CVE-2024-21000 to CVE-2024-21999
73 CVEs with public proof-of-concept exploits.
- CVE-2024-210064 PoCsVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected…
- CVE-2024-211071 PoCVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are…
- CVE-2024-211114 PoCsVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are…
- CVE-2024-211361 PoCVulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are…
- CVE-2024-211823 PoCsKEVVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected…
- CVE-2024-212621 PoCVulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 9.0.0…
- CVE-2024-213051 PoCHypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
- CVE-2024-213062 PoCsMicrosoft Bluetooth Driver Spoofing Vulnerability
- CVE-2024-213202 PoCsWindows Themes Spoofing Vulnerability
- CVE-2024-2133811 PoCsKEVWindows Kernel Elevation of Privilege Vulnerability
- CVE-2024-213453 PoCsWindows Kernel Elevation of Privilege Vulnerability
- CVE-2024-213781 PoCMicrosoft Outlook Remote Code Execution Vulnerability
- CVE-2024-213881 PoCMicrosoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2024-214091 PoC.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
- CVE-2024-214124 PoCsKEVInternet Shortcut Files Security Feature Bypass Vulnerability
- CVE-2024-2141337 PoCsKEVMicrosoft Outlook Remote Code Execution Vulnerability
- CVE-2024-214856 PoCsVersions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the…
- CVE-2024-214882 PoCsVersions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function…
- CVE-2024-214921 PoCAll versions of the package github.com/greenpau/caddy-security are vulnerable to Insufficient Session Expiration due to improper user…
- CVE-2024-214961 PoCAll versions of the package github.com/greenpau/caddy-security are vulnerable to Cross-site Scripting (XSS) via the Referer header, due to…
- CVE-2024-215001 PoCAll versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Restriction of Excessive Authentication Attempts…
- CVE-2024-215013 PoCsVersions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style…
- CVE-2024-215022 PoCsVersions of the package fastecdsa before 2.3.2 are vulnerable to Use of Uninitialized Variable on the stack, via the curvemath_mul…
- CVE-2024-215041 PoCVersions of the package livewire/livewire from 3.3.5 and before 3.4.9 are vulnerable to Cross-site Scripting (XSS) when a page uses [Url]…
- CVE-2024-215071 PoCVersions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields function, resulting in…
- CVE-2024-215091 PoCVersions of the package mysql2 before 3.9.4 are vulnerable to Prototype Poisoning due to insecure results object creation and improper…
- CVE-2024-215132 PoCsVersions of the package langchain-experimental from 0.0.15 and before 0.0.21 are vulnerable to Arbitrary Code Execution when retrieving…
- CVE-2024-215142 PoCsThis affects versions of the package opencart/opencart from 0.0.0. An SQL Injection issue was identified in the Divido payment extension…
- CVE-2024-215151 PoCThis affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the filename parameter of the…
- CVE-2024-215161 PoCThis affects versions of the package opencart/opencart from 4.0.0.0 and before 4.1.0.0. A reflected XSS issue was identified in the…
- CVE-2024-215171 PoCThis affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the redirect parameter of…
- CVE-2024-215181 PoCThis affects versions of the package opencart/opencart from 4.0.0.0. A Zip Slip issue was identified via the marketplace installer due to…
- CVE-2024-215191 PoCThis affects versions of the package opencart/opencart from 4.0.0.0. An Arbitrary File Creation issue was identified via the database…
- CVE-2024-215201 PoCVersions of the package djangorestframework before 3.15.2 are vulnerable to Cross-site Scripting (XSS) via the break_long_headers template…
- CVE-2024-215242 PoCsAll versions of the package node-stringbuilder are vulnerable to Out-of-bounds Read due to incorrect memory length calculation, by calling…
- CVE-2024-215321 PoCAll versions of the package ggit are vulnerable to Command Injection via the fetchTags(branch) API, which allows user input to specify the…
- CVE-2024-215331 PoCAll versions of the package ggit are vulnerable to Arbitrary Argument Injection via the clone() API, which allows specifying the remote…
- CVE-2024-215343 PoCsAll versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker…
- CVE-2024-215411 PoCVersions of the package dom-iterator before 1.0.1 are vulnerable to Arbitrary Code Execution due to use of the Function constructor…
- CVE-2024-215421 PoCVersions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper…
- CVE-2024-215451 PoCProxmox Virtual Environment is an open-source server management platform for enterprise virtualization. Insufficient safeguards against…
- CVE-2024-215461 PoCVersions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through using a valid…
- CVE-2024-216231 PoCArbitrary Expression Injection in github workflow leads to Command execution & leaking secrets
- CVE-2024-2162619 PoCsrunc container breakout through process.cwd trickery and leaked fds
- CVE-2024-216333 PoCsArbitrary file write on Decoding
- CVE-2024-216401 PoCOOB Access in CefVideoConsumerOSR::OnFrameCaptured
- CVE-2024-216411 PoCFlarum's Logout Route allows open redirects
- CVE-2024-216444 PoCspyLoad unauthenticated flask configuration leakage
- CVE-2024-216453 PoCspyLoad Log Injection
- CVE-2024-216501 PoCXWiki Remote Code Execution vulnerability via user registration
- CVE-2024-216611 PoCArgo CD Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
- CVE-2024-216622 PoCsArgo CD vulnerable to Bypassing of Rate Limit and Brute Force Protection Using Cache Overflow
- CVE-2024-216631 PoCRemote code execution on ReconServer due to improper input sanitization on the prips command
- CVE-2024-216642 PoCsParsing JSON serialized payload without protected field can lead to segfault
- CVE-2024-216652 PoCsPimcore Ecommerce Framework Bundle Improper Access Control allows unprivileged user to access back-office orders list
- CVE-2024-216662 PoCsPimcore Customer Data Framework Improper Access Control allows unprivileged user to access customers duplicates list
- CVE-2024-216672 PoCsPimcore Customer Data Framework Improper Access Control allows unprivileged user to access GDPR extracts
- CVE-2024-216837 PoCsThis High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server.This RCE…
- CVE-2024-216891 PoCThis High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689 was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0,…
- CVE-2024-217321 PoCFlyCms through abbaa5a allows XSS via the permission management feature.
- CVE-2024-217331 PoCApache Tomcat: Leaking of unrelated request bodies in default error page
- CVE-2024-217542 PoCsA use of password hash with insufficient computational effort vulnerability [CWE-916] affecting FortiOS version 7.4.3 and below, 7.2 all…
- CVE-2024-2176210 PoCsKEVA out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14,…
- CVE-2024-217731 PoCMultiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port or Wi-Fi to…
- CVE-2024-217931 PoCBIG-IP Central Manager OData Injection Vulnerability
- CVE-2024-218211 PoCMultiple TP-LINK products allow a network-adjacent authenticated attacker with access to the product from the LAN port or Wi-Fi to execute…
- CVE-2024-218271 PoCA leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build…
- CVE-2024-2188714 PoCsKEVA command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an…
- CVE-2024-218881 PoCA privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a…
- CVE-2024-218934 PoCsKEVA server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x,…
- CVE-2024-219073 PoCsImproper Handling of Exceptional Conditions in Newtonsoft.Json
- CVE-2024-219781 PoCImproper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data…
- CVE-2024-219801 PoCImproper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or…