CVE-2021-47000 to CVE-2021-47999
277 CVEs with public proof-of-concept exploits.
- CVE-2021-477011 PoCOpenBMCS User Management Privilege Escalation
- CVE-2021-477021 PoCOpenBMCS Cross Site Request Forgery (CSRF) via sendFeedback.php
- CVE-2021-477031 PoCOpenBMCS Server Side Request Forgery (SSRF) via /php/query.php
- CVE-2021-477041 PoCOpenBMCS SQL Injection via obix_test.php
- CVE-2021-477051 PoCCNC_Ctrl DllUnregisterServer Access Violation
- CVE-2021-477061 PoCCOMMAX Biometric Access Control System Authentication Bypass
- CVE-2021-477071 PoCCOMMAX CVD-Axx DVR Weak Default Credentials Stream Disclosure
- CVE-2021-477081 PoCCOMMAX Smart Home IoT Control System SQL Injection Authentication Bypass
- CVE-2021-477091 PoCCOMMAX Smart Home Ruvie CCTV Bridge DVR Service Config Write / DoS
- CVE-2021-477101 PoCCOMMAX Smart Home Ruvie CCTV Bridge DVR Service RTSP Credentials Disclosure
- CVE-2021-477131 PoCHasura GraphQL 1.3.3 Denial of Service via Malicious GraphQL Query
- CVE-2021-477141 PoCHasura GraphQL 1.3.3 Local File Read via SQL Injection
- CVE-2021-477151 PoCHasura GraphQL 1.3.3 Server-Side Request Forgery via Remote Schema Injection
- CVE-2021-477161 PoCOrangescrum 1.8.0 Cross-Site Scripting via Authenticated Endpoints
- CVE-2021-477171 PoCIntelliChoice eFORCE Software Suite Username Enumeration
- CVE-2021-477181 PoCOpenBMCS Directory Listing Information Disclosure
- CVE-2021-477191 PoCCNC_Ctrl DllUnregisterServer f5501 Access Violation
- CVE-2021-477201 PoCOrangescrum 1.8.0 Authenticated SQL Injection via Multiple Parameters
- CVE-2021-477211 PoCOrangescrum 1.8.0 Authenticated Privilege Escalation via User Session Manipulation
- CVE-2021-477221 PoCZucchetti Axess CLOKI Access Control 1.64 Cross-Site Request Forgery
- CVE-2021-477231 PoCSTVS ProVision Cross-Site Request Forgery (Add Admin)
- CVE-2021-477241 PoCSTVS ProVision Authenticated File Disclosure via archive.rb
- CVE-2021-477251 PoCSTVS ProVision 5.9.10 Authenticated Reflected Cross-Site Scripting via Files Parameter
- CVE-2021-477261 PoCNuCom 11N Wireless Router 5.07.90 Privilege Escalation via Configuration Backup
- CVE-2021-477271 PoCSelea Targa IP Camera Unauthenticated Stream Disclosure
- CVE-2021-477281 PoCSelea Targa IP Camera Remote Code Execution via Utils
- CVE-2021-477291 PoCSelea Targa IP Camera Stored Cross-Site Scripting via Files List
- CVE-2021-477301 PoCSelea Targa IP Camera Cross-Site Request Forgery via Admin Creation
- CVE-2021-477311 PoCSelea Targa IP Camera Developer Backdoor Configuration Overwrite
- CVE-2021-477321 PoCCMSimple 5.2 Stored Cross-Site Scripting via Filebrowser External Input
- CVE-2021-477331 PoCCMSimple 5.4 Cross-Site Scripting via HTML Unicode Encoding
- CVE-2021-477341 PoCCMSimple 5.4 Authenticated Local File Inclusion Remote Code Execution
- CVE-2021-477351 PoCCMSimple 5.4 Authenticated Remote Code Execution via Template Editing
- CVE-2021-477361 PoCCMSimple_XH 1.7.4 Authenticated Remote Code Execution via Content Editing
- CVE-2021-477371 PoCCSZ CMS 1.2.7 HTML Injection Vulnerability via Member Dashboard
- CVE-2021-477381 PoCCSZ CMS 1.2.7 Persistent Cross-Site Scripting via Private Messaging
- CVE-2021-477391 PoCEpic Games Easy Anti-Cheat 4.0 Local Privilege Escalation via Unquoted Service Path
- CVE-2021-477401 PoCKZTech JT3500V 4G LTE CPE 2.0.1 Insufficient Session Expiration Vulnerability
- CVE-2021-477411 PoCZBL EPON ONU Broadband Router V100R001 Privilege Escalation via Configuration Endpoint
- CVE-2021-477421 PoCEpic Games Psyonix Rocket League <=1.95 Elevation of Privileges via Insecure Permissions
- CVE-2021-477431 PoCCOMMAX Biometric Access Control System 1.0.0 Reflected XSS via Cookie Parameters
- CVE-2021-477441 PoCCypress Solutions CTM-200/CTM-ONE 1.3.6 Hard-coded Credentials Remote Root
- CVE-2021-477451 PoCCypress Solutions CTM-200 2.7.1 Root Remote OS Command Injection via Firmware Upgrade
- CVE-2021-477461 PoCNodeBB Plugin Emoji 3.2.1 - Arbitrary File Write
- CVE-2021-477471 PoCmeterN 1.2.3 Authenticated Remote Code Execution via Admin Scripts
- CVE-2021-477481 PoCHasura GraphQL 1.3.3 - Remote Code Execution
- CVE-2021-477491 PoCYouPHPTube <= 7.8 - Directory Traversal
- CVE-2021-477501 PoCYouPHPTube <= 7.8 - Cross-Site Scripting
- CVE-2021-477511 PoCCuteEditor for PHP 6.6 - Directory Traversal
- CVE-2021-477521 PoCAWebServer GhostBuilding 18 - Denial of Service (DoS)
- CVE-2021-477531 PoCphpKF CMS 3.00 Beta y6 - Remote Code Execution (RCE) (Unauthenticated)
- CVE-2021-477542 PoCsArunna 1.0.0 - 'Multiple' Cross-Site Request Forgery (CSRF)
- CVE-2021-477551 PoCOliver Library Server v5 - Arbitrary File Download
- CVE-2021-477561 PoCLaravel Valet 2.0.3 - Local Privilege Escalation (macOS)
- CVE-2021-477571 PoCChikitsa Patient Management System 2.0.2 - 'plugin' Remote Code Execution (RCE) (Authenticated)
- CVE-2021-477581 PoCChikitsa Patient Management System 2.0.2 - Remote Code Execution (RCE) (Authenticated)
- CVE-2021-477591 PoCMTPutty 1.0.1.21 - SSH Password Disclosure
- CVE-2021-477611 PoCMilleGPG5 5.7.2 Luglio 2021 (x64) - Local Privilege Escalation
- CVE-2021-477621 PoCHTTPDebuggerPro 9.11 - Unquoted Service Path
- CVE-2021-477631 PoCAimeos Laravel ecommerce platform 2021.10 LTS - 'sort' SQL injection
- CVE-2021-477641 PoCAbsoluteTelnet 11.24 - 'Phone' Denial of Service (PoC)
- CVE-2021-477651 PoCAbsoluteTelnet 11.24 - 'Username' Denial of Service (PoC)
- CVE-2021-477661 PoCKmaleon 1.1.0.205 - 'tipocomb' SQL Injection (Authenticated)
- CVE-2021-477671 PoC10-Strike Network Inventory Explorer Pro 9.31 - 'srvInventoryWebServer' Unquoted Service Path
- CVE-2021-477682 PoCsImportExportTools NG 10.0.4 - HTML Injection
- CVE-2021-477692 PoCsIsshue Shopping Cart 3.5 - 'Title' Cross Site Scripting (XSS)
- CVE-2021-477701 PoCOpenPLC 3 - Remote Code Execution
- CVE-2021-477712 PoCsRDP Manager 4.9.9.3 - Denial-of-Service (PoC)
- CVE-2021-477721 PoC10-Strike Network Inventory Explorer Pro 9.31 - Buffer Overflow (SEH)
- CVE-2021-477731 PoCDynojet Power Core 2.3.0 - Unquoted Service Path
- CVE-2021-477741 PoCKingdia CD Extractor 3.0.2 - Buffer Overflow (SEH)
- CVE-2021-477751 PoCYouTube Video Grabber 1.9.9.1 - Buffer Overflow (SEH)
- CVE-2021-477761 PoCUmbraco v8.14.1 - 'baseUrl' SSRF
- CVE-2021-477771 PoCBuild Smart ERP 21.0817 - 'eidValue' SQL Injection (Unauthenticated)
- CVE-2021-477782 PoCsGetSimple CMS My SMTP Contact Plugin 1.1.2 - PHP Code Injection
- CVE-2021-477791 PoCDolibarr ERP-CRM 14.0.2 - Stored Cross-Site Scripting (XSS) / Privilege Escalation
- CVE-2021-477801 PoCMacro Expert 4.7 - Unquoted Service Path
- CVE-2021-477811 PoCCmder Console Emulator 1.3.18 - 'Cmder.exe' Denial of Service (PoC)
- CVE-2021-477821 PoCOdine Solutions GateKeeper 1.0 - 'trafficCycle' SQL Injection
- CVE-2021-477831 PoCPhpwcms 1.9.30 - Arbitrary File Upload
- CVE-2021-477841 PoCCyberfox Web Browser 52.9.1 - Denial of Service (PoC)
- CVE-2021-477851 PoCEther_MP3_CD_Burner 1.3.8 - Buffer Overflow (SEH)
- CVE-2021-477863 PoCsRedragon Gaming Mouse - 'REDRAGON_MOUSE.sys' Denial of Service (PoC)
- CVE-2021-477871 PoCTotalAV 5.15.69 - Unquoted Service Path
- CVE-2021-477881 PoCWebsiteBaker 2.13.0 - Remote Code Execution (RCE) (Authenticated)
- CVE-2021-477893 PoCsYenkee Hornet Gaming Mouse - 'GM312Fltr.sys' Denial of Service (PoC)
- CVE-2021-477901 PoCActive WebCam 11.5 - Unquoted Service Path
- CVE-2021-477911 PoCSmartFTP Client 10.0.2909.0 - 'Multiple' Denial of Service
- CVE-2021-477921 PoCRemote Mouse 4.002 - Unquoted Service Path
- CVE-2021-477932 PoCsTelegram Desktop 2.9.2 - Denial of Service (PoC)
- CVE-2021-477942 PoCsZesleCP 3.1.9 - Remote Code Execution (RCE) (Authenticated)
- CVE-2021-477952 PoCsGeoVision Geowebserver 5.3.3 - Local FIle Inclusion
- CVE-2021-477961 PoCDenver Smart Wifi Camera SHC-150 - 'Telnet' Remote Code Execution (RCE)
- CVE-2021-477972 PoCsLeawo Prof. Media 11.0.0.1 - Denial of Service (DoS) (PoC)
- CVE-2021-477982 PoCsNoteBurner 2.35 - Denial Of Service (DoS) (PoC)
- CVE-2021-477991 PoCVisual Tools DVR VX16 4.2.28 - Local Privilege Escalation
- CVE-2021-478001 PoCb2evolution 7.2.2 - 'edit account details' Cross-Site Request Forgery (CSRF)
- CVE-2021-478011 PoCVianeos OctoPUS 5 - 'login_user' SQLi
- CVE-2021-478021 PoCTenda D151 & D301 - Configuration Download
- CVE-2021-478031 PoCiFunbox 4.2 - 'Apple Mobile Device Service' Unquoted Service Path
- CVE-2021-478041 PoCWise Care 365 5.6.7.568 - 'WiseBootAssistant' Unquoted Service Path
- CVE-2021-478051 PoCDisk Savvy 13.6.14 - 'Multiple' Unquoted Service Path
- CVE-2021-478061 PoCDup Scout 13.5.28 - 'Multiple' Unquoted Service Path
- CVE-2021-478071 PoCSync Breeze 13.6.18 - 'Multiple' Unquoted Service Path
- CVE-2021-478081 PoCCotonti Siena 0.9.19 - 'maintitle' Stored Cross-Site Scripting
- CVE-2021-478091 PoCDisk Sorter Enterprise 13.6.12 - 'Disk Sorter Enterprise' Unquoted Service Path
- CVE-2021-478101 PoCWibuKey Runtime 6.51 - 'WkSvW32.exe' Unquoted Service Path
- CVE-2021-478111 PoCGrocery crud 1.6.4 - 'order_by' SQL Injection
- CVE-2021-478121 PoCGravCMS 1.10.7 - Arbitrary YAML Write/Update (Unauthenticated) (2)
- CVE-2021-478132 PoCsBackup Key Recovery 2.2.7 - Denial of Service (PoC)
- CVE-2021-478142 PoCsNBMonitor 1.6.8 - Denial of Service (PoC)
- CVE-2021-478152 PoCsNsauditor 3.2.3 - Denial of Service (PoC)
- CVE-2021-478162 PoCsThecus N4800Eco Nas Server Control Panel - Command Injection
- CVE-2021-478171 PoCOpenEMR 5.0.2.1 - Remote Code Execution
- CVE-2021-478181 PoCDupTerminator 1.4.5639.37199 - Denial of Service
- CVE-2021-478191 PoCProjeQtOr Project Management 9.1.4 - Remote Code Execution
- CVE-2021-478201 PoCUbee EVW327 - 'Enable Remote Access' Cross-Site Request Forgery (CSRF)
- CVE-2021-478211 PoCRarmaRadio 2.72.8 - Denial of Service
- CVE-2021-478221 PoCDiskBoss Service 12.2.18 - 'diskbsa.exe' Unquoted Service Path
- CVE-2021-478231 PoCePowerSvc 6.0.3008.0 - 'ePowerSvc.exe' Unquoted Service Path
- CVE-2021-478242 PoCsiDailyDiary 4.30 - Denial of Service (PoC)
- CVE-2021-478251 PoCAcer Updater Service 1.2.3500.0 - 'UpdaterService.exe' Unquoted Service Path
- CVE-2021-478261 PoCAcer Backup Manager Module 3.0.0.99 - 'IScheduleSvc.exe' Unquoted Service Path
- CVE-2021-478271 PoCWebSSH for iOS 14.16.10 - 'mashREPL' Denial of Service
- CVE-2021-478281 PoCBOOTP Turbo 2.0.0.1253 - 'bootpt.exe' Unquoted Service Path
- CVE-2021-478291 PoCDHCP Broadband 4.1.0.1503 - 'dhcpt.exe' Unquoted Service Path
- CVE-2021-478302 PoCsGetSimple CMS My SMTP Contact Plugin 1.1.1 - CSRF
- CVE-2021-478311 PoCSandboxie 5.49.7 - Denial of Service
- CVE-2021-478331 PoCWifiHotSpot 1.0.0.0 - 'WifiHotSpotService.exe' Unquoted Service Path
- CVE-2021-478341 PoCSchlix CMS 2.2.6-6 - 'title' Persistent Cross-Site Scripting (Authenticated)
- CVE-2021-478352 PoCsFreeter 1.2.1 - Persistent Cross-Site Scripting
- CVE-2021-478362 PoCsMarkdown Explorer 0.1.1 - Persistent Cross-Site Scripting
- CVE-2021-478372 PoCsMarkdownify 1.2.0 - Persistent Cross-Site Scripting
- CVE-2021-478382 PoCsMarkright 1.0 - Persistent Cross-Site Scripting
- CVE-2021-478392 PoCsMarky 0.0.1 - Persistent Cross-Site Scripting
- CVE-2021-478402 PoCsMoeditor 0.2.0 - Persistent Cross-Site Scripting
- CVE-2021-478412 PoCsSnipCommand 0.1.0 - Persistent Cross-Site Scripting
- CVE-2021-478422 PoCsStudyMD 0.3.2 - Persistent Cross-Site Scripting
- CVE-2021-478432 PoCsTagstoo 2.0.1 - Stored XSS to RCE
- CVE-2021-478442 PoCsXmind 2020 - Persistent Cross-Site Scripting
- CVE-2021-478451 PoCSpy Emergency 25.0.650 - Unquoted Service Path
- CVE-2021-478461 PoCDigital Crime Report Management System 1.0 - SQL Injection
- CVE-2021-478471 PoCDisk Sorter Server 13.6.12 - 'Disk Sorter Server' Unquoted Service Path
- CVE-2021-478481 PoCBlitar Tourism 1.0 - Authentication Bypass SQLi
- CVE-2021-478491 PoCMini Mouse 9.3.0 - Local File inclusion / Path Traversal
- CVE-2021-478501 PoCMini Mouse 9.2.0 - Path Traversal
- CVE-2021-478511 PoCMini Mouse 9.2.0 - Remote Code Execution
- CVE-2021-478521 PoCRockstar Service - Insecure File Permissions
- CVE-2021-478541 PoCDD-WRT 45723 - UPNP Buffer Overflow
- CVE-2021-478551 PoCOpenlitespeed 1.7.9 - 'Notes' Stored Cross-Site Scripting
- CVE-2021-478561 PoCEasy Cart Shopping Cart 2021 Cross-Site Scripting via Search Parameter
- CVE-2021-478571 PoCMoodle 3.10.3 - 'label' Persistent Cross Site Scripting
- CVE-2021-478581 PoCGenexis Platinum-4410 P4410-V2-1.31A - 'start_addr' Persistent Cross-Site Scripting
- CVE-2021-478591 PoCActivIdentity 8.2 - 'ac.sharedstore' Unquoted Service Path
- CVE-2021-478603 PoCsGetSimple CMS Custom JS 0.1 - CSRF to XSS to RCE
- CVE-2021-478611 PoCEvent Log Explorer 4.9.3 - 'ElodeaEventCollectorService' Unquoted Service Path
- CVE-2021-478621 PoCHi-Rez Studios 5.1.6.3 - 'HiPatchService' Unquoted Service Path
- CVE-2021-478631 PoCMacPaw Encrypto 1.0.1 - 'Encrypto Service' Unquoted Service Path
- CVE-2021-478641 PoCOSAS Traverse Extension 11 - 'travextensionhostsvc' Unquoted Service Path
- CVE-2021-478651 PoCProFTPD 1.3.7a - Remote Denial of Service
- CVE-2021-478661 PoCWIN-PACK PRO 4.8 - 'GuardTourService' Unquoted Service Path
- CVE-2021-478671 PoCWIN-PACK PRO 4.8 - 'ScheduleService' Unquoted Service Path
- CVE-2021-478681 PoCWIN-PACK PRO 4.8 - 'WPCommandFileService' Unquoted Service Path
- CVE-2021-478691 PoCBRAdmin Professional 3.75 - 'BRA_Scheduler' Unquoted Service Path
- CVE-2021-478702 PoCsGetSimple CMS My SMTP Contact Plugin 1.1.2 - Stored XSS
- CVE-2021-478711 PoCHestia Control Panel 1.3.2 - Arbitrary File Write
- CVE-2021-478721 PoCSEO Panel < 4.9.0 - 'order_col' Blind SQL Injection
- CVE-2021-478731 PoCVestaCP < 0.9.8-25 - Stored Cross-Site Scripting
- CVE-2021-478741 PoCVFS for Git 1.0.21014.1 - 'GVFS.Service' Unquoted Service Path
- CVE-2021-478751 PoCGeoGebra CAS Calculator 6.0.631.0 - Denial of Service
- CVE-2021-478761 PoCGeoGebra Classic 5.0.631.0-d - Denial of Service
- CVE-2021-478771 PoCGeoGebra Graphing Calculator 6.0.631.0 - Denial Of Service
- CVE-2021-478781 PoCeBeam Education Suite 2.5.0.9 - 'eBeam Device Service' Unquoted Service Path
- CVE-2021-478791 PoCeBeam Interactive Suite 3.6 - 'eBeam Stylus Driver' Unquoted Service Path
- CVE-2021-478801 PoCRealtek Wireless LAN Utility 700.1631 - 'Realtek11nSU' Unquoted Service Path
- CVE-2021-478812 PoCsdataSIMS Avionics ARINC 664-1 - Local Buffer Overflow
- CVE-2021-478821 PoCFreeLAN 2.2 - 'FreeLAN Service' Unquoted Service Path
- CVE-2021-478831 PoCSandboxie Plus v0.7.2 - 'SbieSvc' Unquoted Service Path
- CVE-2021-478841 PoCConfiguration Tool 1.6.53 - 'OpLclSrv' Unquoted Service Path
- CVE-2021-478851 PoCPayment Terminal Multiple Versions Non-Persistent Cross-Site Scripting
- CVE-2021-478861 PoCPingzapper 2.3.1 - 'PingzapperSvc' Unquoted Service Path
- CVE-2021-478871 PoCPrint Job Accounting 4.4.10 - 'OkiJaSvc' Unquoted Service Path
- CVE-2021-478881 PoCTextpattern 4.8.3 - Remote code execution
- CVE-2021-478891 PoCSoftros LAN Messenger 9.6.4 - 'SoftrosSpellChecker' Unquoted Service Path
- CVE-2021-478901 PoCLogonExpert 8.1 - 'LogonExpertSvc' Unquoted Service Path
- CVE-2021-478911 PoCUnified Remote 3.9.0.2463 - Remote Code Execution
- CVE-2021-478921 PoCPEEL Shopping 9.3.0 - 'Comments/Special Instructions' Stored Cross-Site Scripting
- CVE-2021-478931 PoCAgataSoft PingMaster Pro 2.1 - Denial of Service
- CVE-2021-478941 PoCManaged Switch Port Mapping Tool 2.85.2 - Denial of Service
- CVE-2021-478951 PoCNsauditor 3.2.2.0 - 'Event Description' Denial of Service
- CVE-2021-478961 PoCPDFCOMPLETE Corporate Edition 4.1.45 - 'pdfcDispatcher' Unquoted Service Path
- CVE-2021-478971 PoCPEEL Shopping 9.3.0 - 'address' Stored Cross-Site Scripting
- CVE-2021-478981 PoCEpson USB Display 1.6.0.0 Unquoted Service Path Vulnerability
- CVE-2021-478991 PoCYetiShare File Hosting Script 5.1.0 Remote File Upload SSRF Vulnerability
- CVE-2021-479001 PoCGila CMS < 2.0.0 - Remote Code Execution
- CVE-2021-479011 PoCdirsearch 0.4.1 - CSV Injection
- CVE-2021-479021 PoCTesta Online Test Management System 3.4.7 - 'q' SQL Injection
- CVE-2021-479031 PoCLiteSpeed Web Server Enterprise 5.4.11 - Command Injection
- CVE-2021-479043 PoCsPhreeBooks 5.2.3 - Remote Code Execution
- CVE-2021-479051 PoCMyBB Delete Account Plugin 1.4 - Cross-Site Scripting
- CVE-2021-479061 PoCBloofoxCMS 0.5.2.1 - 'text' Stored Cross Site Scripting
- CVE-2021-479071 PoCRocket LMS 1.1 Persistent Cross-Site Scripting via Support Tickets
- CVE-2021-479081 PoCUltimate POS 4.4 Persistent Cross-Site Scripting via Product Name
- CVE-2021-479091 PoCMult-E-Cart Ultimate 2.4 SQL Injection via Vulnerable ID Parameters
- CVE-2021-479101 PoCWordPress Plugin AccessPress Social Icons 1.8.2 Stored XSS
- CVE-2021-479111 PoCAffiliate Pro 1.7 Reflected Cross-Site Scripting via Index Module
- CVE-2021-479121 PoCPHP Melody 3.0 Non-Persistent Cross-Site Scripting via Multiple Parameters
- CVE-2021-479131 PoCPHP Melody 3.0 Persistent Cross-Site Scripting via Video Editor
- CVE-2021-479141 PoCPHP Melody 3.0 Persistent XSS Vulnerability via Edit Video Parameter
- CVE-2021-479151 PoCPHP Melody 3.0 SQL Injection Vulnerability via Edit Video Parameter
- CVE-2021-479171 PoCSimple CMS 2.1 Persistent Cross-Site Scripting via User Input Parameters
- CVE-2021-479181 PoCSimple CMS 2.1 SQL Injection Vulnerability via Users Module
- CVE-2021-479191 PoCSimple CMS 2.1 Non-Persistent Cross-Site Scripting via Preview Parameter
- CVE-2021-479201 PoCWebMO Job Manager 20.0 Cross-Site Scripting via Search Parameters
- CVE-2021-479211 PoCFree Photo & Video Vault 0.0.2 Directory Traversal Vulnerability via Web Request
- CVE-2021-479221 PoCWordPress Plugin Slider by Soliloquy 2.6.2 Stored XSS
- CVE-2021-479231 PoCOpenCart 3.0.3.8 Session Fixation via OCSESSID Cookie
- CVE-2021-479241 PoCWordPress Plugin Ultimate Product Catalogue 5.8.2 Stored XSS via price
- CVE-2021-479251 PoCCMDBuild 3.3.2 Multiple Stored Cross-Site Scripting
- CVE-2021-479261 PoCWordPress Contact Form to Email 1.3.24 Stored XSS
- CVE-2021-479271 PoCWordPress Plugin WP Symposium Pro 2021.10 Stored XSS via wps_admin_forum_add_name
- CVE-2021-479281 PoCOpencart TMD Vendor System 3.x Blind SQL Injection via product route
- CVE-2021-479291 PoCWordPress Plugin Filterable Portfolio Gallery 1.0 Stored XSS
- CVE-2021-479301 PoCBalbooa Joomla Forms Builder 2.0.6 SQL Injection Unauthenticated
- CVE-2021-479311 PoCExponent CMS 2.6 Multiple Vulnerabilities Stored XSS Authentication
- CVE-2021-479321 PoCWordPress TheCartPress 1.5.3.6 Privilege Escalation Unauthenticated
- CVE-2021-479331 PoCWordPress MStore API 2.0.6 Arbitrary File Upload
- CVE-2021-479341 PoCMyBB Timeline Plugin 1.0 Cross-Site Scripting and CSRF
- CVE-2021-479351 PoCSentry 8.2.0 Remote Code Execution via Pickle Deserialization
- CVE-2021-479361 PoCOpenCATS 0.9.4 Remote Code Execution via Resume Upload
- CVE-2021-479371 PoCe107 CMS 2.3.0 Authenticated Remote Code Execution via Theme Upload
- CVE-2021-479381 PoCImpressCMS 1.4.2 Remote Code Execution via Autotasks
- CVE-2021-479391 PoCEvolution CMS 3.1.6 Authenticated Remote Code Execution via Module Creation
- CVE-2021-479401 PoCWordPress Download From Files 1.48 Arbitrary File Upload
- CVE-2021-479411 PoCWordPress Plugin Survey & Poll 1.5.7.3 SQL Injection via sss_params
- CVE-2021-479421 PoCHome Assistant Community Store 1.10.0 Path Traversal Account Takeover
- CVE-2021-479432 PoCsTextPattern CMS 4.8.7 Remote Code Execution via File Upload
- CVE-2021-479441 PoCmemono Notepad 4.2 Denial of Service via Buffer Overflow
- CVE-2021-479451 PoCArgus Surveillance DVR 4.0 Unquoted Service Path Privilege Escalation
- CVE-2021-479461 PoCOpenCart 3.0.3.6 Account Takeover via Cross Site Request Forgery
- CVE-2021-479471 PoCProjectsend r1295 Stored Cross-Site Scripting via files-edit.php
- CVE-2021-479481 PoCWordPress GetPaid Plugin 2.4.6 HTML Injection via Help Text
- CVE-2021-479491 PoCCyberPanel 2.1 Authenticated Remote Code Execution via Symlink Attack
- CVE-2021-479501 PoCAdvanced Guestbook 2.4.4 Persistent XSS via Smilies
- CVE-2021-479511 PoCWordPress Picture Gallery 1.4.2 Stored XSS via Edit Content URL
- CVE-2021-479521 PoCpython jsonpickle 2.0.0 Remote Code Execution via py/repr
- CVE-2021-479531 PoCOpenCart 3.0.3.7 Cross-Site Request Forgery via account/password
- CVE-2021-479541 PoCLayerBB 1.1.4 SQL Injection via search_query Parameter
- CVE-2021-479551 PoCCouchCMS 2.2.1 Cross-Site Scripting via SVG File Upload
- CVE-2021-479561 PoCEgavilanMedia PHPCRUD 1.0 SQL Injection via firstname
- CVE-2021-479571 PoCWordPress Plugin Cookie Law Bar 1.2.1 Stored XSS via clb_bar_msg
- CVE-2021-479581 PoCCouchCMS 2.2.1 Server-Side Request Forgery via SVG upload
- CVE-2021-479591 PoCWordPress Plugin WPGraphQL 1.3.5 Denial of Service
- CVE-2021-479621 PoCSavsoft Quiz 5.0 Persistent Cross-Site Scripting via User Settings
- CVE-2021-479631 PoCAnote 1.0 Persistent Cross-Site Scripting Leading to Code Execution
- CVE-2021-479641 PoCSchlix CMS 2.2.6-6 Remote Code Execution via core.blockmanager
- CVE-2021-479651 PoCWordPress Plugin WP Super Edit 2.5.4 Unrestricted File Upload
- CVE-2021-479661 PoCPHP Timeclock 1.04 SQL Injection via login.php
- CVE-2021-479671 PoCPHP Timeclock 1.04 Multiple Cross-Site Scripting via Parameters
- CVE-2021-479681 PoCPodcast Generator 3.1 Persistent Cross-Site Scripting via long_description
- CVE-2021-479691 PoCColor Notes 1.4 Denial of Service via Long Character String
- CVE-2021-479701 PoCMacaron Notes 5.5 Denial of Service via Buffer Overflow
- CVE-2021-479711 PoCMy Notes Safe 5.3 Denial of Service via Buffer Overflow
- CVE-2021-479721 PoCSticky Notes & Color Widgets 1.4.2 Denial of Service
- CVE-2021-479731 PoCSticky Notes Widget 3.0.6 Denial of Service via Buffer Overflow
- CVE-2021-479741 PoCVX Search 13.5.28 Unquoted Service Path Privilege Escalation
- CVE-2021-479751 PoCWordPress Plugin WP Learn Manager 1.1.2 Stored XSS
- CVE-2021-479761 PoCTextPattern CMS 4.9.0-dev Authenticated Remote Code Execution via Plugin Upload
- CVE-2021-479771 PoCWordPress Anti-Malware Security Bruteforce Firewall <= 4.20.72 Directory Traversal
- CVE-2021-479781 PoCProcessMaker 3.5.4 Local File Inclusion via Path Traversal
- CVE-2021-479791 PoCWordPress Plugin Backup and Restore 1.0.3 Arbitrary File Deletion
- CVE-2021-479801 PoCFuel CMS 1.4.13 Blind SQL Injection via col Parameter
- CVE-2021-479811 PoCQuick.CMS 6.7 Cross-Site Scripting via CSRF to Sliders Form
- CVE-2021-479821 PoCWordPress Plugin WP-Paginate 2.1.3 Stored XSS via preset
- CVE-2021-479831 PoCWordPress Plugin Stripe Payments < 2.0.40 Stored XSS via currency_code
- CVE-2021-479841 PoCWordPress Plugin WP24 Domain Check 1.6.2 Stored XSS
- CVE-2021-479851 PoCBrother SAPSprint 7.60 Unquoted Service Path Privilege Escalation