CVE-2021-4000 to CVE-2021-4999
121 CVEs with public proof-of-concept exploits.
- CVE-2021-40001 PoCOpen Redirect in star7th/showdoc
- CVE-2021-40021 PoCA memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps some regions of memory twice using…
- CVE-2021-40051 PoCCross-Site Request Forgery (CSRF) in firefly-iii/firefly-iii
- CVE-2021-40151 PoCCross-Site Request Forgery (CSRF) in firefly-iii/firefly-iii
- CVE-2021-40171 PoCCross-Site Request Forgery (CSRF) in star7th/showdoc
- CVE-2021-40181 PoCCross-site Scripting (XSS) - Stored in snipe/snipe-it
- CVE-2021-40191 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2021-40201 PoCCross-site Scripting (XSS) - Stored in meetecho/janus-gateway
- CVE-2021-40261 PoCImproper Access Control in bookstackapp/bookstack
- CVE-2021-40321 PoCA vulnerability was found in the Linux kernel's KVM subsystem in arch/x86/kvm/lapic.c kvm_free_lapic when a failure allocation was…
- CVE-2021-40331 PoCCross-Site Request Forgery (CSRF) in kevinpapst/kimai2
- CVE-2021-4034227 PoCsKEVA local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow…
- CVE-2021-40351 PoCWocu Monitoring stored Cross-Site Scripting (XSS)
- CVE-2021-40392 PoCsA command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS…
- CVE-2021-40431 PoCNULL Pointer Dereference in gpac/gpac
- CVE-2021-40441 PoCInvalid handling of X509_verify_cert() internal errors in libssl
- CVE-2021-404518 PoCsTP-LINK Tapo C200 remote code execution vulnerability
- CVE-2021-40491 PoCCross-Site Request Forgery (CSRF) in livehelperchat/livehelperchat
- CVE-2021-40501 PoCCross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat
- CVE-2021-40691 PoCUse After Free in vim/vim
- CVE-2021-40701 PoCOff-by-one Error in v2fly/v2ray-core
- CVE-2021-40731 PoCRegistrationMagic <= 5.0.1.7 Authentication Bypass
- CVE-2021-40801 PoCUnrestricted Upload of File with Dangerous Type in crater-invoice/crater
- CVE-2021-40821 PoCCross-Site Request Forgery (CSRF) in pimcore/pimcore
- CVE-2021-40841 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2021-40891 PoCImproper Access Control in snipe/snipe-it
- CVE-2021-40921 PoCCross-Site Request Forgery (CSRF) in yetiforcecompany/yetiforcecrm
- CVE-2021-40971 PoCCRLF Injection in phpservermon/phpservermon
- CVE-2021-41031 PoCCross-site Scripting (XSS) - Stored in vanessa219/vditor
- CVE-2021-41043 PoCsDeserialization of untrusted data in JMSAppender in Apache Log4j 1.2
- CVE-2021-41071 PoCCross-site Scripting (XSS) - Reflected in yetiforcecompany/yetiforcecrm
- CVE-2021-41081 PoCCross-site Scripting (XSS) - Stored in snipe/snipe-it
- CVE-2021-41101 PoCNULL Pointer Dereference in mruby/mruby
- CVE-2021-41111 PoCBusiness Logic Errors in yetiforcecompany/yetiforcecrm
- CVE-2021-41151 PoCThere is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The…
- CVE-2021-41161 PoCCross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm
- CVE-2021-41181 PoCDeserialization of Untrusted Data in pytorchlightning/pytorch-lightning
- CVE-2021-41191 PoCImproper Access Control in bookstackapp/bookstack
- CVE-2021-41211 PoCCross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm
- CVE-2021-41231 PoCCross-Site Request Forgery (CSRF) in livehelperchat/livehelperchat
- CVE-2021-41241 PoCCross-site Scripting (XSS) - Stored in meetecho/janus-gateway
- CVE-2021-41301 PoCCross-Site Request Forgery (CSRF) in snipe/snipe-it
- CVE-2021-41311 PoCCross-Site Request Forgery (CSRF) in livehelperchat/livehelperchat
- CVE-2021-41321 PoCCross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat
- CVE-2021-41361 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2021-41391 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2021-41431 PoCCross-site Scripting (XSS) - Generic in bigbluebutton/bigbluebutton
- CVE-2021-41461 PoCBusiness Logic Errors in pimcore/pimcore
- CVE-2021-41542 PoCsA use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local…
- CVE-2021-41561 PoCAn out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file…
- CVE-2021-41621 PoCCross-Site Request Forgery (CSRF) in archivy/archivy
- CVE-2021-41641 PoCCross-Site Request Forgery (CSRF) in janeczku/calibre-web
- CVE-2021-41661 PoCOut-of-bounds Read in vim/vim
- CVE-2021-41691 PoCCross-site Scripting (XSS) - Reflected in livehelperchat/livehelperchat
- CVE-2021-41701 PoCCross-site Scripting (XSS) - Stored in janeczku/calibre-web
- CVE-2021-41711 PoCBusiness Logic Errors in janeczku/calibre-web
- CVE-2021-41731 PoCUse After Free in vim/vim
- CVE-2021-41751 PoCCross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat
- CVE-2021-41761 PoCCross-site Scripting (XSS) - Reflected in livehelperchat/livehelperchat
- CVE-2021-41771 PoCGeneration of Error Message Containing Sensitive Information in livehelperchat/livehelperchat
- CVE-2021-41781 PoCA arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an…
- CVE-2021-41791 PoCCross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat
- CVE-2021-41871 PoCUse After Free in vim/vim
- CVE-2021-41881 PoCNULL Pointer Dereference in mruby/mruby
- CVE-2021-41901 PoCLarge loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file
- CVE-2021-41914 PoCsAn issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab…
- CVE-2021-41921 PoCUse After Free in vim/vim
- CVE-2021-41931 PoCOut-of-bounds Read in vim/vim
- CVE-2021-41941 PoCImproper Access Control in bookstackapp/bookstack
- CVE-2021-42041 PoCAn out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This flaw allows a…
- CVE-2021-42081 PoCExportFeed <= 2.0.1.0 - Admin+ SQL Injection
- CVE-2021-42211 PoCIf a domain name contained a RTL character, it would cause the domain to be rendered to the right of the path. This could lead to user…
- CVE-2021-42222 PoCsWP Paginate < 2.1.4 - Admin+ Stored Cross-Site Scripting
- CVE-2021-42252 PoCsSP Project & Document Manager < 4.24 - Subscriber+ Shell Upload
- CVE-2021-42261 PoCRSFirewall < 1.1.25 - IP Block Bypass
- CVE-2021-42271 PoCArk Comment Editor <= 2.15.6 - Iframe Injection via Comment
- CVE-2021-42421 PoCSapido BR270n/BRC76n/GR297/RB1732 syscmd.htm os command injection
- CVE-2021-42451 PoCchbrown rfc6902 pointer.ts prototype pollution
- CVE-2021-42501 PoCcgriego active_attr Regex boolean_typecaster.rb call denial of service
- CVE-2021-42641 PoCLinkedIn dustjs prototype pollution
- CVE-2021-42791 PoCStarcounter-Jack JSON-Patch prototype pollution
- CVE-2021-43051 PoCWoorank robots-txt-guard patterns.js makePathPattern redos
- CVE-2021-43071 PoCYomguithereal Baobab prototype pollution
- CVE-2021-43151 PoCNYUCCL psiTurk experiment.py special elements used in a template engine
- CVE-2021-43272 PoCsSerenityOS TypedArray.cpp initialize_typed_array_from_array_buffer integer overflow
- CVE-2021-43281 PoC狮子鱼CMS ApiController.class.php goods_detail sql injection
- CVE-2021-43742 PoCsWordPress Automatic Plugin <= 3.53.2 - Unauthenticated Arbitrary Options Update
- CVE-2021-43801 PoCPinterest Automatic <= 4.14.3 - Unuathenticated Arbitrary Options Update
- CVE-2021-43871 PoCOpal Estate <= 1.6.11 - Cross-Site Request Forgery Bypass
- CVE-2021-43881 PoCOpal Estate <= 1.6.11 - Missing Authorization
- CVE-2021-43891 PoCWP Travel <= 4.4.6 - Cross-Site Request Forgery Bypass
- CVE-2021-43911 PoCUltimate Gift Cards for WooCommerce <= 2.1.1 - Cross-Site Request Forgery Bypass
- CVE-2021-43931 PoCeCommerce Product Catalog Plugin for WordPress <= 3.0.17 - Cross-Site Request Forgery Bypass
- CVE-2021-43941 PoCLocations <= 3.2.1 - Cross-Site Request Forgery Bypass
- CVE-2021-44061 PoCAuthenticated Remote COmmand Execution as root in OSNEXUS QuantaStor version 6.0.0.355 and others
- CVE-2021-44181 PoCCustom CSS, JS & PHP <= 2.0.7 - Cross-Site Request Forgery Bypass
- CVE-2021-44255 PoCsDefender Security <= 2.4.6 - Cross-Site Request Forgery Bypass
- CVE-2021-44265 PoCsAbsolute Reviews <= 1.0.8 - Cross-Site Request Forgery Bypass
- CVE-2021-44275 PoCsVuukle Comments, Reactions, Share Bar, Revenue <= 3.4.31 - Cross-Site Request Forgery Bypass
- CVE-2021-44283 PoCswhat3words Autosuggest Plugin Setting class-w3w-autosuggest-public.php enqueue_scripts information disclosure
- CVE-2021-44322 PoCsPCMan FTP Server USER Command denial of service
- CVE-2021-44331 PoCKarjasoft Sami HTTP Server HTTP HEAD Rrequest denial of service
- CVE-2021-44341 PoCSocial Warfare <= 3.5.2 - Remote Code Execution
- CVE-2021-44362 PoCs3DPrint Lite < 1.9.1.5 - Unauthenticated Arbitrary File Upload
- CVE-2021-44451 PoCPremium Addons for Elementor <= 4.5.1 - Authenticated (Subscriber+) Limited Arbitrary Option Update
- CVE-2021-44481 PoCKaswara Modern VC Addons <= 3.0.1 - Missing Authorization
- CVE-2021-44493 PoCsZoomSounds <= 5.96 - Unauthenticated Arbitrary File Upload
- CVE-2021-44551 PoCWordpress Plugin Smart Product Review <= 1.0.4 - Unauthenticated Arbitrary File Upload
- CVE-2021-44571 PoCZoomSounds < 6.05 - Unauthenticated Arbitrary File Upload
- CVE-2021-44613 PoCsSeeyon Zhiyuan OA Web Application System < 7.0 SP1 Authentication Bypass
- CVE-2021-44622 PoCsEmployee Records System v1.0 Arbitrary File Upload RCE
- CVE-2021-44635 PoCsLongjing Technology BEMS API <= 1.21 Remote Arbitrary File Download
- CVE-2021-44642 PoCsFIberHome AN5506-04-FA / HG6245D Routers Remote Stack Overflow
- CVE-2021-44654 PoCsReQuest Serious Play F3 Media Server <= 7.0.3 Remote DoS
- CVE-2021-44661 PoCIPCop <= 2.1.9 Authenticated RCE
- CVE-2021-44672 PoCsPositive Technologies MaxPatrol 8 & XSpider Remote DoS
- CVE-2021-44682 PoCsPLANEX CS-QP50F-ING2 Smart Camera Remote Configuration Disclosure
- CVE-2021-44691 PoCDenver SHO-110 IP Camera Unauthenticated Snapshot Access
- CVE-2021-44701 PoCTG8 Firewall Unauthenticated RCE via runphpcmd.php
- CVE-2021-44711 PoCTG8 Firewall Unauthenticated User Password Disclosure
- CVE-2021-44731 PoCTianxin Internet Behavior Management System Command Injection via toQuery.php