CVE-2024-23000 to CVE-2024-23999
95 CVEs with public proof-of-concept exploits.
- CVE-2024-230311 PoCCross Site Scripting (XSS) vulnerability in is_water parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via…
- CVE-2024-230321 PoCCross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.
- CVE-2024-230331 PoCCross Site Scripting vulnerability in the path parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.
- CVE-2024-230341 PoCCross Site Scripting vulnerability in the input parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.
- CVE-2024-230521 PoCAn issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject()…
- CVE-2024-230541 PoCAn issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package…
- CVE-2024-230552 PoCsAn issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of…
- CVE-2024-230571 PoCTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the tz parameter in the setNtpCfg…
- CVE-2024-230581 PoCTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pass parameter in the…
- CVE-2024-230591 PoCTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the username parameter in the…
- CVE-2024-230601 PoCTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter in the setDmzCfg…
- CVE-2024-230611 PoCTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the minute parameter in the…
- CVE-2024-231083 PoCsAn improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.1.0 through…
- CVE-2024-231138 PoCsKEVA use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13,…
- CVE-2024-231142 PoCsApache Camel: Camel-CassandraQL: Unsafe Deserialization from CassandraAggregationRepository
- CVE-2024-232081 PoCThe issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.3, watchOS 10.3, tvOS 17.3, iOS 17.3 and…
- CVE-2024-232223 PoCsKEVA type confusion issue was addressed with improved checks. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3.…
- CVE-2024-232981 PoCA logic issue was addressed with improved state management.
- CVE-2024-233091 PoCThe LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due to reliance on…
- CVE-2024-233292 PoCschangedetection.io API endpoint is not secured with API token
- CVE-2024-233301 PoCTuta loads images from external resources
- CVE-2024-233312 PoCsVite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem
- CVE-2024-2333420 PoCsaiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
- CVE-2024-233371 PoCjq has signed integer overflow in jv.c:jvp_array_write
- CVE-2024-233391 PoChoolock does not block Prototype pollution with object-path related utilities
- CVE-2024-233469 PoCspymatgen arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
- CVE-2024-234431 PoCA high-privileged user, allowed to create custom osquery packs 17 could affect the availability of Kibana by uploading a maliciously…
- CVE-2024-235251 PoCThe Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.
- CVE-2024-236201 PoCIBM Merge Healthcare eFilm Workstation SYSTEM Privilege Escalation
- CVE-2024-236331 PoCLabel Studio XSS Vulnerability on Data Import
- CVE-2024-236342 PoCsGeoServer arbitrary file renaming vulnerability in REST Coverage/Data Store API
- CVE-2024-236412 PoCsSending a GET or HEAD request with a body crashes SvelteKit
- CVE-2024-236462 PoCsPimcore Admin Classic Bundle SQL Injection in Admin download files as zip
- CVE-2024-236481 PoCPimcore Admin Classic Bundle host header injection in the password reset
- CVE-2024-236491 PoCAny authenticated user may obtain private message details from other users on the same instance
- CVE-2024-236521 PoCBuildKit possible host system access from mount stub cleaner
- CVE-2024-236531 PoCBuildKit interactive containers API does not validate entitlements check
- CVE-2024-236551 PoCAttacker can prevent users from accessing received emails
- CVE-2024-236561 PoCDex 2.37.0 is discarding TLSconfig and always serves deprecated TLS 1.0/1.1 and insecure ciphers
- CVE-2024-236572 PoCsPath Traversal: '../filedir' in Nuxt Devtools
- CVE-2024-236591 PoCSPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded file. This is related to javascript/bigup.js and…
- CVE-2024-236601 PoCThe Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library…
- CVE-2024-236661 PoCA client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and…
- CVE-2024-236731 PoCApache Sling Servlets Resolver: Malicious code execution via path traversal
- CVE-2024-236812 PoCsArtemis Java Test Sandbox Libary Load Escape
- CVE-2024-2369221 PoCsKEVRejetto HTTP File Server 2.3m Unauthenticated RCE
- CVE-2024-237051 PoCIn multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could…
- CVE-2024-237081 PoCIn multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a clipboard message has…
- CVE-2024-237091 PoCIn multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information…
- CVE-2024-237222 PoCsIn Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of…
- CVE-2024-237243 PoCsGhost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG…
- CVE-2024-237291 PoCThe ColorOS Internet Browser com.heytap.browser application 45.10.3.4.1 for Android allows a remote attacker to execute arbitrary…
- CVE-2024-237332 PoCsThe /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core_Fix7 allows…
- CVE-2024-237382 PoCsAn issue in Postman version 10.22 and before on macOS allows a remote attacker to execute arbitrary code via the RunAsNode and…
- CVE-2024-237392 PoCsAn issue in Discord for macOS version 0.0.291 and before, allows remote attackers to execute arbitrary code via the RunAsNode and…
- CVE-2024-237402 PoCsAn issue in Kap for macOS version 3.6.0 and before, allows remote attackers to execute arbitrary code via the RunAsNode and…
- CVE-2024-237412 PoCsAn issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and…
- CVE-2024-237422 PoCsAn issue in Loom on macOS version 0.196.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and…
- CVE-2024-237432 PoCsNotion through 3.1.0 on macOS might allow code execution because of RunAsNode and enableNodeClilnspectArguments. NOTE: the vendor states…
- CVE-2024-237451 PoCIn Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB attack. NIB files can be manipulated to execute arbitrary…
- CVE-2024-237461 PoCMiro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments…
- CVE-2024-237471 PoCThe Moderna Sistemas ModernaNet Hospital Management System 2024 is susceptible to an Insecure Direct Object Reference (IDOR)…
- CVE-2024-237493 PoCsKiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insufficient input…
- CVE-2024-237501 PoCMetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to…
- CVE-2024-237511 PoCLlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in NLSQLTableQueryEngine,…
- CVE-2024-237521 PoCGenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of…
- CVE-2024-237561 PoCThe HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to…
- CVE-2024-237592 PoCsDeserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the…
- CVE-2024-237601 PoCCleartext Storage of Sensitive Information in Gambio 4.9.2.0 allows attackers to obtain sensitive information via error-handler.log.json…
- CVE-2024-237611 PoCServer Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitrary code via crafted smarty email template.
- CVE-2024-237621 PoCUnrestricted File Upload vulnerability in Content Manager feature in Gambio 4.9.2.0 allows attackers to execute arbitrary code via upload…
- CVE-2024-237631 PoCSQL Injection vulnerability in Gambio through 4.9.2.0 allows attackers to run arbitrary SQL commands via crafted GET request using…
- CVE-2024-237651 PoCAn issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes an unidentified service on port 7412 on the…
- CVE-2024-237661 PoCAn issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes a web interface on port 80. An unauthenticated GET…
- CVE-2024-237671 PoCAn issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated changes to a…
- CVE-2024-237721 PoCAn issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file create vulnerability exists in the…
- CVE-2024-237731 PoCAn issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file delete vulnerability exists in the…
- CVE-2024-237741 PoCAn issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An unquoted Windows search path vulnerability exists in the…
- CVE-2024-238171 PoCDolibarr Application Home Page HTML injection vulnerability
- CVE-2024-238221 PoCThruk Incorrect limitation of a pathname to a restricted directory (Path Traversal) (CWE-22)
- CVE-2024-238241 PoCmailcow ipixel flood attack leads to Denial of Service in admin page
- CVE-2024-238251 PoCTablePress SSRF vulnerability due to insufficient filtering of cloud provider hosts
- CVE-2024-238261 PoCUploading an image with a specific filename causes a server-side DoS
- CVE-2024-238271 PoCNginx-UI arbitrary file write through the Import Certificate feature
- CVE-2024-238291 PoCaiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators
- CVE-2024-238332 PoCsOpenRefine JDBC Attack Vulnerability
- CVE-2024-2389766 PoCsKEVJenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character…
- CVE-2024-238981 PoCJenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests…
- CVE-2024-239171 PoCIn JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
- CVE-2024-239221 PoCSony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability
- CVE-2024-239401 PoCTrend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable…
- CVE-2024-239852 PoCsEzServer 6.4.017 allows a denial of service (daemon crash) via a long string, such as one for the RNTO command.
- CVE-2024-239952 PoCsCross Site Scripting (XSS) in Beekeeper Studio 4.1.13 and earlier allows remote attackers to execute arbitrary code in the column name of…
- CVE-2024-239972 PoCsLukas Bach yana =<1.0.16 is vulnerable to Cross Site Scripting (XSS) via src/electron-main.ts.
- CVE-2024-239982 PoCsgoanother Another Redis Desktop Manager =<1.6.1 is vulnerable to Cross Site Scripting (XSS) via src/components/Setting.vue.