CVE-2021-45000 to CVE-2021-45999
148 CVEs with public proof-of-concept exploits.
- CVE-2021-450071 PoCPlesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and…
- CVE-2021-450081 PoCPlesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE:…
- CVE-2021-450109 PoCsA path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote…
- CVE-2021-450252 PoCsASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage…
- CVE-2021-450262 PoCsASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).
- CVE-2021-450272 PoCsAn arbitrary file download vulnerability in Oliver v5 Library Server Versions < 5.00.008.053 via the FileServlet function allows for…
- CVE-2021-450342 PoCsA vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O…
- CVE-2021-450411 PoCSuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving…
- CVE-2021-450434 PoCsHD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_Language parameter.
- CVE-2021-4504615 PoCsKEVApache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
- CVE-2021-450671 PoCAdobe Acrobat Reader Memory Corruption could lead to Information Disclosure
- CVE-2021-450781 PoCstab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow)…
- CVE-2021-450851 PoCXSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when…
- CVE-2021-450861 PoCXSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name…
- CVE-2021-450871 PoCXSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated…
- CVE-2021-450881 PoCXSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page.
- CVE-2021-450922 PoCsThinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath…
- CVE-2021-450981 PoCAn issue was discovered in Suricata before 6.0.4. It is possible to bypass/evade any HTTP-based signature by faking an RST TCP packet with…
- CVE-2021-450991 PoCThe addon.stdin service in addon-ssh (aka Home Assistant Community Add-on: SSH & Web Terminal) before 10.0.0 has an attack surface that…
- CVE-2021-4510510 PoCsApache Log4j2 does not always protect from infinite recursion in lookup evaluation
- CVE-2021-451171 PoCThe OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointer dereference.
- CVE-2021-452221 PoCAn issue was discovered in COINS Construction Cloud 11.12. Due to logical flaws in the human ressources interface, it is vulnerable to…
- CVE-2021-452231 PoCAn issue was discovered in COINS Construction Cloud 11.12. Due to insufficient input neutralization, it is vulnerable to denial of service…
- CVE-2021-452241 PoCAn issue was discovered in COINS Construction Cloud 11.12. In several locations throughout the application, JavaScript code is passed as a…
- CVE-2021-452251 PoCAn issue was discovered in COINS Construction Cloud 11.12. Due to improper input neutralization, it is vulnerable to reflected cross-site…
- CVE-2021-452261 PoCAn issue was discovered in COINS Construction Cloud 11.12. Due to improper validation of user-controlled HTTP headers, attackers can cause…
- CVE-2021-452271 PoCAn issue was discovered in COINS Construction Cloud 11.12. Due to an inappropriate use of HTML IFRAME elements, the file upload…
- CVE-2021-452281 PoCAn XSS issue was discovered in COINS Construction Cloud 11.12. Due to insufficient neutralization of user input in the description of a…
- CVE-2021-4523213 PoCssecurity vulnerability on unauthorized access.
- CVE-2021-452521 PoCMultiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are…
- CVE-2021-452531 PoCThe id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL injection attacks. A…
- CVE-2021-452551 PoCThe email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL…
- CVE-2021-452581 PoCA stack overflow vulnerability exists in gpac 1.1.0 via the gf_bifs_dec_proto_list function, which causes a segmentation fault and…
- CVE-2021-452591 PoCAn Invalid pointer reference vulnerability exists in gpac 1.1.0 via the gf_svg_node_del function, which causes a segmentation fault and…
- CVE-2021-452601 PoCA null pointer dereference vulnerability exists in gpac 1.1.0 in the lsr_read_id.part function, which causes a segmentation fault and…
- CVE-2021-452621 PoCAn invalid free vulnerability exists in gpac 1.1.0 via the gf_sg_command_del function, which causes a segmentation fault and application…
- CVE-2021-452631 PoCAn invalid free vulnerability exists in gpac 1.1.0 via the gf_svg_delete_attribute_value function, which causes a segmentation fault and…
- CVE-2021-452671 PoCAn invalid memory address dereference vulnerability exists in gpac 1.1.0 via the svg_node_start function, which causes a segmentation…
- CVE-2021-452681 PoCA Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution…
- CVE-2021-452811 PoCQuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the user supplied input…
- CVE-2021-452861 PoCDirectory Traversal vulnerability exists in ZZCMS 2021 via the skin parameter in 1) index.php, 2) bottom.php, and 3) top_index.php.
- CVE-2021-452881 PoCA Double Free vulnerability exists in filedump.c in GPAC 1.0.1, which could cause a Denail of Service via a crafted file in the MP4Box…
- CVE-2021-452891 PoCA vulnerability exists in GPAC 1.0.1 due to an omission of security-relevant Information, which could cause a Denial of Service. The…
- CVE-2021-452911 PoCThe gf_dump_setup function in GPAC 1.0.1 allows malicoius users to cause a denial of service (Invalid memory address dereference) via a…
- CVE-2021-452921 PoCThe gf_isom_hint_rtp_read function in GPAC 1.0.1 allows attackers to cause a denial of service (Invalid memory address dereference) via a…
- CVE-2021-452971 PoCAn infinite loop vulnerability exists in Gpac 1.0.1 in gf_get_bit_size.
- CVE-2021-453281 PoCGitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.
- CVE-2021-453343 PoCsSourcecodester Online Thesis Archiving System 1.0 is vulnerable to SQL Injection. An attacker can bypass admin authentication and gain…
- CVE-2021-453401 PoCIn Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause…
- CVE-2021-453411 PoCA buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote…
- CVE-2021-453421 PoCA buffer overflow vulnerability in CDataList of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote…
- CVE-2021-453431 PoCIn LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the application using a…
- CVE-2021-453461 PoCA Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the…
- CVE-2021-453801 PoCAppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.php
- CVE-2021-453822 PoCsKEVA Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and…
- CVE-2021-453851 PoCA Null Pointer Dereference vulnerability exits in ffjpeg d5cfd49 (2021-12-06) in bmp_load(). When the size information in metadata of the…
- CVE-2021-453861 PoCtcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv6() at tree.c
- CVE-2021-453871 PoCtcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv4() at tree.c.
- CVE-2021-453911 PoCA Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in the goform/setIPv6Status binary…
- CVE-2021-453921 PoCA Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in page /goform/setIPv6Status via…
- CVE-2021-454011 PoCA Command injection vulnerability exists in Tenda AC10U AC1200 Smart Dual-band Wireless Router AC10U V1.0 Firmware V15.03.06.49_multi via…
- CVE-2021-454061 PoCIn SalonERP 3.0.1, a SQL injection vulnerability allows an attacker to inject payload using 'sql' parameter in SQL query while generating…
- CVE-2021-454081 PoCOpen Redirect vulnerability exists in SeedDMS 6.0.15 in out.Login.php, which llows remote malicious users to redirect users to malicious…
- CVE-2021-454111 PoCIn Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and…
- CVE-2021-454141 PoCA Remote Code Execution (RCE) vulnerability exists in DataRobot through 2021-10-28 because it allows submission of a Docker environment or…
- CVE-2021-454162 PoCsReflected Cross-site scripting (XSS) vulnerability in RosarioSIS 8.2.1 allows attackers to inject arbitrary HTML via the search_term…
- CVE-2021-454173 PoCsAIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs),…
- CVE-2021-454181 PoCCertain Starcharge products are vulnerable to Directory Traversal via main.cgi. The affected products include: Nova 360 Cabinet…
- CVE-2021-454201 PoCEmerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi,…
- CVE-2021-454223 PoCsReprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_process "count"…
- CVE-2021-454231 PoCA Buffer Overflow vulnerabilityexists in Pev 0.81 via the pe_exports function from exports.c.. The array offsets_to_Names is dynamically…
- CVE-2021-454252 PoCsReflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScript codes.
- CVE-2021-454271 PoCEmerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. An attacker can browse…
- CVE-2021-454284 PoCsTLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files…
- CVE-2021-454291 PoCA Buffer Overflow vulnerablity exists in VirusTotal YARA git commit: 605b2edf07ed8eb9a2c61ba22eb2e7c362f47ba7 via yr_set_configuration in…
- CVE-2021-454591 PoClib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter.
- CVE-2021-454611 PoCFreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to…
- CVE-2021-454641 PoCkvmtool through 39181fc allows an out-of-bounds write, related to virtio/balloon.c and virtio/pci.c. This allows a guest OS user to…
- CVE-2021-454661 PoCIn CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to…
- CVE-2021-454672 PoCsIn CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause…
- CVE-2021-454681 PoCImperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade…
- CVE-2021-454691 PoCIn __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an…
- CVE-2021-454851 PoCIn the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a…
- CVE-2021-455111 PoCCertain NETGEAR devices are affected by authentication bypass. This affects AC2100 before 2021-08-27, AC2400 before 2021-08-27, AC2600…
- CVE-2021-456081 PoCCertain D-Link, Edimax, NETGEAR, TP-Link, Tenda, and Western Digital devices are affected by an integer overflow by an unauthenticated…
- CVE-2021-457444 PoCsA Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.
- CVE-2021-457454 PoCsA Stored Cross Site Scripting (XSS) vulnerability exists in Bludit 3.13.1 via the About Plugin in login panel.
- CVE-2021-457601 PoCGPAC v1.1.0 was discovered to contain an invalid memory address dereference via the function gf_list_last(). This vulnerability allows…
- CVE-2021-457611 PoCROPium v3.1 was discovered to contain an invalid memory address dereference via the find() function.
- CVE-2021-457621 PoCGPAC v1.1.0 was discovered to contain an invalid memory address dereference via the function gf_sg_vrml_mf_reset(). This vulnerability…
- CVE-2021-457631 PoCGPAC v1.1.0 was discovered to contain an invalid call in the function gf_node_changed(). This vulnerability can lead to a Denial of…
- CVE-2021-457641 PoCGPAC v1.1.0 was discovered to contain an invalid memory address dereference via the function shift_chunk_offsets.isra().
- CVE-2021-457671 PoCGPAC 1.1.0 was discovered to contain an invalid memory address dereference via the function lsr_read_id(). This vulnerability can lead to…
- CVE-2021-457691 PoCA NULL pointer dereference in AcseConnection_parseMessage at src/mms/iso_acse/acse.c of libiec61850 v1.5.0 can lead to a segmentation…
- CVE-2021-457832 PoCsBookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to obtain sensitive…
- CVE-2021-457851 PoCTruDesk Help Desk/Ticketing Solution v1.1.11 is vulnerable to a Cross-Site Request Forgery (CSRF) attack which would allow an attacker to…
- CVE-2021-457861 PoCIn maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.
- CVE-2021-457881 PoCTime-based SQL Injection vulnerabilities were found in Metersphere v1.15.4 via the "orders" parameter.
- CVE-2021-457931 PoCSlims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained.
- CVE-2021-458021 PoCMartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter values are added…
- CVE-2021-458031 PoCMartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is added to the SQL…
- CVE-2021-458112 PoCsA SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to…
- CVE-2021-458121 PoCNUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can steal the user's…
- CVE-2021-458143 PoCsNettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel with an…
- CVE-2021-458181 PoCSAFARI Montage 8.7.32 is affected by a CRLF injection vulnerability which can lead to HTTP response splitting.
- CVE-2021-458212 PoCsA blind SQL injection vulnerability exists in Xbtit 3.1 via the sid parameter in ajaxchat/getHistoryChatData.php file that is accessible…
- CVE-2021-458222 PoCsA cross-site scripting vulnerability is present in Xbtit 3.1. The stored XSS vulnerability occurs because /ajaxchat/sendChatData.php does…
- CVE-2021-458291 PoCHDF5 1.13.1-1 is affected by: segmentation fault, which causes a Denial of Service.
- CVE-2021-458301 PoCA heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which could cause a…
- CVE-2021-458321 PoCA Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 at at hdf5/src/H5Eint.c, which causes a Denial of Service…
- CVE-2021-458331 PoCA Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 via the H5D__create_chunk_file_map_hyper function in…
- CVE-2021-458351 PoCThe Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of dangerous types to the application…
- CVE-2021-458371 PoCIt is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending a specifically…
- CVE-2021-458391 PoCIt is possible to obtain the first administrator's hash set up on the system in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517)…
- CVE-2021-458411 PoCIn Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address…
- CVE-2021-458431 PoCglFusion CMS v1.7.9 is affected by a reflected Cross Site Scripting (XSS) vulnerability. The value of the title request parameter is…
- CVE-2021-458442 PoCsImproper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted…
- CVE-2021-458461 PoCA flaw in the AMF parser of Slic3r libslic3r 1.3.0 allows an attacker to cause an application crash using a crafted AMF document, where a…
- CVE-2021-458511 PoCA Server-Side Request Forgery (SSRF) attack in FUXA 1.1.3 can be carried out leading to the obtaining of sensitive information from the…
- CVE-2021-458561 PoCAccu-Time Systems MAXIMUS 1.0 telnet service suffers from a remote buffer overflow which causes the telnet service to crash
- CVE-2021-458601 PoCAn integer overflow in DTSStreamReader::findFrame() of tsMuxer git-2678966 allows attackers to cause a Denial of Service (DoS) via a…
- CVE-2021-458611 PoCThere is an Assertion `num <= INT_BIT' failed at BitStreamReader::skipBits in /bitStream.h:132 of tsMuxer git-c6a0277.
- CVE-2021-458631 PoCtsMuxer git-2678966 was discovered to contain a heap-based buffer overflow via the function HevcUnit::updateBits in hevc.cpp.
- CVE-2021-458641 PoCtsMuxer git-c6a0277 was discovered to contain a segmentation fault via DTSStreamReader::findFrame in dtsStreamReader.cpp.
- CVE-2021-458682 PoCsIn the Linux kernel before 5.15.3, fs/quota/quota_tree.c does not validate the block number in the quota tree (on disk). This can, for…
- CVE-2021-458861 PoCAn issue was discovered in PONTON X/P Messenger before 3.11.2. Anti-CSRF tokens are globally valid, making the web application vulnerable…
- CVE-2021-458871 PoCAn issue was discovered in PONTON X/P Messenger before 3.11.2. Due to path traversal in private/SchemaSetUpload.do for uploaded ZIP files,…
- CVE-2021-458881 PoCAn issue was discovered in PONTON X/P Messenger before 3.11.2. The navigation tree that is shown on the left side of every page of the web…
- CVE-2021-458891 PoCAn issue was discovered in PONTON X/P Messenger before 3.11.2. Several functions are vulnerable to reflected XSS, as demonstrated by…
- CVE-2021-458911 PoCAn issue was discovered in Softwarebuero Zauner ARC 4.2.0.4., that allows attackers to escalate privileges within the application, since…
- CVE-2021-458931 PoCAn issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is Improper Handling of Case Sensitivity, which makes password guessing…
- CVE-2021-458941 PoCAn issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is Cleartext Transmission of Sensitive Information.
- CVE-2021-458971 PoCSuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.
- CVE-2021-459013 PoCsThe password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the…
- CVE-2021-459041 PoCOpenWrt 21.02.1 allows XSS via the Port Forwards Add Name screen.
- CVE-2021-459051 PoCOpenWrt 21.02.1 allows XSS via the Traffic Rules Name screen.
- CVE-2021-459061 PoCOpenWrt 21.02.1 allows XSS via the NAT Rules Name screen.
- CVE-2021-459071 PoCAn issue was discovered in gif2apng 1.9. There is a stack-based buffer overflow involving a for loop. An attacker has little influence…
- CVE-2021-459081 PoCAn issue was discovered in gif2apng 1.9. There is a stack-based buffer overflow involving a while loop. An attacker has little influence…
- CVE-2021-459091 PoCAn issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow vulnerability in the DecodeLZW function. It allows an…
- CVE-2021-459101 PoCAn issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow within the main function. It allows an attacker to write…
- CVE-2021-459111 PoCAn issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow in the main function. It allows an attacker to write 2…
- CVE-2021-459191 PoCStudio 42 elFinder through 2.1.31 allows XSS via an SVG document.
- CVE-2021-459602 PoCsIn Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc…
- CVE-2021-459661 PoCAn issue was discovered in Pascom Cloud Phone System before 7.20.x. In the management REST API, /services/apply in exd.pl allows remote…
- CVE-2021-459672 PoCsAn issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads…
- CVE-2021-459682 PoCsAn issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Phone System before…
- CVE-2021-459721 PoCThe giftrans function in giftrans 1.12.2 contains a stack-based buffer overflow because a value inside the input file determines the…