CVE-2024-11000 to CVE-2024-11999
211 CVEs with public proof-of-concept exploits.
- CVE-2024-110001 PoCCodeAstro Real Estate Management System About Us Page aboutedit.php unrestricted upload
- CVE-2024-110031 PoCQualys discovered that needrestart, before version 3.8, passes unsanitized data to a library (Modules::ScanDeps) which expects safe input.…
- CVE-2024-110261 PoCIntelligent Apps Freenow App Keystore SSL.java hard-coded password
- CVE-2024-110421 PoCArbitrary File Delete in invoke-ai/invokeai
- CVE-2024-110441 PoCOpen Redirect in automatic1111/stable-diffusion-webui
- CVE-2024-110461 PoCD-Link DI-8003 upgrade_filter.asp upgrade_filter_asp os command injection
- CVE-2024-110471 PoCD-Link DI-8003 upgrade_filter.asp upgrade_filter_asp stack-based overflow
- CVE-2024-110481 PoCD-Link DI-8003 dbsrv.asp dbsrv_asp stack-based overflow
- CVE-2024-110491 PoCZKTeco ZKBio Time Image File photo direct request
- CVE-2024-110501 PoCAMTT Hotel Broadband Operation System language.php cross site scripting
- CVE-2024-110511 PoCAMTT Hotel Broadband Operation System online_status.php sql injection
- CVE-2024-110541 PoCSourceCodester Simple Music Cloud Community System ajax.php unrestricted upload
- CVE-2024-110551 PoC1000 Projects Beauty Parlour Management System admin-profile.php sql injection
- CVE-2024-110561 PoCTenda AC10 WifiExtraSet FUN_0046AC38 stack-based overflow
- CVE-2024-110571 PoCCodezips Hospital Appointment System removeBranchResult.php sql injection
- CVE-2024-110581 PoCCodeAstro Real Estate Management System About Us Page aboutedit.php sql injection
- CVE-2024-110591 PoCProject Worlds Free Download Online Shopping System success.php sql injection
- CVE-2024-110601 PoCJinher Network Collaborative Management Platform 金和数字化智能办公平台 AcceptShow.aspx sql injection
- CVE-2024-110611 PoCTenda AC10 fast_setting_wifi_set FUN_0044db3c stack-based overflow
- CVE-2024-110701 PoCSanluan PublicCMS Tag Type save cross site scripting
- CVE-2024-110733 PoCsSourceCodester Hospital Management System delete-account.php improper authorization
- CVE-2024-110741 PoCitsourcecode Tailoring Management System incadd.php sql injection
- CVE-2024-110761 PoCcode-projects Job Recruitment activation.php sql injection
- CVE-2024-110771 PoCcode-projects Job Recruitment index.php sql injection
- CVE-2024-110781 PoCcode-projects Job Recruitment register.php cross site scripting
- CVE-2024-110961 PoCcode-projects Task Manager newProject.php sql injection
- CVE-2024-110971 PoCSourceCodester Student Record Management System Main Menu infinite loop
- CVE-2024-110991 PoCcode-projects Job Recruitment login.php sql injection
- CVE-2024-111001 PoC1000 Projects Beauty Parlour Management System index.php sql injection
- CVE-2024-111011 PoC1000 Projects Beauty Parlour Management System search-invoices.php sql injection
- CVE-2024-111022 PoCsSourceCodester Hospital Management System edit-doc.php cross site scripting
- CVE-2024-111071 PoCSystem Dashboard < 2.8.15 - Unauthenticated Stored XSS
- CVE-2024-111081 PoCSerious Slider < 1.2.7 - Contributor+ Stored XSS via Shortcode
- CVE-2024-111091 PoCWP Google Review Slider < 15.6 - Admin+ Stored XSS
- CVE-2024-111111 PoCInappropriate implementation in Autofill in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage…
- CVE-2024-111141 PoCInappropriate implementation in Views in Google Chrome on Windows prior to 131.0.6778.69 allowed a remote attacker who had compromised the…
- CVE-2024-111201 PoCKEVGeoVision EOL devices - OS Command Injection
- CVE-2024-111211 PoC上海灵当信息科技有限公司 Lingdang CRM index.php sql injection
- CVE-2024-111221 PoC上海灵当信息科技有限公司 Lingdang CRM index.php unrestricted upload
- CVE-2024-111231 PoC上海灵当信息科技有限公司 Lingdang CRM pdf.php path traversal
- CVE-2024-111241 PoCTimGeyssens UIOMatic uioMaticObject.r sql injection
- CVE-2024-111251 PoCGetSimpleCMS profile.php cross-site request forgery
- CVE-2024-111271 PoCcode-projects Job Recruitment admin.php sql injection
- CVE-2024-111291 PoCGeneration of Error Message Containing Sensitive Information in GitLab
- CVE-2024-111301 PoCZZCMS msg.php cross site scripting
- CVE-2024-111381 PoCDedeCMS friendlink_add.php unrestricted upload
- CVE-2024-111401 PoCReal WP Shop Lite Ajax eCommerce Shopping Cart <= 2.0.8 - Admin+ Stored XSS
- CVE-2024-111411 PoCSailthru Triggermail < 1.1 - Subscriber+ Stored XSS
- CVE-2024-111751 PoCPublic CMS Voting Management save cross site scripting
- CVE-2024-111831 PoCSimple Side Tab < 2.2.0 - Admin+ Stored XSS
- CVE-2024-111841 PoCWP Enabled SVG <= 0.7 - Author+ Stored XSS via SVG
- CVE-2024-111891 PoCSocial Share And Social Locker – ARSocial < 1.4.2 - Admin+ Stored XSS
- CVE-2024-111901 PoCjwp-a11y <= 4.1.7 - Admin+ Stored XSS
- CVE-2024-112011 PoCmyCred – Loyalty Points and Rewards plugin <= 2.7.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via mycred_send Shortcode
- CVE-2024-112071 PoCApereo CAS login redirect
- CVE-2024-112082 PoCsApereo CAS login session expiration
- CVE-2024-112091 PoCApereo CAS 2FA login improper authentication
- CVE-2024-112101 PoCEyouCMS FilemanagerLogic.php editFile path traversal
- CVE-2024-112111 PoCEyouCMS Website Logo unrestricted upload
- CVE-2024-112121 PoCSourceCodester Best Employee Management System fetch_product_details.php sql injection
- CVE-2024-112131 PoCSourceCodester Best Employee Management System edit_role.php sql injection
- CVE-2024-112141 PoCSourceCodester Best Employee Management System profile.php unrestricted upload
- CVE-2024-112211 PoCFull Screen (Page) Background Image Slideshow <= 1.1 - Admin+ Stored XSS
- CVE-2024-112231 PoCWPForms < 1.9.2.3 - Admin+ Stored XSS
- CVE-2024-112331 PoCSingle byte overread with convert.quoted-printable-decode filter
- CVE-2024-112341 PoCConfiguring a proxy in a stream context might allow for CRLF injection in URIs
- CVE-2024-112351 PoCReference counting in php_request_shutdown causes Use-After-Free
- CVE-2024-112372 PoCsTP-Link VN020 F3v(T) DHCP DISCOVER Packet Parser TP-Thumper stack-based overflow
- CVE-2024-112382 PoCsLandray EKP sysUiComponent.do delPreviewFile path traversal
- CVE-2024-112391 PoCLandray EKP API Interface import.do deleteFile path traversal
- CVE-2024-112401 PoCIBPhoenix ibWebAdmin Banco de Dados Tab database.php cross site scripting
- CVE-2024-112411 PoCcode-projects Job Recruitment reset.php sql injection
- CVE-2024-112421 PoCZZCMS Keyword Filtering ad_list.php sql injection
- CVE-2024-112431 PoCcode-projects Online Shop Store signup.php cross site scripting
- CVE-2024-112441 PoCcode-projects Farmacia editar-cliente.php sql injection
- CVE-2024-112451 PoCcode-projects Farmacia editar-produto.php sql injection
- CVE-2024-112461 PoCcode-projects Farmacia adicionar-cliente.php cross site scripting
- CVE-2024-112471 PoCSourceCodester Online Eyewear Shop Inventory Page Master.php cross site scripting
- CVE-2024-112481 PoCTenda AC10 SetSysAutoRebbotCfg formSetRebootTimer stack-based overflow
- CVE-2024-112501 PoCcode-projects Inventory Management editProduct.php sql injection
- CVE-2024-112511 PoCerzhongxmu Jeewms AuthInterceptor cgReportController.do sql injection
- CVE-2024-112521 PoCSocial Sharing Plugin – Sassy Social Share <= 3.3.69 - Reflected Cross-Site Scripting via heateor_mastodon_share Parameter
- CVE-2024-112561 PoC1000 Projects Portfolio Management System MCA login.php sql injection
- CVE-2024-112571 PoC1000 Projects Beauty Parlour Management System forgot-password.php sql injection
- CVE-2024-112581 PoC1000 Projects Beauty Parlour Management System index.php sql injection
- CVE-2024-112591 PoCcode-projects Farmacia fornecedores.php cross site scripting
- CVE-2024-112611 PoCSourceCodester Student Record Management System Number of Students Menu StudentRecordManagementSystem.cpp memory corruption
- CVE-2024-112621 PoCSourceCodester Student Record Management System View All Student Marks main stack-based overflow
- CVE-2024-112661 PoCGeocache Stat Bar Widget <= 0.911 - Admin+ Stored XSS
- CVE-2024-112671 PoCJSP Store Locator <= 1.0 - Contributor+ SQL Injection
- CVE-2024-112691 PoCAHAthat Plugin <= 1.6 - Admin+ SQL Injection
- CVE-2024-112721 PoCContact Form & SMTP Plugin for WordPress by PirateForms < 2.6.0 - Admin+ Stored XSS
- CVE-2024-112731 PoCContact Form & SMTP Plugin for WordPress by PirateForms < 2.6.0 - Admin+ Stored XSS
- CVE-2024-112742 PoCsURL Redirection to Untrusted Site ('Open Redirect') in GitLab
- CVE-2024-113032 PoCsPath Traversal
- CVE-2024-113052 PoCsAltenergy Power Control Software status_zigbee get_status_zigbee sql injection
- CVE-2024-113061 PoCAltenergy Power Control Software database improper authorization
- CVE-2024-113181 PoCIDOR vulnerability in AbsysNet
- CVE-2024-113203 PoCsCommand Injection leading to RCE via LDAP Misconfiguration
- CVE-2024-113561 PoCTourmaster < 5.3.4 - Unauthenticated Stored XSS via Room Booking
- CVE-2024-113571 PoCGoodlayers Core < 2.0.10 - Contributor+ Stored XSS
- CVE-2024-113721 PoCConnexion Logs <= 3.0.2 - Admin+ SQL Injection
- CVE-2024-113731 PoCConnexion Logs <= 3.0.2 - Log Deletion via CSRF
- CVE-2024-113922 PoCsHugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability
- CVE-2024-113931 PoCHugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability
- CVE-2024-113941 PoCHugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability
- CVE-2024-113962 PoCsEvent monster <= 1.4.3 - Information Exposure Via Visitors List Export
- CVE-2024-114231 PoCUltimate Gift Cards for WooCommerce <= 3.0.6 - Missing Authorization to Infinite Money Glitch
- CVE-2024-114671 PoCOmnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successful exploitation of…
- CVE-2024-114881 PoC115cms web_user.html cross site scripting
- CVE-2024-114891 PoC115cms file.html cross site scripting
- CVE-2024-114901 PoC115cms set.html cross site scripting
- CVE-2024-114911 PoC115cms useradmin.html cross site scripting
- CVE-2024-114921 PoC115cms appurladd.html cross site scripting
- CVE-2024-114932 PoCs115cms pageAE.html cross site scripting
- CVE-2024-115021 PoCPlanning Center Online Giving <= 1.0.0 - Contributor+ XSS via Shortcode
- CVE-2024-115031 PoCWP Tabs < 2.2.7 - Admin+ Stored XSS
- CVE-2024-115872 PoCsidcCMS classProvCity.php GetCityOptionJs cross site scripting
- CVE-2024-115891 PoCitsourcecode Tailoring Management System expcatedit.php sql injection
- CVE-2024-115901 PoC1000 Projects Bookstore Management System forget_password_process.php sql injection
- CVE-2024-115911 PoC1000 Projects Beauty Parlour Management System add-services.php sql injection
- CVE-2024-115921 PoC1000 Projects Beauty Parlour Management System about-us.php sql injection
- CVE-2024-116052 PoCsWP Publications <= 1.2 - Admin+ Stored XSS
- CVE-2024-116061 PoCTabs Shortcode <= 2.0.2 - Contributor+ XSS via Shortcode
- CVE-2024-116071 PoCGTPayment Donations <= 1.0.0 - Stored XSS via CSRF
- CVE-2024-116131 PoCWordPress File Upload <= 4.24.15 - Unauthenticated Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion
- CVE-2024-116161 PoCDouble-fetch heap overflow
- CVE-2024-116181 PoCIPC Unigy Management System HTTP Request server-side request forgery
- CVE-2024-116301 PoCE-Lins H685/H685f/H700/H720/H750/H820/H820Q/H820Q0/H900 OEM Backend hard-coded credentials
- CVE-2024-116311 PoCitsourcecode Tailoring Management System expedit.php sql injection
- CVE-2024-116321 PoCcode-projects Simple Car Rental System book_car.php sql injection
- CVE-2024-116351 PoCWordPress File Upload <= 4.24.12 - Unuathenticated Remote Code Execution
- CVE-2024-116361 PoCEmail Subscribers < 5.7.45 - Admin+ Stored XSS
- CVE-2024-116381 PoCGtbabel < 6.6.9 - Unauthenticated Admin Account Takeover
- CVE-2024-116431 PoCAccessibility by AllAccessible <= 1.3.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Option Update
- CVE-2024-116441 PoCWP-SVG <= 0.9 - Contributor+ Stored XSS via Shortcode
- CVE-2024-116451 PoCFloat Block <= 1.7 - Admin+ Stored XSS via Widget
- CVE-2024-116461 PoC1000 Projects Beauty Parlour Management System edit-services.php sql injection
- CVE-2024-116471 PoC1000 Projects Beauty Parlour Management System view-appointment.php sql injection
- CVE-2024-116481 PoC1000 Projects Beauty Parlour Management System add-customer.php sql injection
- CVE-2024-116491 PoC1000 Projects Beauty Parlour Management System search-appointment.php sql injection
- CVE-2024-116501 PoCTenda i9 GetIPTV websReadEvent null pointer dereference
- CVE-2024-116511 PoCEnGenius ENH1350EXT/ENS500-AC/ENS620EXT wifi_schedule command injection
- CVE-2024-116521 PoCEnGenius ENH1350EXT/ENS500-AC/ENS620EXT sn_https command injection
- CVE-2024-116531 PoCEnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_traceroute command injection
- CVE-2024-116541 PoCEnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_traceroute6 command injection
- CVE-2024-116551 PoCEnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_pinginterface command injection
- CVE-2024-116561 PoCEnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_ping6 command injection
- CVE-2024-116571 PoCEnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_nslookup command injection
- CVE-2024-116581 PoCEnGenius ENH1350EXT/ENS500-AC/ENS620EXT ajax_getChannelList command injection
- CVE-2024-116591 PoCEnGenius ENH1350EXT/ENS500-AC/ENS620EXT diag_iperf command injection
- CVE-2024-116601 PoCcode-projects Farmacia usuario.php cross site scripting
- CVE-2024-116611 PoCCodezips Free Exam Hall Seating Management System Profile Image profile.php unrestricted upload
- CVE-2024-116621 PoCwelliamcao OpsManage API Endpoint deploy_api.py deploy_host_vars deserialization
- CVE-2024-116631 PoCCodezips E-Commerce Site search.php sql injection
- CVE-2024-116642 PoCseNMS TGZ File controller.py multiselect_filtering path traversal
- CVE-2024-116671 PoCKEVA directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX…
- CVE-2024-116731 PoC1000 Projects Bookstore Management System cross-site request forgery
- CVE-2024-116741 PoCCodeAstro Hospital Management System his_doc_update-account.php unrestricted upload
- CVE-2024-116751 PoCCodeAstro Hospital Management System Add Patient Details Page his_admin_register_patient.php cross site scripting
- CVE-2024-116761 PoCCodeAstro Hospital Management System Add Laboratory Equipment Page his_admin_add_lab_equipment.php cross site scripting
- CVE-2024-116771 PoCCodeAstro Hospital Management System Add Vendor Details Page his_admin_add_vendor.php cross site scripting
- CVE-2024-116781 PoCCodeAstro Hospital Management System his_doc_register_patient.php cross site scripting
- CVE-2024-116805 PoCsKEVProjectSend Unauthenticated Configuration Modification
- CVE-2024-116811 PoCRemote Code Execution in MacPorts
- CVE-2024-117161 PoCWhile assignment of a user to a team (bracket) in CTFd should be possible only once, at the registration, a flaw in logic implementation…
- CVE-2024-117171 PoCTokens in CTFd used for account activation and password resetting can be used interchangeably for these operations. When used, they are…
- CVE-2024-117181 PoCtarteaucitron.js for WordPress < 0.3.0 - Author+ Stored XSS
- CVE-2024-117191 PoCtarteaucitron.js for WordPress < 0.3.0 - Stored XSS via CSRF
- CVE-2024-117283 PoCsKiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 - Unauthenticated SQL Injection
- CVE-2024-117401 PoCDownload Manager <= 3.3.03 - Unauthenticated Arbitrary Shortcode Execution
- CVE-2024-117421 PoCSourceCodester Best House Rental Management System ajax.php cross site scripting
- CVE-2024-117431 PoCSourceCodester Best House Rental Management System POST Request ajax.php cross-site request forgery
- CVE-2024-117441 PoC1000 Projects Portfolio Management System MCA register.php sql injection
- CVE-2024-117451 PoCTenda AC8 SetStaticRouteCfg route_static_check stack-based overflow
- CVE-2024-118171 PoCPHPGurukul User Registration & Login and User Management System index.php sql injection
- CVE-2024-118181 PoCPHPGurukul User Registration & Login and User Management System signup.php sql injection
- CVE-2024-118191 PoC1000 Projects Portfolio Management System MCA forgot_password_process.php sql injection
- CVE-2024-118201 PoCcode-projects Crud Operation System add.php cross site scripting
- CVE-2024-118281 PoCInefficient Algorithmic Complexity in GitLab
- CVE-2024-118411 PoCTithe.ly Giving Button <= 1.1 - Contributor+ Stored XSS via Shortcode
- CVE-2024-118421 PoCDN Shipping by Weight for WooCommerce < 1.2 - Settings Update via CSRF
- CVE-2024-118431 PoCPanorama – WordPress Project Management Plugin <= 1.5.1 - Admin+ Stored XSS
- CVE-2024-118461 PoCTravel Tour < 5.2.4 - Reflected XSS
- CVE-2024-118471 PoCWP SVG Upload <= 1.0.0 - Author+ Stored XSS via SVG
- CVE-2024-118481 PoCNitroPack <= 1.17.0 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update
- CVE-2024-118491 PoCPods – Custom Content Types and Fields < 3.2.8.1 - Admin+ Stored XSS
- CVE-2024-118602 PoCsSourceCodester Best House Rental Management System POST Request ajax.php improper authorization
- CVE-2024-118681 PoCLearnPress – WordPress LMS Plugin <= 4.2.7.3 - Course Material Sensitive Information Exposure via REST API
- CVE-2024-119212 PoCsGive < 3.19.0 - Reflected XSS
- CVE-2024-119241 PoCEmail Subscribers < 5.7.52 - Admin+ Stored XSS
- CVE-2024-119543 PoCsPimcore Search Document cross site scripting
- CVE-2024-119551 PoCGLPI index.php redirect
- CVE-2024-119563 PoCsPimcore customer-data-framework list sql injection
- CVE-2024-119591 PoCD-Link DIR-605L formResetStatistic buffer overflow
- CVE-2024-119601 PoCD-Link DIR-605L formSetPortTr buffer overflow
- CVE-2024-119611 PoCGuangzhou Huayi Intelligent Technology Jeewms WmOmNoticeHController.java preHandle information disclosure
- CVE-2024-119621 PoCcode-projects Simple Car Rental System login.php sql injection
- CVE-2024-119631 PoCcode-projects Responsive Hotel Site room.php sql injection
- CVE-2024-119641 PoCPHPGurukul Complaint Management system index.php sql injection
- CVE-2024-119651 PoCPHPGurukul Complaint Management system reset-password.php sql injection
- CVE-2024-119661 PoCPHPGurukul Complaint Management system index.php sql injection
- CVE-2024-119671 PoCPHPGurukul Complaint Management system reset-password.php sql injection
- CVE-2024-119681 PoCcode-projects Farmacia pagamento.php sql injection
- CVE-2024-119701 PoCcode-projects Concert Ticket Ordering System tour(cor).php sql injection
- CVE-2024-119711 PoCGuizhou Xiaoma Technology jpress Avatar upload cross site scripting
- CVE-2024-119725 PoCsHunk Companion < 1.9.0 - Unauthenticated Plugin Installation
- CVE-2024-119951 PoCcode-projects Farmacia pagamento.php cross site scripting
- CVE-2024-119961 PoCcode-projects Farmacia editar-fornecedor.php cross site scripting
- CVE-2024-119971 PoCcode-projects Farmacia vendas.php cross site scripting
- CVE-2024-119981 PoCcode-projects Farmacia visualizer-forneccedor.chp sql injection