CVE-2021-46000 to CVE-2021-46999
231 CVEs with public proof-of-concept exploits.
- CVE-2021-460053 PoCsSourcecodester Car Rental Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via vehicalorcview parameter.
- CVE-2021-460061 PoCIn Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function, an attacker can…
- CVE-2021-460071 PoCtotolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input…
- CVE-2021-460081 PoCIn totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has…
- CVE-2021-460091 PoCIn Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations…
- CVE-2021-460101 PoCTotolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An…
- CVE-2021-460131 PoCAn unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can leverage this…
- CVE-2021-460191 PoCAn untrusted pointer dereference in rec_db_destroy() at rec-db.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application…
- CVE-2021-460201 PoCAn untrusted pointer dereference in mrb_vm_exec() of mruby v3.0.0 can lead to a segmentation fault or application crash.
- CVE-2021-460211 PoCAn Use-After-Free vulnerability in rec_record_destroy() at rec-record.c of GNU Recutils v1.8.90 can lead to a segmentation fault or…
- CVE-2021-460221 PoCAn Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or…
- CVE-2021-460231 PoCAn Untrusted Pointer Dereference was discovered in function mrb_vm_exec in mruby before 3.1.0-rc. The vulnerability causes a segmentation…
- CVE-2021-460271 PoCmysiteforme, as of 19-12-2022, has a CSRF vulnerability in the background blog management. The attacker constructs a CSRF load. Once the…
- CVE-2021-460281 PoCIn mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once the…
- CVE-2021-460391 PoCA Pointer Dereference Vulnerabilty exists in GPAC 1.0.1 via the shift_chunk_offsets.part function, which causes a Denial of Service…
- CVE-2021-460611 PoCAn SQL Injection vulnerability exists in Sourcecodester Computer and Mobile Repair Shop Management system (RSMS) 1.0 via the code…
- CVE-2021-460621 PoCMCMS v5.2.5 was discovered to contain an arbitrary file deletion vulnerability via the component oldFileName.
- CVE-2021-460631 PoCMCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module.
- CVE-2021-460674 PoCsIn Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.
- CVE-2021-460685 PoCsA Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the My Account Section in login panel.
- CVE-2021-460692 PoCsA Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Mechanic List Section in login…
- CVE-2021-460704 PoCsA Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service Requests Section in…
- CVE-2021-460712 PoCsA Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Category List Section in login…
- CVE-2021-460722 PoCsA Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List Section in login…
- CVE-2021-460732 PoCsA Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the User List Section…
- CVE-2021-460744 PoCsA Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Settings Section…
- CVE-2021-460751 PoCA Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users can access the…
- CVE-2021-460764 PoCsSourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in multiple…
- CVE-2021-460784 PoCsAn Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can upload…
- CVE-2021-460794 PoCsAn Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can upload…
- CVE-2021-460804 PoCsA Cross Site Request Forgery (CSRF) vulnerability exists in Vehicle Service Management System 1.0. An successful CSRF attacks leads to…
- CVE-2021-460881 PoCZabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run…
- CVE-2021-460891 PoCIn JeecgBoot 3.0, there is a SQL injection vulnerability that can operate the database with root privileges.
- CVE-2021-460971 PoCDolphinphp v1.5.0 contains a remote code execution vulnerability in /application/common.php#action_log
- CVE-2021-461011 PoCIn Git for windows through 2.34.1 when using git pull to update the local warehouse, git.cmd can be run directly.
- CVE-2021-461022 PoCsFrom version 0.2.14 to 0.2.16 for Solana rBPF, function "relocate" in the file src/elf.rs has an integer overflow bug because the…
- CVE-2021-461041 PoCAn issue was discovered in webp_server_go 0.4.0. There is a directory traversal vulnerability that can read arbitrary file information on…
- CVE-2021-461071 PoCLigeo Archives Ligeo Basics as of 02_01-2022 is vulnerable to Server Side Request Forgery (SSRF) which allows an attacker to read any…
- CVE-2021-461081 PoCD-Link DSL-2730E CT-20131125 devices allow XSS via the username parameter to the password page in the maintenance configuration.
- CVE-2021-461091 PoCInvalid input sanitizing leads to reflected Cross Site Scripting (XSS) in ASUS RT-AC52U_B1 3.0.0.4.380.10931 can lead to a user session…
- CVE-2021-461132 PoCsIn MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP…
- CVE-2021-461221 PoCTp-Link TL-WR840N (EU) v6.20 Firmware (0.9.1 4.17 v0001.0 Build 201124 Rel.64328n) is vulnerable to Buffer Overflow via the Password reset…
- CVE-2021-461432 PoCsIn doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.
- CVE-2021-461681 PoCSpin v6.5.1 was discovered to contain an out-of-bounds write in lex() at spinlex.c.
- CVE-2021-461691 PoCModex v2.11 was discovered to contain an Use-After-Free vulnerability via the component tcache.
- CVE-2021-461701 PoCAn issue was discovered in JerryScript commit a6ab5e9. There is an Use-After-Free in lexer_compare_identifier_to_string in js-lexer.c file.
- CVE-2021-461711 PoCModex v2.11 was discovered to contain a NULL pointer dereference in set_create_id() at xtract.c.
- CVE-2021-461951 PoCGCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows…
- CVE-2021-461981 PoCAn SQL Injection vulnerability exists in Sourceodester Courier Management System 1.0 via the email parameter in /cms/ajax.php app.
- CVE-2021-462001 PoCAn SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php.
- CVE-2021-462011 PoCAn SQL Injection vulnerability exists in Sourcecodester Online Resort Management System 1.0 via the id parameterv in /orms/ node.
- CVE-2021-462031 PoCTaocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter.
- CVE-2021-462041 PoCTaocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter. SQL injection vulnerability via…
- CVE-2021-462401 PoCA NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_dump_vrml_sffield () at scene_manager/scene_dump.c.…
- CVE-2021-462421 PoCHDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry.
- CVE-2021-462431 PoCAn untrusted pointer dereference vulnerability exists in HDF5 v1.13.1-1 via the function H5O__dtype_decode_helper () at…
- CVE-2021-462441 PoCA Divide By Zero vulnerability exists in HDF5 v1.13.1-1 vis the function H5T__complete_copy () at /hdf5/src/H5T.c. This vulnerability…
- CVE-2021-462471 PoCThe use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from ASUS CMAX6000…
- CVE-2021-462551 PoCeyouCMS V1.5.5-UTF8-SP3_1 suffers from Arbitrary file deletion due to insufficient filtering of the parameter filename.
- CVE-2021-462621 PoCTenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the PPPoE module. This vulnerability…
- CVE-2021-462631 PoCTenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the wifiTime module. This vulnerability…
- CVE-2021-462641 PoCTenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the onlineList module. This…
- CVE-2021-462651 PoCTenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the wanBasicCfg module. This…
- CVE-2021-463071 PoCAn SQL Injection vulnerability exists in Projectworlds Online Examination System 1.0 via the eid parameter in account.php.
- CVE-2021-463081 PoCAn SQL Injection vulnerability exists in Sourcecodester Online Railway Reservation Sysytem 1.0 via the sid parameter.
- CVE-2021-463091 PoCAn SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter.
- CVE-2021-463101 PoCAn issue was discovered IW44Image.cpp in djvulibre 3.5.28 in allows attackers to cause a denial of service via divide by zero.
- CVE-2021-463121 PoCAn issue was discovered IW44EncodeCodec.cpp in djvulibre 3.5.28 in allows attackers to cause a denial of service via divide by zero.
- CVE-2021-463141 PoCA Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetNetworkTomographySettings.php of D-Link Router DIR-846…
- CVE-2021-463151 PoCRemote Command Execution (RCE) vulnerability exists in HNAP1/control/SetWizardConfig.php in D-Link Router DIR-846 DIR846A1_FW100A43.bin…
- CVE-2021-463191 PoCRemote Code Execution (RCE) vulnerability exists in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin.…
- CVE-2021-463211 PoCTenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the wifiBasicCfg module. This…
- CVE-2021-463221 PoCDuktape v2.99.99 was discovered to contain a SEGV vulnerability via the component duk_push_tval in duktape/duk_api_stack.c.
- CVE-2021-463231 PoCEspruino 2v11.251 was discovered to contain a SEGV vulnerability via src/jsinteractive.c in jsiGetDeviceFromClass.
- CVE-2021-463241 PoCEspruino 2v11.251 was discovered to contain a stack buffer overflow via src/jsvar.c in jsvNewFromString.
- CVE-2021-463251 PoCEspruino 2v10.246 was discovered to contain a stack buffer overflow via src/jsutils.c in vcbprintf.
- CVE-2021-463261 PoCModdable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via the component __asan_memcpy.
- CVE-2021-463271 PoCModdable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsArray.c in fx_Array_prototype_sort.
- CVE-2021-463291 PoCModdable SDK v11.5.0 was discovered to contain a SEGV vulnerability via the component _fini.
- CVE-2021-463301 PoCModdable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsDataView.c in fx_ArrayBuffer_prototype_concat.
- CVE-2021-463311 PoCModdable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsProxy.c in fxProxyGetPrototype.
- CVE-2021-463321 PoCModdable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via xs/sources/xsDataView.c in fxUint8Getter.
- CVE-2021-463331 PoCModdable SDK v11.5.0 was discovered to contain an invalid memory access vulnerability via the component __asan_memmove.
- CVE-2021-463341 PoCModdable SDK v11.5.0 was discovered to contain a stack buffer overflow via the component __interceptor_strcat.
- CVE-2021-463351 PoCModdable SDK v11.5.0 was discovered to contain a NULL pointer dereference in the component fx_Function_prototype_hasInstance.
- CVE-2021-463361 PoCThere is an Assertion 'opts & PARSER_CLASS_LITERAL_CTOR_PRESENT' failed at /parser/js/js-parser-expr.c(parser_parse_class_body) in…
- CVE-2021-463371 PoCThere is an Assertion 'page_p != NULL' failed at /parser/js/js-parser-mem.c(parser_list_get) in JerryScript 3.0.0.
- CVE-2021-463381 PoCThere is an Assertion 'ecma_is_lexical_environment (object_p)' failed at /base/ecma-helpers.c(ecma_get_lex_env_type) in JerryScript 3.0.0.
- CVE-2021-463391 PoCThere is an Assertion 'lit_is_valid_cesu8_string (string_p, string_size)' failed at…
- CVE-2021-463401 PoCThere is an Assertion 'context_p->stack_top_uint8 == SCAN_STACK_TRY_STATEMENT || context_p->stack_top_uint8 == SCAN_STACK_CATCH_STATEMENT'…
- CVE-2021-463421 PoCThere is an Assertion 'ecma_is_lexical_environment (obj_p) || !ecma_op_object_is_fast_array (obj_p)' failed at…
- CVE-2021-463431 PoCThere is an Assertion 'context_p->token.type == LEXER_LITERAL' failed at /jerry-core/parser/js/js-parser-expr.c in JerryScript 3.0.0.
- CVE-2021-463441 PoCThere is an Assertion 'flags & PARSER_PATTERN_HAS_REST_ELEMENT' failed at /jerry-core/parser/js/js-parser-expr.c in JerryScript 3.0.0.
- CVE-2021-463451 PoCThere is an Assertion 'cesu8_cursor_p == cesu8_end_p' failed at /jerry-core/lit/lit-strings.c in JerryScript 3.0.0.
- CVE-2021-463461 PoCThere is an Assertion 'local_tza == ecma_date_local_time_zone_adjustment (date_value)' failed at…
- CVE-2021-463471 PoCThere is an Assertion 'ecma_object_check_class_name_is_object (obj_p)' failed at /jerry-core/ecma/operations/ecma-objects.c in JerryScript…
- CVE-2021-463481 PoCThere is an Assertion 'ECMA_STRING_IS_REF_EQUALS_TO_ONE (string_p)' failed at /jerry-core/ecma/base/ecma-literal-storage.c in JerryScript…
- CVE-2021-463491 PoCThere is an Assertion 'type == ECMA_OBJECT_TYPE_GENERAL || type == ECMA_OBJECT_TYPE_PROXY' failed at…
- CVE-2021-463501 PoCThere is an Assertion 'ecma_is_value_object (value)' failed at jerryscript/jerry-core/ecma/base/ecma-helpers-value.c in JerryScript 3.0.0.
- CVE-2021-463511 PoCThere is an Assertion 'local_tza == ecma_date_local_time_zone_adjustment (date_value)' failed at…
- CVE-2021-463541 PoCThinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the…
- CVE-2021-463602 PoCsAuthenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrary code via…
- CVE-2021-463612 PoCsAn issue in the Freemark Filter of Magnolia CMS v6.2.11 and below allows attackers to bypass security restrictions and execute arbitrary…
- CVE-2021-463622 PoCsA Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows…
- CVE-2021-463632 PoCsAn issue in the Export function of Magnolia v6.2.3 and below allows attackers to perform Formula Injection attacks via crafted CSV/XLS…
- CVE-2021-463642 PoCsA vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via a crafted YAML…
- CVE-2021-463652 PoCsAn issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via a crafted XLF file.
- CVE-2021-463662 PoCsAn issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site…
- CVE-2021-463672 PoCsRiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated attacker can…
- CVE-2021-463682 PoCsTRIGONE Remote System Monitor 3.61 is vulnerable to an unquoted path service allowing local users to launch processes with elevated…
- CVE-2021-463712 PoCsantd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the foreground leads…
- CVE-2021-463721 PoCScoold 1.47.2 is a Q&A/knowledge base platform written in Java. When writing a Q&A, the markdown editor is vulnerable to a XSS attack when…
- CVE-2021-463783 PoCsDLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration…
- CVE-2021-463794 PoCsDLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.
- CVE-2021-463815 PoCsLocal File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow].
- CVE-2021-463821 PoCUnauthenticated cross-site scripting (XSS) in Netgear WAC120 AC Access Point may lead to mulitple attacks like session hijacking even…
- CVE-2021-463874 PoCsZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads to bypass security…
- CVE-2021-463931 PoCThere is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v10 variable is…
- CVE-2021-463941 PoCThere is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v13 variable is…
- CVE-2021-463988 PoCsA Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin…
- CVE-2021-464081 PoCTenda AX12 v22.03.01.21 was discovered to contain a stack buffer overflow in the function sub_422CE4. This vulnerability allows attackers…
- CVE-2021-464163 PoCsInsecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to…
- CVE-2021-464177 PoCsInsecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin…
- CVE-2021-464184 PoCsAn unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.
- CVE-2021-464194 PoCsAn unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system files and scripts.
- CVE-2021-464211 PoCFranklin Fueling Systems FFS T5 Series 1.8.7.7299 is affected by an unauthenticated directory traversal vulnerability, which allows an…
- CVE-2021-4642218 PoCsTelesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands…
- CVE-2021-464231 PoCTelesquare TLR-2005KSH 1.0.0 is affected by an unauthenticated file download vulnerability that allows a remote attacker to download a…
- CVE-2021-464243 PoCsTelesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file,…
- CVE-2021-464261 PoCphpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functionality.
- CVE-2021-464272 PoCsAn SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php.
- CVE-2021-464282 PoCsA Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the…
- CVE-2021-464361 PoCAn issue was discovered in ZZCMS 2021. There is a SQL injection vulnerability in ad_manage.php.
- CVE-2021-464371 PoCAn issue was discovered in ZZCMS 2021. There is a cross-site scripting (XSS) vulnerability in ad_manage.php.
- CVE-2021-464401 PoCStoring passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an…
- CVE-2021-464411 PoCIn the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute…
- CVE-2021-464421 PoCIn the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", and perform…
- CVE-2021-464511 PoCAn SQL Injection vulnerabilty exists in Sourcecodester Online Project Time Management System 1.0 via the pid parameter in the load_file…
- CVE-2021-464611 PoCnjs through 0.7.0, used in NGINX, was discovered to contain an out-of-bounds array access via njs_vmcode_typeof in /src/njs_vmcode.c.
- CVE-2021-464621 PoCnjs through 0.7.1, used in NGINX, was discovered to contain a segmentation violation via njs_object_set_prototype in /src/njs_object.c.
- CVE-2021-464631 PoCnjs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerability in…
- CVE-2021-464741 PoCJsish v3.5.0 was discovered to contain a heap buffer overflow via jsiEvalCodeSub in src/jsiEval.c. This vulnerability can lead to a Denial…
- CVE-2021-464751 PoCJsish v3.5.0 was discovered to contain a heap buffer overflow via jsi_ArraySliceCmd in src/jsiArray.c. This vulnerability can lead to a…
- CVE-2021-464771 PoCJsish v3.5.0 was discovered to contain a heap buffer overflow via RegExp_constructor in src/jsiRegexp.c. This vulnerability can lead to a…
- CVE-2021-464781 PoCJsish v3.5.0 was discovered to contain a heap buffer overflow via jsiClearStack in src/jsiEval.c. This vulnerability can lead to a Denial…
- CVE-2021-464801 PoCJsish v3.5.0 was discovered to contain a heap buffer overflow via jsiValueObjDelete in src/jsiEval.c. This vulnerability can lead to a…
- CVE-2021-464811 PoCJsish v3.5.0 was discovered to contain a memory leak via linenoise at src/linenoise.c.
- CVE-2021-464821 PoCJsish v3.5.0 was discovered to contain a heap buffer overflow via NumberConstructor at src/jsiNumber.c.
- CVE-2021-464831 PoCJsish v3.5.0 was discovered to contain a heap buffer overflow via BooleanConstructor at src/jsiBool.c.
- CVE-2021-464841 PoCJsish v3.5.0 was discovered to contain a heap-use-after-free via Jsi_IncrRefCount in src/jsiValue.c. This vulnerability can lead to a…
- CVE-2021-464851 PoCJsish v3.5.0 was discovered to contain a SEGV vulnerability via Jsi_ValueIsNumber at src/jsiValue.c. This vulnerability can lead to a…
- CVE-2021-464861 PoCJsish v3.5.0 was discovered to contain a SEGV vulnerability via jsi_ArraySpliceCmd at src/jsiArray.c. This vulnerability can lead to a…
- CVE-2021-464871 PoCJsish v3.5.0 was discovered to contain a SEGV vulnerability via /lib/x86_64-linux-gnu/libc.so.6+0x18e506. This vulnerability can lead to a…
- CVE-2021-464881 PoCJsish v3.5.0 was discovered to contain a SEGV vulnerability via jsi_ArrayConcatCmd at src/jsiArray.c. This vulnerability can lead to a…
- CVE-2021-464891 PoCJsish v3.5.0 was discovered to contain a heap-use-after-free via Jsi_DecrRefCount in src/jsiValue.c. This vulnerability can lead to a…
- CVE-2021-464901 PoCJsish v3.5.0 was discovered to contain a SEGV vulnerability via NumberConstructor at src/jsiNumber.c. This vulnerability can lead to a…
- CVE-2021-464911 PoCJsish v3.5.0 was discovered to contain a SEGV vulnerability via Jsi_CommandPkgOpts at src/jsiCmds.c. This vulnerability can lead to a…
- CVE-2021-464941 PoCJsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_ValueLookupBase in src/jsiValue.c. This vulnerability can lead to a…
- CVE-2021-464951 PoCJsish v3.5.0 was discovered to contain a heap-use-after-free via DeleteTreeValue in src/jsiObj.c. This vulnerability can lead to a Denial…
- CVE-2021-464961 PoCJsish v3.5.0 was discovered to contain a heap-use-after-free via Jsi_ObjFree in src/jsiObj.c. This vulnerability can lead to a Denial of…
- CVE-2021-464971 PoCJsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_UserObjDelete in src/jsiUserObj.c. This vulnerability can lead to a…
- CVE-2021-464981 PoCJsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_wswebsocketObjFree in src/jsiWebSocket.c. This vulnerability can lead…
- CVE-2021-464991 PoCJsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_ValueCopyMove in src/jsiValue.c. This vulnerability can lead to a…
- CVE-2021-465001 PoCJsish v3.5.0 was discovered to contain a heap-use-after-free via jsi_ArgTypeCheck in src/jsiFunc.c. This vulnerability can lead to a…
- CVE-2021-465011 PoCJsish v3.5.0 was discovered to contain a heap-use-after-free via SortSubCmd in src/jsiArray.c. This vulnerability can lead to a Denial of…
- CVE-2021-465021 PoCJsish v3.5.0 was discovered to contain a heap-use-after-free via /usr/lib/x86_64-linux-gnu/libasan.so.4+0x5166d. This vulnerability can…
- CVE-2021-465031 PoCJsish v3.5.0 was discovered to contain a heap-use-after-free via /usr/lib/x86_64-linux-gnu/libasan.so.4+0x79732. This vulnerability can…
- CVE-2021-465041 PoCThere is an Assertion 'vp != resPtr' failed at jsiEval.c in Jsish v3.5.0.
- CVE-2021-465051 PoCJsish v3.5.0 was discovered to contain a stack overflow via /usr/lib/x86_64-linux-gnu/libasan.so.4+0x5b1e5.
- CVE-2021-465061 PoCThere is an Assertion 'v->d.lval != v' failed at src/jsiValue.c in Jsish v3.5.0.
- CVE-2021-465071 PoCJsish v3.5.0 was discovered to contain a stack overflow via Jsi_LogMsg at src/jsiUtils.c.
- CVE-2021-465081 PoCThere is an Assertion `i < parts_cnt' failed at src/mjs_bcode.c in Cesanta MJS v2.20.0.
- CVE-2021-465091 PoCCesanta MJS v2.20.0 was discovered to contain a stack overflow via snquote at mjs/src/mjs_json.c.
- CVE-2021-465101 PoCThere is an Assertion `s < mjs->owned_strings.buf + mjs->owned_strings.len' failed at src/mjs_gc.c in Cesanta MJS v2.20.0.
- CVE-2021-465111 PoCThere is an Assertion `m->len >= sizeof(v)' failed at src/mjs_core.c in Cesanta MJS v2.20.0.
- CVE-2021-465121 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_apply at src/mjs_exec.c. This vulnerability can lead to a…
- CVE-2021-465131 PoCCesanta MJS v2.20.0 was discovered to contain a global buffer overflow via mjs_mk_string at mjs/src/mjs_string.c.
- CVE-2021-465141 PoCThere is an Assertion 'ppos != NULL && mjs_is_number(*ppos)' failed at src/mjs_core.c in Cesanta MJS v2.20.0.
- CVE-2021-465151 PoCThere is an Assertion `mjs_stack_size(&mjs->scopes) >= scopes_len' failed at src/mjs_exec.c in Cesanta MJS v2.20.0.
- CVE-2021-465161 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_stack_size at mjs/src/mjs_core.c. This vulnerability can lead…
- CVE-2021-465171 PoCThere is an Assertion `mjs_stack_size(&mjs->scopes) > 0' failed at src/mjs_exec.c in Cesanta MJS v2.20.0.
- CVE-2021-465181 PoCCesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via mjs_disown at src/mjs_core.c.
- CVE-2021-465191 PoCCesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via mjs_array_length at src/mjs_array.c.
- CVE-2021-465201 PoCCesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via mjs_jprintf at src/mjs_util.c.
- CVE-2021-465211 PoCCesanta MJS v2.20.0 was discovered to contain a global buffer overflow via c_vsnprintf at mjs/src/common/str_util.c.
- CVE-2021-465221 PoCCesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via /usr/lib/x86_64-linux-gnu/libasan.so.4+0xaff53.
- CVE-2021-465231 PoCCesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via to_json_or_debug at mjs/src/mjs_json.c.
- CVE-2021-465241 PoCCesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via snquote at mjs/src/mjs_json.c.
- CVE-2021-465251 PoCCesanta MJS v2.20.0 was discovered to contain a heap-use-after-free via mjs_apply at src/mjs_exec.c.
- CVE-2021-465261 PoCCesanta MJS v2.20.0 was discovered to contain a global buffer overflow via snquote at src/mjs_json.c.
- CVE-2021-465271 PoCCesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via mjs_get_cstring at src/mjs_string.c.
- CVE-2021-465281 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x5361e. This vulnerability can lead to a Denial…
- CVE-2021-465291 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x8814e. This vulnerability can lead to a Denial…
- CVE-2021-465301 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_execute at src/mjs_exec.c. This vulnerability can lead to a…
- CVE-2021-465311 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x8d28e. This vulnerability can lead to a Denial…
- CVE-2021-465321 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via exec_expr at src/mjs_exec.c. This vulnerability can lead to a…
- CVE-2021-465341 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via getprop_builtin_foreign at src/mjs_exec.c. This vulnerability can…
- CVE-2021-465351 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0xe533e. This vulnerability can lead to a Denial…
- CVE-2021-465371 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x9a30e. This vulnerability can lead to a Denial…
- CVE-2021-465381 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via gc_compact_strings at src/mjs_gc.c. This vulnerability can lead to…
- CVE-2021-465391 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /lib/x86_64-linux-gnu/libc.so.6+0x45a1f. This vulnerability can…
- CVE-2021-465401 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_get_mjs at src/mjs_builtin.c. This vulnerability can lead to a…
- CVE-2021-465411 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x2c6ae. This vulnerability can lead to a Denial…
- CVE-2021-465421 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_print at src/mjs_builtin.c. This vulnerability can lead to a…
- CVE-2021-465431 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /lib/x86_64-linux-gnu/libc.so.6+0x18e810. This vulnerability can…
- CVE-2021-465441 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/lib/x86_64-linux-gnu/libasan.so.4+0x59e19. This vulnerability…
- CVE-2021-465451 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /lib/x86_64-linux-gnu/libc.so.6+0x4b44b. This vulnerability can…
- CVE-2021-465461 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_next at src/mjs_object.c. This vulnerability can lead to a…
- CVE-2021-465471 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via /usr/local/bin/mjs+0x2c17e. This vulnerability can lead to a Denial…
- CVE-2021-465481 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via add_lineno_map_item at src/mjs_bcode.c. This vulnerability can lead…
- CVE-2021-465491 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via parse_cval_type at src/mjs_ffi.c. This vulnerability can lead to a…
- CVE-2021-465501 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via free_json_frame at src/mjs_json.c. This vulnerability can lead to a…
- CVE-2021-465531 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_set_internal at src/mjs_object.c. This vulnerability can lead…
- CVE-2021-465541 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_json_stringify at src/mjs_json.c. This vulnerability can lead…
- CVE-2021-465561 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_bcode_insert_offset at src/mjs_bcode.c. This vulnerability can…
- CVE-2021-465581 PoCMultiple cross-site scripting (XSS) vulnerabilities in the Add User module of Issabel PBX 20200102 allows attackers to execute arbitrary…
- CVE-2021-467001 PoCIn libsixel 1.8.6, sixel_encoder_output_without_macro (called from sixel_encoder_encode_frame in encoder.c) has a double free.
- CVE-2021-467022 PoCsTor Browser 9.0.7 on Windows 10 build 10586 is vulnerable to information disclosure. This could allow local attackers to bypass the…
- CVE-2021-467031 PoCIn the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .NET code in a…
- CVE-2021-467043 PoCsIn GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument…
- CVE-2021-467431 PoCIn Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) header, when multiple…
- CVE-2021-467801 PoCEasy Google Maps < 1.9.32 - Reflected Cross-Site Scripting
- CVE-2021-467811 PoCComing Soon by Supsystic < 1.7.6 - Reflected Cross-Site Scripting
- CVE-2021-467821 PoCPricing Table by Supsystic < 1.9.5 - Reflected Cross-Site Scripting
- CVE-2021-468201 PoCArbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to…
- CVE-2021-468241 PoCCross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Lastname parameter to the Update…
- CVE-2021-468292 PoCsGNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as…
- CVE-2021-468501 PoCmyVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and…
- CVE-2021-468881 PoCAn issue was discovered in hledger before 1.23. A Stored Cross-Site Scripting (XSS) vulnerability exists in toBloodhoundJson that allows…
- CVE-2021-468891 PoCThe 10Web Photo Gallery plugin through 1.5.69 for WordPress allows XSS via theme_id for bwg_frontend_data. NOTE: other parameters are…
- CVE-2021-468981 PoCviews/switch.py in django-grappelli (aka Django Grappelli) before 2.15.2 attempts to prevent external redirection with startswith("/") but…