vulnerability which may lead to sensitive file leak on related host.
- CVE-2021-437371 PoCAn issus was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can modify administrator account's password.
- CVE-2021-437381 PoCAn issue was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can that can add the administrator account.
- CVE-2021-437411 PoCCMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on…
- CVE-2021-437421 PoCCMSimple 5.4 is vulnerable to Cross Site Scripting (XSS) via the file upload feature.
- CVE-2021-437783 PoCsPath traversal in GLPI barcode plugin
- CVE-2021-437791 PoCRemote Command Execution vulnerability
- CVE-2021-437892 PoCsBlind SQLi using Search filters in PrestaShop
- CVE-2021-4379869 PoCsKEVGrafana path traversal
- CVE-2021-437991 PoCRabbitMQ exposes ports with weak default secrets in Zulip Server
- CVE-2021-438091 PoCLocal Code Execution through Argument Injection via dash leading git url parameter in Gemfile
- CVE-2021-438101 PoCCross-site Scripting (XSS) when redirect an url
- CVE-2021-438111 PoCCode injection via unsafe YAML loading
- CVE-2021-438211 PoCFiles Accessible to External Parties in Opencast
- CVE-2021-438281 PoCImproper Privilege Management in Patrowl
- CVE-2021-438291 PoCUnrestricted Upload of Files in Patrowl
- CVE-2021-438311 PoCFiles on the host computer can be accessed from the Gradio interface
- CVE-2021-438371 PoCTemplate injection in vault-cli
- CVE-2021-438471 PoCAuthorization Bypass in Space Invite in HumHub
- CVE-2021-438481 PoCUnititialized memory access in h2o
- CVE-2021-438577 PoCsGerapy may contain remote code execution vulnerability
- CVE-2021-438582 PoCsUser privilege escalation in MinIO
- CVE-2021-438901 PoCKEVWindows AppX Installer Spoofing Vulnerability
- CVE-2021-438911 PoCVisual Studio Code Remote Code Execution Vulnerability
- CVE-2021-438933 PoCsWindows Encrypting File System (EFS) Elevation of Privilege Vulnerability
- CVE-2021-439081 PoCVisual Studio Code Spoofing Vulnerability
- CVE-2021-439363 PoCsDistributed Data Systems WebHM
- CVE-2021-439691 PoCThe login.jsp page of Quicklert for Digium 10.0.0 (1043) is affected by both Blind SQL Injection with Out-of-Band Interaction (DNS) and…
- CVE-2021-439701 PoCAn arbitrary file upload vulnerability exists in albumimages.jsp in Quicklert for Digium 10.0.0 (1043) via a .mp3;.jsp filename for a file…
- CVE-2021-439711 PoCA SQL injection vulnerability in /mobile/SelectUsers.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to execute…
- CVE-2021-439741 PoCAn issue was discovered in SysAid ITIL 20.4.74 b10. The /enduserreg endpoint is used to register end users anonymously, but does not…
- CVE-2021-439911 PoCPersistent XSS via Avatar Upload in Kentico Xperience CMS