CVE-2024-22000 to CVE-2024-22999
123 CVEs with public proof-of-concept exploits.
- CVE-2024-220171 PoCsetuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid().This allows the process to…
- CVE-2024-220244 PoCsAn XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x)…
- CVE-2024-220261 PoCA local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and…
- CVE-2024-220492 PoCshttparty Multipart/Form-Data Request Tampering Vulnerability
- CVE-2024-220861 PoChandle_request in http.c in cherry through 4b877df has an sscanf stack-based buffer overflow via a long URI, leading to remote code…
- CVE-2024-220871 PoCroute in main.c in Pico HTTP Server in C through f3b69a6 has an sprintf stack-based buffer overflow via a long URI, leading to remote code…
- CVE-2024-220881 PoCLotos WebServer through 0.1.1 (commit 3eb36cc) has a use-after-free in buffer_avail() at buffer.h via a long URI, because realloc is…
- CVE-2024-221071 PoCAn issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at…
- CVE-2024-221081 PoCAn issue was discovered in GTB Central Console 15.17.1-30814.NG. The method setTermsHashAction at /opt/webapp/lib/PureApi/CCApi.class.php…
- CVE-2024-221208 PoCsTime Based SQL Injection in Zabbix Server Audit Log
- CVE-2024-221451 PoCWordPress InstaWP Connect plugin <= 0.1.0.8 - Arbitrary Option Update to Privilege Escalation vulnerability
- CVE-2024-221901 PoCUntrusted search path under some conditions on Windows allows arbitrary code execution
- CVE-2024-221912 PoCsStored cross-site scripting (XSS) in `key_value` field in Avo
- CVE-2024-221962 PoCsAuthenticated (user role) SQL injection in `OrderAndPaginate` (GHSL-2023-270)
- CVE-2024-221972 PoCsAuthenticated (user role) remote command execution by modifying `nginx` settings (GHSL-2023-269)
- CVE-2024-221982 PoCsAuthenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GHSL-2023-268)
- CVE-2024-222021 PoCUser Removal Page Allows Spoofing Of User Details
- CVE-2024-222071 PoCDefault swagger-ui configuration exposes all files in the module
- CVE-2024-222081 PoCphpMyFAQ sharing FAQ functionality can easily be abused for phishing purposes
- CVE-2024-222111 PoCFreeRDP integer Overflow leading to Heap Overflow
- CVE-2024-222341 PoCCVE-2024-22234: Broken Access Control in Spring Security With Direct Use of isFullyAuthenticated
- CVE-2024-222434 PoCsCVE-2024-22243: Spring Framework URL Parsing with Host Validation
- CVE-2024-222622 PoCsCVE-2024-22262: Spring Framework URL Parsing with Host Validation
- CVE-2024-222744 PoCsThe vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the…
- CVE-2024-222751 PoCThe vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance…
- CVE-2024-223181 PoCIBM i Access Client Solutions information disclosure
- CVE-2024-223191 PoCIBM Operational Decision Manager JDNI injection
- CVE-2024-223202 PoCsIBM Operational Decision Manager code execution
- CVE-2024-223682 PoCsThe Spreadsheet::ParseXLSX package before 0.28 for Perl can encounter an out-of-memory condition during parsing of a crafted XLSX…
- CVE-2024-223693 PoCsApache Camel: Camel-SQL: Unsafe Deserialization from JDBCAggregationRepository
- CVE-2024-223711 PoCApache Camel issue on ExchangeCreatedEvent
- CVE-2024-223931 PoCApache Answer: Pixel Flood Attack by uploading the large pixel file
- CVE-2024-224091 PoCDefault Privileges allow for high level operations for low privileged users in datahub
- CVE-2024-224112 PoCsCross site scripting in Action messages on Avo
- CVE-2024-224121 PoCClickHouse's Role-based Access Control is bypassed when query caching is enabled.
- CVE-2024-224141 PoCUser profile page vulnerable to Cross Site Scripting (XSS) in flaskBlog
- CVE-2024-224164 PoCsCross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation
- CVE-2024-224181 PoCStored Cross-site Scripting Vulnerability via Malicious File Names in GroupOffice
- CVE-2024-224192 PoCsconcat built-in can corrupt memory in vyper
- CVE-2024-224221 PoCUnauthenticated Denial of Service (DOS) attack in AnythingLLM
- CVE-2024-224761 PoCImproper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to…
- CVE-2024-225131 PoCdjangorestframework-simplejwt version 5.3.1 and before is vulnerable to information disclosure. A user can access web application…
- CVE-2024-225141 PoCAn issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file.
- CVE-2024-225151 PoCUnrestricted File Upload vulnerability in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to upload arbitrary files via the upload…
- CVE-2024-225261 PoCBuffer Overflow vulnerability in bandisoft bandiview v7.0, allows local attackers to cause a denial of service (DoS) via exr image file.
- CVE-2024-225291 PoCTOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040 (handle function of formUploadFile) of…
- CVE-2024-225321 PoCBuffer Overflow vulnerability in XNSoft NConvert 7.163 (for Windows x86) allows attackers to cause a denial of service via crafted xwd file.
- CVE-2024-225451 PoCAn issue was discovered in TRENDnet TEW-824DRU version 1.04b01, allows unauthenticated attackers to execute arbitrary code via the…
- CVE-2024-225461 PoCTRENDnet TEW-815DAP 1.0.2.0 is vulnerable to Command Injection via the do_setNTP function. An authenticated attacker with administrator…
- CVE-2024-225491 PoCFlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the email settings of the website settings section.
- CVE-2024-225501 PoCAn arbitrary file upload vulnerability in the component /alsdemo/ss/mediam.cgi of ShopSite v14.0 allows attackers to execute arbitrary…
- CVE-2024-225511 PoCWhatACart v2.0.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /site/default/search.
- CVE-2024-225621 PoCswftools 0.9.2 was discovered to contain a Stack Buffer Underflow via the function dict_foreach_keyvalue at swftools/lib/q.c.
- CVE-2024-225681 PoCFlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/del.
- CVE-2024-225691 PoCStored Cross-Site Scripting (XSS) vulnerability in POSCMS v4.6.2, allows attackers to execute arbitrary code via a crafted payload to…
- CVE-2024-225911 PoCFlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_save.
- CVE-2024-225921 PoCFlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_update
- CVE-2024-225931 PoCFlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/add_group_save
- CVE-2024-226031 PoCFlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/links/add_link
- CVE-2024-226111 PoCOpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and…
- CVE-2024-226351 PoCWebCalendar v1.3.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component…
- CVE-2024-226371 PoCForm Tools v3.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component…
- CVE-2024-226382 PoCsliveSite v2019.1 was discovered to contain a remote code execution (RCE) vulenrabiity via the component /livesite/edit_designer_region.php…
- CVE-2024-226391 PoCiGalerie v3.0.22 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Titre (Title) field in the editing…
- CVE-2024-226401 PoCTCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color.
- CVE-2024-226411 PoCTCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.
- CVE-2024-226511 PoCThere is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmware v1.04.
- CVE-2024-226531 PoCyasm commit 9defefae was discovered to contain a NULL pointer dereference via the yasm_section_bcs_append function at section.c.
- CVE-2024-226541 PoCtcpreplay v4.4.4 was discovered to contain an infinite loop via the tcprewrite function at get.c.
- CVE-2024-226601 PoCTOTOLINK_A3700R_V9.1.2u.6165_20211012has a stack overflow vulnerability via setLanguageCfg
- CVE-2024-226621 PoCTOTOLINK A3700R_V9.1.2u.6165_20211012 has a stack overflow vulnerability via setParentalRules
- CVE-2024-226631 PoCTOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg
- CVE-2024-226671 PoCVim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is…
- CVE-2024-226991 PoCFlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/update_group_save.
- CVE-2024-227151 PoCStupid Simple CMS <=1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin-edit.php.
- CVE-2024-227171 PoCCross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the First Name field in the…
- CVE-2024-227181 PoCCross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the client_id parameter in the…
- CVE-2024-227191 PoCSQL Injection vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary SQL commands via the 'keyword' when searching for a…
- CVE-2024-227201 PoCKanboard 1.2.34 is vulnerable to Html Injection in the group management feature.
- CVE-2024-227211 PoCCross Site Request Forgery (CSRF) vulnerability in Form Tools 3.1.1 allows attackers to manipulate sensitive user data via crafted link.
- CVE-2024-227221 PoCServer Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name…
- CVE-2024-227231 PoCWebtrees 2.1.18 is vulnerable to Directory Traversal. By manipulating the "media_folder" parameter in the URL, an attacker (in this case,…
- CVE-2024-227293 PoCsNETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.
- CVE-2024-227331 PoCTP Link MR200 V4 Firmware version 210201 was discovered to contain a null-pointer-dereference in the web administration panel on…
- CVE-2024-227342 PoCsAn issue was discovered in AMCS Group Trux Waste Management Software before version 7.19.0018.26912, allows local attackers to obtain…
- CVE-2024-227492 PoCsGPAC v2.3 was detected to contain a buffer overflow via the function gf_isom_new_generic_sample_description function in the…
- CVE-2024-227511 PoCD-Link DIR-882 DIR882A1_FW130B06 was discovered to contain a stack overflow via the sub_477AA0 function.
- CVE-2024-227731 PoCIntelbras Action RF 1200 routers 1.2.2 and earlier and Action RG 1200 routers 2.1.7 and earlier expose the Password in Cookie resulting in…
- CVE-2024-227741 PoCAn issue in Panoramic Corporation Digital Imaging Software v.9.1.2.7600 allows a local attacker to escalate privileges via the…
- CVE-2024-227951 PoCInsecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the…
- CVE-2024-228171 PoCFlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_conf_updagte
- CVE-2024-228181 PoCFlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerbility via /system/site/filterKeyword_save
- CVE-2024-228191 PoCFlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_templets_update.
- CVE-2024-228361 PoCAn OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when…
- CVE-2024-228521 PoCD-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows…
- CVE-2024-228531 PoCD-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain…
- CVE-2024-228541 PoCDOM-based HTML injection vulnerability in the main page of Darktrace Threat Visualizer version 6.1.27 (bundle version 61050) and before…
- CVE-2024-228551 PoCA cross-site scripting (XSS) vulnerability in the User Maintenance section of ITSS iMLog v1.307 allows attackers to execute arbitrary web…
- CVE-2024-228891 PoCDue to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a…
- CVE-2024-228912 PoCsNteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.
- CVE-2024-228941 PoCAn issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps…
- CVE-2024-228992 PoCsVinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime…
- CVE-2024-229002 PoCsVinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the…
- CVE-2024-229012 PoCsVinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.
- CVE-2024-229022 PoCsVinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.
- CVE-2024-229032 PoCsVinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the…
- CVE-2024-229111 PoCA stack-buffer-underflow vulnerability was found in SWFTools v0.9.2, in the function parseExpression at src/swfc.c:2602.
- CVE-2024-229121 PoCA global-buffer-overflow was found in SWFTools v0.9.2, in the function countline at swf5compiler.flex:327. It allows an attacker to cause…
- CVE-2024-229131 PoCA heap-buffer-overflow was found in SWFTools v0.9.2, in the function swf5lex at lex.swf5.c:1321. It allows an attacker to cause code…
- CVE-2024-229141 PoCA heap-use-after-free was found in SWFTools v0.9.2, in the function input at lex.swf5.c:2620. It allows an attacker to cause denial of…
- CVE-2024-229151 PoCA heap-use-after-free was found in SWFTools v0.9.2, in the function swf_DeleteTag at rfxswf.c:1193. It allows an attacker to cause code…
- CVE-2024-229161 PoCIn D-LINK Go-RT-AC750 v101b03, the sprintf function in the sub_40E700 function within the cgibin is susceptible to stack overflow.
- CVE-2024-229171 PoCSQL injection vulnerability in Dynamic Lab Management System Project in PHP v.1.0 allows a remote attacker to execute arbitrary code via a…
- CVE-2024-229191 PoCswftools0.9.2 was discovered to contain a global-buffer-overflow vulnerability via the function parseExpression at swftools/src/swfc.c:2587.
- CVE-2024-229201 PoCswftools 0.9.2 was discovered to contain a heap-use-after-free via the function bufferWriteData in swftools/lib/action/compile.c.
- CVE-2024-229222 PoCsAn issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the…
- CVE-2024-229272 PoCsCross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via…
- CVE-2024-229392 PoCsCross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the…
- CVE-2024-229421 PoCTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the hostName parameter in the…
- CVE-2024-229551 PoCswftools 0.9.2 was discovered to contain a stack-buffer-underflow vulnerability via the function parseExpression at…
- CVE-2024-229561 PoCswftools 0.9.2 was discovered to contain a heap-use-after-free vulnerability via the function removeFromTo at swftools/src/swfc.c:838
- CVE-2024-229571 PoCswftools 0.9.2 was discovered to contain an Out-of-bounds Read vulnerability via the function dict_do_lookup in swftools/lib/q.c:1190.
- CVE-2024-229832 PoCsSQL injection vulnerability in Projectworlds Visitor Management System in PHP v.1.0 allows a remote attacker to escalate privileges via…