Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Spring Cloud Netflix | Spring Cloud Netflix versions 2.2.x prior to 2.2.10.Release + and old unsupported versions | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Spring Cloud Netflix Hystrix Dashboard template resolution vulnerability CVE-2021-22053 | https://github.com/SecCoder-Security-Lab/spring-cloud-netflix-hystrix-dashboard-cve-2021-22053 | POC Details |
| 2 | CVE-2021-22053: Spring Cloud Netflix Hystrix Dashboard template resolution vulnerability | https://github.com/Vulnmachines/CVE-2021-22053 | POC Details |
| 3 | Spring Cloud Netflix Hystrix Dashboard prior to version 2.2.10 is susceptible to remote code execution. Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the resolution of view templates. When a request is made at `/hystrix/monitor;[user-provided data]`, the path elements following `hystrix/monitor` are being evaluated as SpringEL expressions, which can lead to code execution. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-22053.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-23433 | 5.9 MEDIUM | Prototype Pollution |
| CVE-2021-37592 | Suricata 缓冲区错误漏洞 | |
| CVE-2021-29325 | Moddable SDK 缓冲区错误漏洞 | |
| CVE-2021-29323 | Moddable SDK 缓冲区错误漏洞 | |
| CVE-2021-29324 | Moddable SDK 缓冲区错误漏洞 | |
| CVE-2021-22028 | Greenplum Database 路径遍历漏洞 | |
| CVE-2021-3962 | ImageMagick 资源管理错误漏洞 | |
| CVE-2021-22030 | Greenplum Database 日志信息泄露漏洞 | |
| CVE-2021-33850 | WordPress 跨站脚本漏洞 | |
| CVE-2021-29326 | Moddable SDK 缓冲区错误漏洞 | |
| CVE-2021-41435 | ASUS routers 安全漏洞 | |
| CVE-2021-41436 | ASUS routers 环境问题漏洞 | |
| CVE-2021-44033 | Ionic Identity Vault 安全漏洞 | |
| CVE-2021-44025 | Roundcube Webmail 跨站脚本漏洞 | |
| CVE-2021-44026 | Roundcube Webmail SQL注入漏洞 | |
| CVE-2021-21898 | LibreCAD 缓冲区错误漏洞 | |
| CVE-2021-21899 | LibreCAD 缓冲区错误漏洞 | |
| CVE-2021-21900 | LibreCAD 资源管理错误漏洞 | |
| CVE-2021-29327 | Moddable SDK 缓冲区错误漏洞 | |
| CVE-2021-29328 | Moddable SDK 缓冲区错误漏洞 |
Showing top 20 of 35 CVEs. View all on vendor page → →
No comments yet