CVE-2021-44000 to CVE-2021-44999
203 CVEs with public proof-of-concept exploits.
- CVE-2021-440262 PoCsKEVRoundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
- CVE-2021-440321 PoCTP-Link Omada SDN Software Controller before 5.0.15 does not check if the authentication method specified in a connection request is…
- CVE-2021-440491 PoCCyberArk Endpoint Privilege Manager (EPM) through 11.5.3.328 before 2021-12-20 allows a local user to gain elevated privileges via a…
- CVE-2021-440761 PoCAn issue was discovered in CrushFTP 9. The creation of a new user through the /WebInterface/UserManager/ interface allows an attacker,…
- CVE-2021-440775 PoCsKEVZoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to…
- CVE-2021-440801 PoCA Command Injection vulnerability in httpd web server (setup.cgi) in SerComm h500s, FW: lowi-h500s-v3.4.22 allows logged in administrators…
- CVE-2021-440871 PoCA Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated…
- CVE-2021-440881 PoCAn SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass…
- CVE-2021-440911 PoCA Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in register.php via the…
- CVE-2021-440921 PoCAn SQL Injection vulnerability exists in code-projects Pharmacy Management 1.0 via the username parameter in the administer login form.
- CVE-2021-441081 PoCA null pointer dereference in src/amf/namf-handler.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a…
- CVE-2021-441091 PoCA buffer overflow in lib/sbi/message.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request.
- CVE-2021-441111 PoCA Directory Traversal vulnerability exists in S-Cart 6.7 via download in sc-admin/backup.
- CVE-2021-441171 PoCA Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to…
- CVE-2021-441271 PoCIn DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execute arbitrary system…
- CVE-2021-441321 PoCA command injection vulnerability in the function formImportOMCIShell of C-DATA ONU4FERW V2.1.13_X139 allows attackers to execute…
- CVE-2021-441381 PoCThere is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to…
- CVE-2021-441392 PoCsSentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).
- CVE-2021-441423 PoCsThe Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and…
- CVE-2021-441522 PoCsAn issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an…
- CVE-2021-441531 PoCAn issue was discovered in Reprise RLM 14.2. When editing the license file, it is possible for an admin user to enable an option to run…
- CVE-2021-441541 PoCAn issue was discovered in Reprise RLM 14.2. By using an admin account, an attacker can write a payload to /goform/edit_opt, which will…
- CVE-2021-441551 PoCAn issue was discovered in /goform/login_process in Reprise RLM 14.2. When an attacker attempts to login, the response if a username is…
- CVE-2021-441681 PoCKEVA download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a…
- CVE-2021-441861 PoCAdobe Bridge SGI File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
- CVE-2021-442081 PoCOX App Suite through 7.10.5 allows XSS via an unknown system message in Chat.
- CVE-2021-442091 PoCOX App Suite through 7.10.5 allows XSS via an HTML 5 element such as AUDIO.
- CVE-2021-442111 PoCOX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature.
- CVE-2021-442121 PoCOX App Suite through 7.10.5 allows XSS via a trailing control character such as the SCRIPT\t substring.
- CVE-2021-442131 PoCOX App Suite through 7.10.5 allows XSS via uuencoding in a multipart/alternative message.
- CVE-2021-442171 PoCIn Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer…
- CVE-2021-442232 PoCsWordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code…
- CVE-2021-442263 PoCsRazer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if…
- CVE-2021-44228448 PoCsKEVApache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
- CVE-2021-442441 PoCAn SQL Injection vulnerabiity exists in Sourcecodester Logistic Hub Parcel's Management System 1.0 via the username parameter in login.php.
- CVE-2021-442451 PoCAn SQL Injection vulnerability exists in Courcecodester COVID 19 Testing Management System (CTMS) 1.0 via the (1) username and (2)…
- CVE-2021-442492 PoCsOnline Motorcycle (Bike) Rental System 1.0 is vulnerable to a Blind Time-Based SQL Injection attack within the login portal. This can lead…
- CVE-2021-442591 PoCA vulnerability is in the 'wx.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to…
- CVE-2021-442602 PoCsA vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote…
- CVE-2021-442611 PoCA vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access…
- CVE-2021-442621 PoCA vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access…
- CVE-2021-442801 PoCattendance management system 1.0 is affected by a SQL injection vulnerability in admin/incFunctions.php through the makeSafe function.
- CVE-2021-443021 PoCBaiCloud-cms v2.5.7 was discovered to contain multiple SQL injection vulnerabilities via the tongji and baidu_map parameters in…
- CVE-2021-443101 PoCAn issue was discovered in Firmware Analysis and Comparison Tool v3.2. With administrator privileges, the attacker could perform stored…
- CVE-2021-443121 PoCAn issue was discovered in Firmware Analysis and Comparison Tool v3.2. Logged in administrators could be targeted by a CSRF attack through…
- CVE-2021-443151 PoCIn Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to view the sensitive…
- CVE-2021-443311 PoCARM astcenc 3.2.0 is vulnerable to Buffer Overflow in function encode_ise().
- CVE-2021-443341 PoCDavid Brackeen ok-file-formats 97f78ca is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a…
- CVE-2021-443351 PoCDavid Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a…
- CVE-2021-443391 PoCDavid Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a…
- CVE-2021-443401 PoCDavid Brackeen ok-file-formats dev version is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a…
- CVE-2021-443421 PoCDavid Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow via function ok_png_transform_scanline() in "/ok_png.c:494".
- CVE-2021-443431 PoCDavid Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a…
- CVE-2021-443471 PoCSQL Injection vulnerability exists in TuziCMS v2.0.6 in App\Manage\Controller\GuestbookController.class.php.
- CVE-2021-443521 PoCA Stack-based Buffer Overflow vulnerability exists in the Tenda AC15 V15.03.05.18_multi device via the list parameter in a post request in…
- CVE-2021-443541 PoCMultiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W…
- CVE-2021-443551 PoCMultiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W…
- CVE-2021-443561 PoCMultiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W…
- CVE-2021-443571 PoCMultiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W…
- CVE-2021-443581 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443591 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443601 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443611 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443621 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443631 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443641 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443651 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443661 PoCMultiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W…
- CVE-2021-443671 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443681 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443691 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443701 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443711 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443721 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443731 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443741 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443751 PoCMultiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W…
- CVE-2021-443761 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443771 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443781 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443791 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443801 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443811 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443821 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443831 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443841 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443851 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443861 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443871 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443881 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443891 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443901 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443911 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443921 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443931 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443941 PoCMultiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W…
- CVE-2021-443951 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443961 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443971 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443981 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-443991 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-444001 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-444011 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-444021 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-444031 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-444041 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-444051 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-444061 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-444071 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-444081 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-444091 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-444101 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-444111 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-444121 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-444131 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-444141 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-444151 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-444161 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-444171 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-444181 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-444191 PoCA denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A…
- CVE-2021-444272 PoCsAn unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers…
- CVE-2021-444281 PoCPinkie 2.15 allows remote attackers to cause a denial of service (daemon crash) via a TFTP read (RRQ) request, aka opcode 1.
- CVE-2021-444291 PoCServa 4.4.0 allows remote attackers to cause a denial of service (daemon crash) via a TFTP read (RRQ) request, aka opcode 1, a related…
- CVE-2021-444442 PoCsA vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected…
- CVE-2021-444512 PoCsAPI sensitive information leak
- CVE-2021-445151 PoCKEVZoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in…
- CVE-2021-445213 PoCsRemote code execution for scripted UDFs
- CVE-2021-445281 PoCA open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in…
- CVE-2021-445297 PoCsKEVA code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code…
- CVE-2021-445541 PoCThinfinity VirtualUI before 3.0 allows a malicious actor to enumerate users registered in the OS (Windows) through the /changePassword…
- CVE-2021-445651 PoCA Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 7.6.1 via the xss_clean function in classes/Security.php, which…
- CVE-2021-445672 PoCsAn unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in…
- CVE-2021-445682 PoCsTwo heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the…
- CVE-2021-445821 PoCA Privilege Escalation vulnerability exists in Sourcecodester Money Transfer Management System 1.0, which allows a remote malicious user…
- CVE-2021-445861 PoCAn issue was discovered in dst-admin v1.3.0. The product has an unauthorized arbitrary file download vulnerability that can expose…
- CVE-2021-445901 PoCIn libming 0.4.8, a memory exhaustion vulnerability exist in the function cws2fws in util/main.c. Remote attackers could launch denial of…
- CVE-2021-445911 PoCIn libming 0.4.8, the parseSWF_DEFINELOSSLESS2 function in util/parser.c lacks a boundary check that would lead to denial-of-service…
- CVE-2021-445932 PoCsSimple College Website 1.0 is vulnerable to unauthenticated file upload & remote code execution via UNION-based SQL injection in the…
- CVE-2021-445952 PoCsWondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send manually crafted…
- CVE-2021-445962 PoCsWondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated…
- CVE-2021-445981 PoCAttendance Management System 1.0 is affected by a Cross Site Scripting (XSS) vulnerability. The value of the FirstRecord request parameter…
- CVE-2021-445991 PoCThe id parameter from Online Enrollment Management System 1.0 system appears to be vulnerable to SQL injection attacks. A crafted payload…
- CVE-2021-446001 PoCThe password parameter on Simple Online Mens Salon Management System (MSMS) 1.0 appears to be vulnerable to SQL injection attacks through…
- CVE-2021-446171 PoCA SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated.
- CVE-2021-446221 PoCA Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/check_reg_verify_code function…
- CVE-2021-446231 PoCA Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 via the /cloud_config/router_post/check_reset_pwd_verify_code…
- CVE-2021-446251 PoCA Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in /cloud_config/cloud_device/info interface, which allows a…
- CVE-2021-446261 PoCA Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/get_reg_verify_code feature,…
- CVE-2021-446271 PoCA Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/get_reset_pwd_veirfy_code…
- CVE-2021-446281 PoCA Buffer Overflow vulnerabiltiy exists in TP-LINK WR-886N 20190826 2.3.8 in thee /cloud_config/router_post/login feature, which allows…
- CVE-2021-446291 PoCA Buffer Overflow vulnerabilitiy exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/register feature, which allows…
- CVE-2021-446301 PoCA Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/modify_account_pwd feature,…
- CVE-2021-446311 PoCA Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/reset_cloud_pwd feature, which…
- CVE-2021-446321 PoCA Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/upgrade_info feature, which…
- CVE-2021-446482 PoCsGNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF…
- CVE-2021-446491 PoCDjango CMS 3.7.3 does not validate the plugin_type parameter while generating error messages for an invalid plugin type, resulting in a…
- CVE-2021-446532 PoCsOnline Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be…
- CVE-2021-446552 PoCsOnline Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability. Admin panel…
- CVE-2021-446572 PoCsIn StackStorm versions prior to 3.6.0, the jinja interpreter was not run in sandbox mode and thus allows execution of unsafe system…
- CVE-2021-446591 PoCAdding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to…
- CVE-2021-446631 PoCA Remote Code Execution (RCE) vulnerability exists in the Xerte Project Xerte through 3.8.4 via a crafted php file through elfinder in…
- CVE-2021-446643 PoCsAn Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by…
- CVE-2021-446652 PoCsA Directory Traversal vulnerability exists in the Xerte Project Xerte through 3.10.3 when downloading a project file via download.php.
- CVE-2021-446671 PoCA Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo parameters.
- CVE-2021-446731 PoCA Remote Code Execution (RCE) vulnerability exists in Croogo 3.0.2via admin/file-manager/attachments, which lets a malicoius user upload a…
- CVE-2021-446841 PoCnaholyr github-todos 3.1.0 is vulnerable to command injection. The range argument for the _hook subcommand is concatenated without any…
- CVE-2021-446851 PoCGit-it through 4.4.0 allows OS command injection at the Branches Aren't Just For Birds challenge step. During the verification process, it…
- CVE-2021-446862 PoCscalibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in…
- CVE-2021-447313 PoCssnapd could be made to escalate privileges and run programs as administrator
- CVE-2021-447331 PoCA use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race…
- CVE-2021-447903 PoCsPossible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
- CVE-2021-448273 PoCsThere is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devices vie the…
- CVE-2021-448293 PoCsCross Site Scripting (XSS) vulnerability exists in index.html in AFI WebACMS through 2.1.0 via the the ID parameter.
- CVE-2021-448323 PoCsApache Log4j2 vulnerable to RCE via JDBC Appender when attacker controls configuration
- CVE-2021-448351 PoCAn issue was discovered in Active Intelligent Visualization 5. The Vdc header is used in a SQL query without being sanitized. This causes…
- CVE-2021-448483 PoCsIn Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication requests depending on…
- CVE-2021-448522 PoCsAn issue was discovered in BS_RCIO64.sys in Biostar RACING GT Evo 2.1.1905.1700. A low-integrity process can open the driver's device…
- CVE-2021-448641 PoCTP-Link WR886N 3.0 1.0.1 Build 150127 Rel.34123n is vulnerable to Buffer Overflow. Authenticated attackers can crash router httpd services…
- CVE-2021-448681 PoCA problem was found in ming-soft MCMS v5.1. There is a sql injection vulnerability in /ms/cms/content/list.do
- CVE-2021-448991 PoCMicro-Star International (MSI) Center <= 1.0.31.0 is vulnerable to multiple Privilege Escalation vulnerabilities in the atidgllk.sys,…
- CVE-2021-449063 PoCsMinimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
- CVE-2021-449081 PoCSailsJS Sails.js <=1.4.0 is vulnerable to Prototype Pollution via controller/load-action-modules.js, function loadActionModules().
- CVE-2021-449151 PoCTaocms 3.0.2 was discovered to contain a blind SQL injection vulnerability via the function Edit category.
- CVE-2021-449162 PoCsOpmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad value is passed…
- CVE-2021-449181 PoCA Null Pointer Dereference vulnerability exists in gpac 1.1.0 in the gf_node_get_field function, which can cause a segmentation fault and…
- CVE-2021-449201 PoCAn invalid memory address dereference vulnerability exists in gpac 1.1.0 in the dump_od_to_saf.isra function, which causes a segmentation…
- CVE-2021-449211 PoCA null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_isom_parse_movie_boxes_internal function, which causes a…
- CVE-2021-449221 PoCA null pointer dereference vulnerability exists in gpac 1.1.0 in the BD_CheckSFTimeOffset function, which causes a segmentation fault and…
- CVE-2021-449241 PoCAn infinite loop vulnerability exists in gpac 1.1.0 in the gf_log function, which causes a Denial of Service.
- CVE-2021-449251 PoCA null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_svg_get_attribute_name function, which causes a segmentation fault…
- CVE-2021-449421 PoCglFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF) vulnerability in…
- CVE-2021-449561 PoCTwo Heap based buffer overflow vulnerabilities exist in ffjpeg through 01.01.2021. It is similar to CVE-2020-23852. Issues that are in the…
- CVE-2021-449571 PoCGlobal buffer overflow vulnerability exist in ffjpeg through 01.01.2021. It is similar to CVE-2020-23705. Issue is in the jfif_encode…
- CVE-2021-449641 PoCUse after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a…
- CVE-2021-449651 PoCDirectory traversal vulnerability in /admin/includes/* directory for PHPGURUKUL Employee Record Management System 1.2 The attacker can…
- CVE-2021-449661 PoCSQL injection bypass authentication vulnerability in PHPGURUKUL Employee Record Management System 1.2 via index.php. An attacker can log…
- CVE-2021-449676 PoCsA Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a…
- CVE-2021-449811 PoCIn QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it into a…
- CVE-2021-449881 PoCJerryscript v3.0.0 and below was discovered to contain a stack overflow via ecma_find_named_property in ecma-helpers.c.
- CVE-2021-449921 PoCThere is an Assertion ''ecma_object_is_typedarray (obj_p)'' failed at /jerry-core/ecma/operations/ecma-typedarray-object.c in Jerryscript…
- CVE-2021-449931 PoCThere is an Assertion ''ecma_is_value_boolean (base_value)'' failed at /jerry-core/ecma/operations/ecma-get-put-value.c in Jerryscript…
- CVE-2021-449941 PoCThere is an Assertion ''JERRY_CONTEXT (jmem_heap_allocated_size) == 0'' failed at /jerry-core/jmem/jmem-heap.c in Jerryscript 3.0.0.