CVE-2024-0 to CVE-2024-999
392 CVEs with public proof-of-concept exploits.
- CVE-2024-00013 PoCsA condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially…
- CVE-2024-00021 PoCA condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.
- CVE-2024-00031 PoCA condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the…
- CVE-2024-00041 PoCA condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate…
- CVE-2024-00051 PoCA condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotely through a…
- CVE-2024-001217 PoCsKEVPAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
- CVE-2024-00151 PoCIn convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to intent…
- CVE-2024-00231 PoCIn ConvertRGBToPlanarYUV of Codec2BufferUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could…
- CVE-2024-00301 PoCIn btif_to_bta_response of btif_gatt_util.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to…
- CVE-2024-00391 PoCIn attp_build_value_cmd of att_protocol.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to…
- CVE-2024-00401 PoCIn setParameter of MtpPacket.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote…
- CVE-2024-004423 PoCsIn createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation. This could…
- CVE-2024-01323 PoCsNVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default…
- CVE-2024-01811 PoCRRJ Nueva Ecija Engineer Online Portal Admin Panel admin_user.php cross site scripting
- CVE-2024-01831 PoCRRJ Nueva Ecija Engineer Online Portal NIA Office students.php cross site scripting
- CVE-2024-01841 PoCRRJ Nueva Ecija Engineer Online Portal Add Enginer edit_teacher.php cross site scripting
- CVE-2024-01851 PoCRRJ Nueva Ecija Engineer Online Portal Avatar dasboard_teacher.php unrestricted upload
- CVE-2024-01861 PoCHuiRan Host Reseller System HTTP POST Request password recovery
- CVE-2024-01871 PoCCommunity by PeepSo < 6.3.1.2 - Reflected XSS
- CVE-2024-01881 PoCRRJ Nueva Ecija Engineer Online Portal change_password_teacher.php weak password
- CVE-2024-01891 PoCRRJ Nueva Ecija Engineer Online Portal Create Message teacher_message.php cross site scripting
- CVE-2024-01901 PoCRRJ Nueva Ecija Engineer Online Portal Quiz add_quiz.php cross site scripting
- CVE-2024-01911 PoCRRJ Nueva Ecija Engineer Online Portal file information disclosure
- CVE-2024-01921 PoCRRJ Nueva Ecija Engineer Online Portal Add Downloadable downloadable.php unrestricted upload
- CVE-2024-01941 PoCCodeAstro Internet Banking System Profile Picture pages_account.php unrestricted upload
- CVE-2024-01956 PoCsspider-flow FunctionController.java FunctionService.saveFunction code injection
- CVE-2024-01961 PoCMagic-Api code injection
- CVE-2024-01971 PoCPrivilege Escalation in Thales SafeNet Sentinel HASP LDK
- CVE-2024-01991 PoCIncorrect Authorization in GitLab
- CVE-2024-02002 PoCsUnsafe Reflection in Github Enterprise Server leading to Command Injection
- CVE-2024-02046 PoCsAuthentication Bypass in GoAnywhere MFT
- CVE-2024-02091 PoCNULL Pointer Dereference in Wireshark
- CVE-2024-02101 PoCUncontrolled Recursion in Wireshark
- CVE-2024-02301 PoCA session management issue was addressed with improved checks. This issue is fixed in Magic Keyboard Firmware Update 2.0.6. An attacker…
- CVE-2024-02311 PoCImproper Control of Resource Identifiers ('Resource Injection') in GitLab
- CVE-2024-02331 PoCEventON (Free < 2.2.8, Premium < 4.5.5) - Reflected XSS
- CVE-2024-02354 PoCsEventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Email Address Disclosure
- CVE-2024-02361 PoCEventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Virtual Event Password Disclosure
- CVE-2024-02371 PoCEventON (Free < 2.2.9, Premium <= 4.5.8) - Unauthenticated Virtual Event Settings Update
- CVE-2024-02381 PoCEventON (Free < 2.2.8, Premium < 4.5.6) - Unauthenticated Arbitrary Post Metadata Update
- CVE-2024-02391 PoCContact Form 7 Connector < 1.2.3 - Reflected XSS
- CVE-2024-02431 PoCServer-side Request Forgery In Recursive URL Loader
- CVE-2024-02471 PoCCodeAstro Online Food Ordering System Admin Panel sql injection
- CVE-2024-02481 PoCEazyDocs < 2.4.0 - Subscriber+ Arbitrary Posts Deletion and Document Management
- CVE-2024-02491 PoCAdvanced Schedule Posts <= 2.1.8 - Reflected XSS
- CVE-2024-02502 PoCsAnalytics Insights for Google Analytics 4 < 6.3 - Open Redirect
- CVE-2024-02581 PoCThe issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4,…
- CVE-2024-02601 PoCSourceCodester Engineers Online Portal Password Change change_password_teacher.php session expiration
- CVE-2024-02611 PoCSentex FTPDMIN RNFR Command denial of service
- CVE-2024-02621 PoCOnline Job Portal Create News Page News.php cross site scripting
- CVE-2024-02632 PoCsACME Ultra Mini HTTPd HTTP GET Request denial of service
- CVE-2024-02641 PoCSourceCodester Clinic Queuing System LoginRegistration.php authorization
- CVE-2024-02652 PoCsSourceCodester Clinic Queuing System GET Parameter index.php file inclusion
- CVE-2024-02661 PoCProject Worlds Online Lawyer Management System User Registration cross site scripting
- CVE-2024-02671 PoCKashipara Hospital Management System Parameter login.php sql injection
- CVE-2024-02681 PoCKashipara Hospital Management System registration.php sql injection
- CVE-2024-02701 PoCKashipara Food Management System item_list_submit.php sql injection
- CVE-2024-02711 PoCKashipara Food Management System addmaterial_edit.php sql injection
- CVE-2024-02721 PoCKashipara Food Management System addmaterialsubmit.php sql injection
- CVE-2024-02731 PoCKashipara Food Management System addwaste_entry.php sql injection
- CVE-2024-02741 PoCKashipara Food Management System billAjax.php sql injection
- CVE-2024-02751 PoCKashipara Food Management System item_edit_submit.php sql injection
- CVE-2024-02761 PoCKashipara Food Management System rawstock_used_damaged_smt.php sql injection
- CVE-2024-02771 PoCKashipara Food Management System party_submit.php sql injection
- CVE-2024-02781 PoCKashipara Food Management System partylist_edit_submit.php sql injection
- CVE-2024-02791 PoCKashipara Food Management System item_list_edit.php sql injection
- CVE-2024-02801 PoCKashipara Food Management System item_type_submit.php sql injection
- CVE-2024-02811 PoCKashipara Food Management System loginCheck.php sql injection
- CVE-2024-02821 PoCKashipara Food Management System addmaterialsubmit.php cross site scripting
- CVE-2024-02831 PoCKashipara Food Management System party_details.php cross site scripting
- CVE-2024-02841 PoCKashipara Food Management System party_submit.php cross site scripting
- CVE-2024-02861 PoCPHPGurukul Hospital Management System Contact Form index.php#contact_us cross site scripting
- CVE-2024-02871 PoCKashipara Food Management System itemBillPdf.php sql injection
- CVE-2024-02881 PoCKashipara Food Management System rawstock_used_damaged_submit.php sql injection
- CVE-2024-02891 PoCKashipara Food Management System stock_entry_submit.php sql injection
- CVE-2024-02901 PoCKashipara Food Management System stock_edit.php sql injection
- CVE-2024-02911 PoCTotolink LR1200GB cstecgi.cgi UploadFirmwareFile command injection
- CVE-2024-02921 PoCTotolink LR1200GB cstecgi.cgi setOpModeCfg os command injection
- CVE-2024-02931 PoCTotolink LR1200GB cstecgi.cgi setUploadSetting os command injection
- CVE-2024-02941 PoCTotolink LR1200GB cstecgi.cgi setUssd os command injection
- CVE-2024-02951 PoCTotolink LR1200GB cstecgi.cgi setWanCfg os command injection
- CVE-2024-02961 PoCTotolink N200RE cstecgi.cgi NTPSyncWithHost os command injection
- CVE-2024-02971 PoCTotolink N200RE cstecgi.cgi UploadFirmwareFile os command injection
- CVE-2024-02981 PoCTotolink N200RE cstecgi.cgi setDiagnosisCfg os command injection
- CVE-2024-02991 PoCTotolink N200RE cstecgi.cgi setTracerouteCfg os command injection
- CVE-2024-03001 PoCByzoro Smart S150 Management Platform HTTP POST Request userattestation.php unrestricted upload
- CVE-2024-03011 PoCfhs-opensource iparking PayTempOrderAction.java getData sql injection
- CVE-2024-03021 PoCfhs-opensource iparking vueLogin deserialization
- CVE-2024-03031 PoCYouke365 Parameter caiji.php server-side request forgery
- CVE-2024-03041 PoCYouke365 collect.php server-side request forgery
- CVE-2024-03054 PoCsGuangzhou Yingke Electronic Technology Ncast Guest Login IPSetup.php information disclosure
- CVE-2024-03061 PoCKashipara Dynamic Lab Management System admin_login_process.php sql injection
- CVE-2024-03071 PoCKashipara Dynamic Lab Management System login_process.php sql injection
- CVE-2024-03081 PoCInis Proxy.php server-side request forgery
- CVE-2024-03111 PoCA malicious insider can bypass the existing policy of Skyhigh Client Proxy without a valid release code.
- CVE-2024-03211 PoCStack-based Buffer Overflow in gpac/gpac
- CVE-2024-03241 PoCUser Profile Builder <= 3.10.8 - Missing Authorization to Plugin Settings Change via wppb_two_factor_authentication_settings_update
- CVE-2024-03372 PoCsTravelpayouts <= 1.1.15 - Open Redirect
- CVE-2024-03411 PoCInis GET Request File.php path traversal
- CVE-2024-03421 PoCInis Sqlite.php sql injection
- CVE-2024-03431 PoCCodeAstro Simple House Rental System Login Panel cross site scripting
- CVE-2024-03441 PoCsoxft TimeMail check.php sql injection
- CVE-2024-03451 PoCCodeAstro Vehicle Booking System User Registration usr-register.php cross site scripting
- CVE-2024-03461 PoCCodeAstro Vehicle Booking System Feedback Page user-give-feedback.php cross site scripting
- CVE-2024-03471 PoCSourceCodester Engineers Online Portal signup_teacher.php weak password
- CVE-2024-03481 PoCSourceCodester Engineers Online Portal File Upload resource consumption
- CVE-2024-03491 PoCSourceCodester Engineers Online Portal missing secure attribute
- CVE-2024-03501 PoCSourceCodester Engineers Online Portal session expiration
- CVE-2024-03511 PoCSourceCodester Engineers Online Portal session fixiation
- CVE-2024-03524 PoCsLikeshop HTTP POST Request File.php userFormImage unrestricted upload
- CVE-2024-03532 PoCsLocal privilege escalation in Windows products
- CVE-2024-03541 PoCunknown-o download-station index.php path traversal
- CVE-2024-03551 PoCPHPGurukul Dairy Farm Shop Management System add-category.php sql injection
- CVE-2024-03561 PoCMandelo ssm_shiro_blog Backend updateRoles access control
- CVE-2024-03571 PoCcoderd-repos Eva HTTP POST Request page sql injection
- CVE-2024-03581 PoCDeShang DSO2O install.php access control
- CVE-2024-03591 PoCcode-projects Simple Online Hotel Reservation System login.php sql injection
- CVE-2024-03601 PoCPHPGurukul Hospital Management System edit-doctor-specialization.php sql injection
- CVE-2024-03611 PoCPHPGurukul Hospital Management System contact.php sql injection
- CVE-2024-03621 PoCPHPGurukul Hospital Management System change-password.php sql injection
- CVE-2024-03631 PoCPHPGurukul Hospital Management System patient-search.php sql injection
- CVE-2024-03641 PoCPHPGurukul Hospital Management System query-details.php sql injection
- CVE-2024-03651 PoCFancy Product Designer < 6.1.5 - Admin+ SQL Injection
- CVE-2024-03681 PoCHustle <= 7.8.3 - Sensitive Information Exposure via Exposed Hubspot API Keys
- CVE-2024-03791 PoCCustom Twitter Feeds – A Tweets Widget or X Feed Widget <= 2.2.1 - Cross-Site Request Forgery to Plugin Options Update
- CVE-2024-03891 PoCSourceCodester Student Attendance System attendance_report.php sql injection
- CVE-2024-03993 PoCsWooCommerce Customers Manager < 29.7 - Subscriber+ SQL Injection
- CVE-2024-04021 PoCImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
- CVE-2024-04061 PoCMholt/archiver: path traversal vulnerability
- CVE-2024-04101 PoCImproper Enforcement of Behavioral Workflow in GitLab
- CVE-2024-04111 PoCDeShang DSMall HTTP GET Request install.php access control
- CVE-2024-04121 PoCDeShang DSShop HTTP GET Request install.php access control
- CVE-2024-04131 PoCDeShang DSKMS install.php access control
- CVE-2024-04141 PoCDeShang DSCMS install.php access control
- CVE-2024-04151 PoCDeShang DSMall Image URL TaobaoExport.php access control
- CVE-2024-04161 PoCDeShang DSMall MemberAuth.php path traversal
- CVE-2024-04171 PoCDeShang DSShop MemberAuth.php path traversal
- CVE-2024-04182 PoCsiSharer and upRedSun File Sharing Wizard GET Request denial of service
- CVE-2024-04191 PoCJasper httpdx HTTP POST Request denial of service
- CVE-2024-04201 PoCMapPress Maps for WordPress < 2.88.15 - Contributor+ Stored XSS
- CVE-2024-04211 PoCMapPress Maps for WordPress < 2.88.16 - Unauthenticated Arbitrary Private/Draft Post Disclosure
- CVE-2024-04221 PoCCodeAstro POS and Inventory Management System New Item Creation Page new_item cross site scripting
- CVE-2024-04231 PoCCodeAstro Online Food Ordering System dishes.php cross site scripting
- CVE-2024-04241 PoCCodeAstro Simple Banking System Create a User Page createuser.php cross site scripting
- CVE-2024-04251 PoCForU CMS password recovery
- CVE-2024-04261 PoCForU CMS cms_template.php sql injection
- CVE-2024-04271 PoCArforms < 6.4.1 - Reflected XSS
- CVE-2024-04591 PoCBlood Bank & Donor Management request-received-bydonar.php sql injection
- CVE-2024-04601 PoCcode-projects Faculty Management System student-print.php sql injection
- CVE-2024-04611 PoCcode-projects Online Faculty Clearance HTTP POST Request deactivate.php sql injection
- CVE-2024-04621 PoCcode-projects Online Faculty Clearance HTTP POST Request designee_view_status.php sql injection
- CVE-2024-04631 PoCcode-projects Online Faculty Clearance HTTP POST Request admin_view_info.php sql injection
- CVE-2024-04641 PoCcode-projects Online Faculty Clearance HTTP GET Request delete_faculty.php sql injection
- CVE-2024-04651 PoCcode-projects Employee Profile Management System download.php path traversal
- CVE-2024-04661 PoCcode-projects Employee Profile Management System file_table.php sql injection
- CVE-2024-04671 PoCcode-projects Employee Profile Management System edit_position_query.php cross site scripting
- CVE-2024-04681 PoCcode-projects Fighting Cock Information System new-father.php unrestricted upload
- CVE-2024-04691 PoCcode-projects Human Resource Integrated System update_personal_info.php sql injection
- CVE-2024-04701 PoCcode-projects Human Resource Integrated System inc_service_credits.php sql injection
- CVE-2024-04711 PoCcode-projects Human Resource Integrated System dec_service_credits.php sql injection
- CVE-2024-04721 PoCcode-projects Dormitory Management System modifyuser.php information disclosure
- CVE-2024-04731 PoCcode-projects Dormitory Management System comment.php sql injection
- CVE-2024-04741 PoCcode-projects Dormitory Management System login.php sql injection
- CVE-2024-04751 PoCcode-projects Dormitory Management System modifyuser.php sql injection
- CVE-2024-04761 PoCBlood Bank & Donor Management request-received-bydonar.php cross site scripting
- CVE-2024-04771 PoCcode-projects Fighting Cock Information System update-deworm.php sql injection
- CVE-2024-04781 PoCcode-projects Fighting Cock Information System edit_chicken.php sql injection
- CVE-2024-04791 PoCTaokeyun HTTP POST Request User.php login sql injection
- CVE-2024-04801 PoCTaokeyun HTTP POST Request Drs.php index sql injection
- CVE-2024-04811 PoCTaokeyun HTTP POST Request Goods.php shopGoods sql injection
- CVE-2024-04821 PoCTaokeyun HTTP POST Request Video.php index sql injection
- CVE-2024-04831 PoCTaokeyun HTTP POST Request Task.php index sql injection
- CVE-2024-04841 PoCcode-projects Fighting Cock Information System update_mother.php sql injection
- CVE-2024-04851 PoCcode-projects Fighting Cock Information System add_con.php sql injection
- CVE-2024-04861 PoCcode-projects Fighting Cock Information System add_con.php sql injection
- CVE-2024-04871 PoCcode-projects Fighting Cock Information System delete-vaccine.php sql injection
- CVE-2024-04881 PoCcode-projects Fighting Cock Information System new-feed.php sql injection
- CVE-2024-04891 PoCcode-projects Fighting Cock Information System edit_chicken.php sql injection
- CVE-2024-04901 PoCHuaxia ERP getAllList information disclosure
- CVE-2024-04921 PoCKashipara Billing Software HTTP POST Request buyer_detail_submit.php sql injection
- CVE-2024-04931 PoCKashipara Billing Software HTTP POST Request submit_delivery_list.php sql injection
- CVE-2024-04941 PoCKashipara Billing Software HTTP POST Request material_bill.php sql injection
- CVE-2024-04951 PoCKashipara Billing Software HTTP POST Request party_submit.php sql injection
- CVE-2024-04961 PoCKashipara Billing Software HTTP POST Request item_list_edit.php sql injection
- CVE-2024-04971 PoCCampcodes Student Information System sql injection
- CVE-2024-04981 PoCProject Worlds Lawyer Management System searchLawyer.php sql injection
- CVE-2024-04991 PoCSourceCodester House Rental Management System index.php cross site scripting
- CVE-2024-05001 PoCSourceCodester House Rental Management System Manage Tenant Details cross site scripting
- CVE-2024-05011 PoCSourceCodester House Rental Management System Manage Invoice Details cross site scripting
- CVE-2024-05021 PoCSourceCodester House Rental Management System Edit User manage_user.php sql injection
- CVE-2024-05031 PoCcode-projects Online FIR System registercomplaint.php cross site scripting
- CVE-2024-05041 PoCcode-projects Simple Online Hotel Reservation System Make a Reservation Page add_reserve.php cross site scripting
- CVE-2024-05051 PoCZhongFuCheng3y Austin Upload Material Menu MaterialController.java getFile unrestricted upload
- CVE-2024-05071 PoCPrivilege Escalation by Code Injection in the Management Console in GitHub Enterprise Server
- CVE-2024-05091 PoCWP 404 Auto Redirect to Similar Post <= 1.0.3 - Reflected Cross-Site Scripting via request
- CVE-2024-05101 PoCHaoKeKeJi YiQiNiu Api.php http_post server-side request forgery
- CVE-2024-05171 PoCOut of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2024-05201 PoCRemote Code Execution due to Full Controlled File Write in mlflow/mlflow
- CVE-2024-05211 PoCCode Injection in paddlepaddle/paddle
- CVE-2024-05231 PoCCmsEasy language_admin.php getslide_child_action sql injection
- CVE-2024-05241 PoCCXBSoft Url-shorting index.php sql injection
- CVE-2024-05251 PoCCXBSoft Url-shorting HTTP POST Request long_s_short.php sql injection
- CVE-2024-05261 PoCCXBSoft Url-shorting HTTP POST Request short_to_long.php sql injection
- CVE-2024-05271 PoCCXBSoft Url-shorting HTTP POST Request update_go.php sql injection
- CVE-2024-05281 PoCCXBSoft Post-Office HTTP POST Request update_go.php sql injection
- CVE-2024-05291 PoCCXBSoft Post-Office HTTP POST Request login_auth.php sql injection
- CVE-2024-05301 PoCCXBSoft Post-Office HTTP POST Request reg_go.php sql injection
- CVE-2024-05311 PoCTenda A15 Web-based Management Interface setBlackRule stack-based overflow
- CVE-2024-05321 PoCTenda A15 Web-based Management Interface WifiExtraSet set_repeat5 stack-based overflow
- CVE-2024-05331 PoCTenda A15 Web-based Management Interface SetOnlineDevName stack-based overflow
- CVE-2024-05341 PoCTenda A15 Web-based Management Interface SetOnlineDevName stack-based overflow
- CVE-2024-05351 PoCTenda PA6 httpd portmap cgiPortMapAdd stack-based overflow
- CVE-2024-05361 PoCTenda W9 httpd setWrlAccessList stack-based overflow
- CVE-2024-05371 PoCTenda W9 httpd setWrlBasicInfo stack-based overflow
- CVE-2024-05381 PoCTenda W9 httpd formQosManage_auto stack-based overflow
- CVE-2024-05391 PoCTenda W9 httpd formQosManage_user stack-based overflow
- CVE-2024-05401 PoCTenda W9 httpd formOfflineSet stack-based overflow
- CVE-2024-05411 PoCTenda W9 httpd formAddSysLogRule stack-based overflow
- CVE-2024-05421 PoCTenda W9 httpd formWifiMacFilterGet stack-based overflow
- CVE-2024-05431 PoCCodeAstro Real Estate Management System propertydetail.php sql injection
- CVE-2024-05462 PoCsEasyFTP LIST Command denial of service
- CVE-2024-05471 PoCAbility FTP Server APPE Command denial of service
- CVE-2024-05481 PoCFreeFloat FTP Server SIZE Command denial of service
- CVE-2024-05501 PoCPrivileged User using traversal to read system files
- CVE-2024-05571 PoCDedeBIZ Website Copyright Setting cross site scripting
- CVE-2024-05581 PoCDedeBIZ makehtml_freelist_action.php sql injection
- CVE-2024-05592 PoCsEnhanced Text Widget < 1.6.6 - Admin+ Stored XSS
- CVE-2024-05611 PoCUltimate Posts Widget < 2.3.1 - Admin+ Stored XSS
- CVE-2024-05663 PoCsSmart Manager < 8.28.0 - Admin+ SQL Injection
- CVE-2024-05691 PoCTotolink T8 Setting cstecgi.cgi getSysStatusCfg information disclosure
- CVE-2024-05711 PoCTotolink LR1200GB cstecgi.cgi setSmsCfg stack-based overflow
- CVE-2024-05721 PoCTotolink LR1200GB cstecgi.cgi setOpModeCfg stack-based overflow
- CVE-2024-05731 PoCTotolink LR1200GB cstecgi.cgi setDiagnosisCfg stack-based overflow
- CVE-2024-05741 PoCTotolink LR1200GB cstecgi.cgi setParentalRules stack-based overflow
- CVE-2024-05751 PoCTotolink LR1200GB cstecgi.cgi setTracerouteCfg stack-based overflow
- CVE-2024-05761 PoCTotolink LR1200GB cstecgi.cgi setIpPortFilterRules stack-based overflow
- CVE-2024-05771 PoCTotolink LR1200GB cstecgi.cgi setLanguageCfg stack-based overflow
- CVE-2024-05781 PoCTotolink LR1200GB cstecgi.cgi UploadCustomModule stack-based overflow
- CVE-2024-05791 PoCTotolink X2000R formMapDelDevice command injection
- CVE-2024-058211 PoCsKernel: io_uring: page use-after-free vulnerability via buffer ring mmap
- CVE-2024-05881 PoCPaid Memberships Pro <= 2.12.10 - Cross-Site Request Forgery
- CVE-2024-05901 PoCMicrosoft Clarity <= 0.9.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting
- CVE-2024-05931 PoCSimple Job Board <= 2.10.8 - Missing Authorization to Unauthenticated Information Disclosure
- CVE-2024-05991 PoCJspxcms Document Management Page InfoController.java cross site scripting
- CVE-2024-06011 PoCZhongFuCheng3y Austin Email Message Template AustinFileUtils.java getRemoteUrl2File server-side request forgery
- CVE-2024-06031 PoCZhiCms giftcontroller.php deserialization
- CVE-2024-06231 PoCVK Block Patterns <= 1.31.1.1 - Cross-Site Request Forgery
- CVE-2024-06241 PoCPaid Memberships Pro <= 2.12.7 - Cross-Site Request Forgery to Level Orders Update
- CVE-2024-06481 PoCYunyou CMS Common.php unrestricted upload
- CVE-2024-06491 PoCZhiHuiYun Search ImageController.php download_network_image server-side request forgery
- CVE-2024-06501 PoCProject Worlds Visitor Management System URL dataset.php cross site scripting
- CVE-2024-06511 PoCPHPGurukul Company Visitor Management System search-visitor.php sql injection
- CVE-2024-06521 PoCPHPGurukul Company Visitor Management System search-visitor.php cross site scripting
- CVE-2024-06541 PoCDeepFaceLab Util.py deserialization
- CVE-2024-06551 PoCNovel-Plus list sql injection
- CVE-2024-06705 PoCsPrivilege escalation in windows agent
- CVE-2024-06721 PoCPz-LinkCard <= 2.5.1 - Reflected XSS
- CVE-2024-06731 PoCPz-LinkCard <= 2.5.1 - Admin+ Stored XSS
- CVE-2024-06771 PoCPz-LinkCard <= 2.5.1 - Contributor+ SSRF
- CVE-2024-06791 PoCColorMag <= 3.1.2 - Missing Authorization to Arbitrary Plugin Installation
- CVE-2024-06831 PoCBulgarisation for WooCommerce <= 3.0.14 - Missing Authorization
- CVE-2024-06841 PoCCoreutils: heap overflow in split --line-bytes with very long lines
- CVE-2024-06922 PoCsSolarWinds Security Event Manager Deserialization of Untrusted Data Remote Code Execution Vulnerability
- CVE-2024-06933 PoCsEFS Easy File Sharing FTP denial of service
- CVE-2024-06953 PoCsEFS Easy Chat Server HTTP GET Request denial of service
- CVE-2024-06961 PoCAtroCore AtroPIM Product Series Overview cross site scripting
- CVE-2024-07001 PoCSimple Tweet <= 1.4.0.2 - Authenticated (Author+) Stored Cross-Site Scripting
- CVE-2024-07051 PoCStripe Payment Plugin for WooCommerce <= 3.7.9 - Unauthenticated SQL Injection
- CVE-2024-07101 PoCGP Unique ID <= 1.5.5 - Unauthenticated Form Submission Unique ID Modification
- CVE-2024-07111 PoCButtons Shortcode and Widget <= 1.16 - Stored XSS via shortcode
- CVE-2024-07121 PoCByzoro Smart S150 Management Platform userattea.php access control
- CVE-2024-07161 PoCByzoro Smart S150 Management Platform Backup File download.php information disclosure
- CVE-2024-07171 PoCD-Link Good Line Router v2 HTTP GET Request devinfo information disclosure
- CVE-2024-07181 PoCliuwy-dlsdys zhglxt HTTP POST Request edit cross site scripting
- CVE-2024-07191 PoCTabs Shortcode and Widget <= 1.17 - Contributor+ Stored Cross-Site Scripting
- CVE-2024-07201 PoCFactoMineR FactoInvestigate HTML Report Generator cross site scripting
- CVE-2024-07211 PoCJspxcms Survey Label cross site scripting
- CVE-2024-07221 PoCcode-projects Social Networking Site Message Page message.php cross site scripting
- CVE-2024-07232 PoCsfreeSSHd denial of service
- CVE-2024-07252 PoCsProSSHD denial of service
- CVE-2024-07261 PoCProject Worlds Student Project Allocation System Admin Login Module admin_login.php cross site scripting
- CVE-2024-07281 PoCForU CMS channel.php file inclusion
- CVE-2024-07291 PoCForU CMS cms_admin.php sql injection
- CVE-2024-07301 PoCProject Worlds Online Time Table Generator course_ajax.php sql injection
- CVE-2024-07311 PoCPCMan FTP Server PUT Command denial of service
- CVE-2024-07321 PoCPCMan FTP Server STOR Command denial of service
- CVE-2024-07331 PoCSmsot HTTP POST Request api.php sql injection
- CVE-2024-07341 PoCSmsot get.php sql injection
- CVE-2024-07351 PoCSourceCodester Online Tours & Travels Management System expense.php exec sql injection
- CVE-2024-07361 PoCEFS Easy File Sharing FTP Login denial of service
- CVE-2024-07372 PoCsXlightftpd Xlight FTP Server Login denial of service
- CVE-2024-07381 PoC个人开源 mldong DecisionModel.java ExpressionEngine code injection
- CVE-2024-07391 PoCHecheng Leadshop leadshop.php deserialization
- CVE-2024-07411 PoCAn out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This…
- CVE-2024-07561 PoCInsert or Embed Articulate Content into WordPress <= 4.3000000023 - Iframe Injection
- CVE-2024-07572 PoCsInsert or Embed Articulate Content into WordPress <= 4.3000000023 - Author+ Upload to RCE
- CVE-2024-07601 PoCA flood of DNS messages over TCP may make the server unstable
- CVE-2024-07621 PoCPotential buffer overflow when handling UEFI variables
- CVE-2024-07651 PoCDefault user role exporting save state of instance
- CVE-2024-07691 PoCKEVD-Link DIR-859 HTTP POST Request hedwig.cgi path traversal
- CVE-2024-07711 PoCNsasoft Product Key Explorer Registration memory corruption
- CVE-2024-07721 PoCNsasoft ShareAlarmPro Registration memory corruption
- CVE-2024-07731 PoCCodeAstro Internet Banking System pages_client_signup.php cross site scripting
- CVE-2024-07741 PoCAny-Capture Any Sound Recorder Registration memory corruption
- CVE-2024-07761 PoCLinZhaoguan pb-cms Comment cross site scripting
- CVE-2024-07781 PoCUniview ISC 2500-S VM.php setNatConfig os command injection
- CVE-2024-07791 PoCEnjoy Social Feed <= 6.2.2 - Unauthenticated Arbitrary Instagram Account Unlinking
- CVE-2024-07801 PoCEnjoy Social Feed <= 6.2.2 - Subscriber+ Plugin Database Reset
- CVE-2024-07811 PoCCodeAstro Internet Banking System pages_client_signup.php redirect
- CVE-2024-07821 PoCCodeAstro Online Railway Reservation System pass-profile.php cross site scripting
- CVE-2024-07832 PoCsProject Worlds Online Admission System documents.php unrestricted upload
- CVE-2024-07841 PoChongmaple octopus list sql injection
- CVE-2024-07951 PoCCreate user API role not enforced
- CVE-2024-07992 PoCsAuthentication Bypass via wizardLogin in Arcserve Unified Data Protection
- CVE-2024-08001 PoCAuthentication Bypass via wizardLogin in Arcserve Unified Data Protection
- CVE-2024-08012 PoCsUnauthenticated DoS in Arcserve Unified Data Protection
- CVE-2024-08151 PoCCommand injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0
- CVE-2024-08171 PoCCommand injection in IrGraph.draw in paddlepaddle/paddle 2.6.0
- CVE-2024-08181 PoCArbitrary File Overwrite Via Path Traversal in paddlepaddle/paddle before 2.6
- CVE-2024-08201 PoCJobs for WordPress < 2.7.4 - Contributor+ Stored XSS
- CVE-2024-08521 PoCcoreActivity < 1.8.1 - Unauthenticated Stored XSS
- CVE-2024-08551 PoCSpiffy Calendar < 4.9.9 - Broken Access Control
- CVE-2024-08561 PoCBooking Calendar < 1.3.83 - CSRF appointment scheduling
- CVE-2024-08581 PoCInnovs HR <= 1.0.3.4 - Employee Creation via CSRF
- CVE-2024-08611 PoCDirect Request ('Forced Browsing') in GitLab
- CVE-2024-08681 PoCcoreActivity < 2.1 - Unauthenticated IP Spoofing
- CVE-2024-08801 PoCQidianbang qdbcrm Password Reset cross-site request forgery
- CVE-2024-08812 PoCsCombo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Access
- CVE-2024-08821 PoCqwdigital LinkWechat Universal Download Interface resource path traversal
- CVE-2024-08831 PoCSourceCodester Online Tours & Travels Management System pay.php prepare sql injection
- CVE-2024-08841 PoCSourceCodester Online Tours & Travels Management System payment.php exec sql injection
- CVE-2024-08851 PoCSpyCamLizard HTTP GET Request denial of service
- CVE-2024-08861 PoCPoikosoft EZ CD Audio Converter Activation denial of service
- CVE-2024-08871 PoCMafiatic Blue Server Connection denial of service
- CVE-2024-08881 PoCBORGChat Service Port 7551 denial of service
- CVE-2024-08891 PoCKmint21 Golden FTP Server PASV Command denial of service
- CVE-2024-08901 PoChongmaple octopus edit sql injection
- CVE-2024-08911 PoChongmaple octopus cross site scripting
- CVE-2024-09021 PoCFancy Product Designer < 6.1.81 - Admin+ Cross Site Scripting via Product Title
- CVE-2024-09041 PoCFancy Product Designer < 6.1.81 - Admin+ Cross Site Scripting
- CVE-2024-09051 PoCFancy Product Designer < 6.1.8 - Reflected Cross Site Scripting
- CVE-2024-09171 PoCremote code execution in paddlepaddle/paddle 2.6.0
- CVE-2024-09181 PoCTRENDnet TEW-800MB POST Request os command injection
- CVE-2024-09191 PoCTRENDnet TEW-815DAP POST Request do_setNTP command injection
- CVE-2024-09201 PoCTRENDnet TEW-822DRE POST Request admin_ping.htm command injection
- CVE-2024-09211 PoCD-Link DIR-816 A2 Web Interface setDeviceSettings os command injection
- CVE-2024-09221 PoCTenda AC10U formQuickIndex stack-based overflow
- CVE-2024-09231 PoCTenda AC10U formSetDeviceName stack-based overflow
- CVE-2024-09241 PoCTenda AC10U formSetPPTPServer stack-based overflow
- CVE-2024-09251 PoCTenda AC10U formSetVirtualSer stack-based overflow
- CVE-2024-09261 PoCTenda AC10U formWifiWpsOOB stack-based overflow
- CVE-2024-09271 PoCTenda AC10U fromAddressNat stack-based overflow
- CVE-2024-09281 PoCTenda AC10U fromDhcpListClient stack-based overflow
- CVE-2024-09291 PoCTenda AC10U fromNatStaticSetting stack-based overflow
- CVE-2024-09301 PoCTenda AC10U fromSetWirelessRepeat stack-based overflow
- CVE-2024-09311 PoCTenda AC10U saveParentControlInfo stack-based overflow
- CVE-2024-09321 PoCTenda AC10U setSmartPowerManagement stack-based overflow
- CVE-2024-09331 PoCNiushop B2B2C Upload.php unrestricted upload
- CVE-2024-09361 PoCvan_der_Schaar LAB TemporAI PKL File load_from_file deserialization
- CVE-2024-09371 PoCvan_der_Schaar LAB synthcity PKL File load_from_file deserialization
- CVE-2024-09381 PoCTongda OA 2017 delete_webmail.php sql injection
- CVE-2024-09393 PoCsByzoro Smart S210 Management Platform uploadfile.php unrestricted upload
- CVE-2024-09411 PoCNovel-Plus list sql injection
- CVE-2024-09421 PoCTotolink N200RE V5 cstecgi.cgi session expiration
- CVE-2024-09431 PoCTotolink N350RT cstecgi.cgi session expiration
- CVE-2024-09442 PoCsTotolink T8 cstecgi.cgi session expiration
- CVE-2024-09451 PoC60IndexPage Parameter file.php server-side request forgery
- CVE-2024-09461 PoC60IndexPage Parameter index.php server-side request forgery
- CVE-2024-09511 PoCAdvanced Social Feeds Widget & Shortcode <= 1.7 - Admin+ Stored XSS
- CVE-2024-09531 PoCWhen a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the…
- CVE-2024-09581 PoCCodeAstro Stock Management System Add Category index.php cross site scripting
- CVE-2024-09591 PoCStanfordVL GibsonEnv pposgd_fuse.py cloudpickle.load deserialization
- CVE-2024-09601 PoCflink-extended ai-flow workflow_command.py cloudpickle.loads deserialization
- CVE-2024-09621 PoCobgm libcoap Configuration File coap_oscore.c get_split_entry stack-based overflow
- CVE-2024-09641 PoCLFI in Gradio
- CVE-2024-09701 PoCUser Activity Tracking and Log < 4.1.4 - IP Spoofing
- CVE-2024-09731 PoCWidget for Social Page Feeds < 6.4 - Admin+ Stored XSS
- CVE-2024-09741 PoCSocial Media Widget < 4.0.9 - Admin+ Stored XSS
- CVE-2024-09863 PoCsIssabel PBX Asterisk-Cli os command injection
- CVE-2024-09871 PoCSichuan Yougou Technology KuERP log neutralization for logs
- CVE-2024-09881 PoCSichuan Yougou Technology KuERP common.php checklogin improper authentication
- CVE-2024-09891 PoCSichuan Yougou Technology KuERP Service.php del_sn_db path traversal
- CVE-2024-09901 PoCTenda i6 httpd setAutoPing formSetAutoPing stack-based overflow
- CVE-2024-09911 PoCTenda i6 httpd setcfm formSetCfm stack-based overflow
- CVE-2024-09921 PoCTenda i6 httpd wifiSSIDset formwrlSSIDset stack-based overflow
- CVE-2024-09931 PoCTenda i6 httpd WifiMacFilterGet formWifiMacFilterGet stack-based overflow
- CVE-2024-09941 PoCTenda W6 httpd setcfm formSetCfm stack-based overflow
- CVE-2024-09951 PoCTenda W6 httpd wifiSSIDset formwrlSSIDset stack-based overflow
- CVE-2024-09961 PoCTenda i9 httpd setcfm formSetCfm stack-based overflow
- CVE-2024-09971 PoCTotolink N200RE cstecgi.cgi setOpModeCfg stack-based overflow
- CVE-2024-09981 PoCTotolink N200RE cstecgi.cgi setDiagnosisCfg stack-based overflow
- CVE-2024-09991 PoCTotolink N200RE cstecgi.cgi setParentalRules stack-based overflow