CVE-2024-24000 to CVE-2024-24999
151 CVEs with public proof-of-concept exploits.
- CVE-2024-240011 PoCjshERP v3.3 is vulnerable to SQL Injection. via the com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo…
- CVE-2024-240021 PoCjshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.MaterialController: com.jsh.erp.utils.BaseResponseInfo…
- CVE-2024-240031 PoCjshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo…
- CVE-2024-240041 PoCjshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo…
- CVE-2024-240342 PoCsSetor Informatica S.I.L version 3.0 is vulnerable to Open Redirect via the hprinter parameter, allows remote attackers to execute…
- CVE-2024-240352 PoCsCross Site Scripting (XSS) vulnerability in Setor Informatica SIL 3.1 allows attackers to run arbitrary code via the hmessage parameter.
- CVE-2024-240411 PoCA stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute…
- CVE-2024-240501 PoCCross Site Scripting (XSS) vulnerability in Sourcecodester Workout Journal App 1.0 allows attackers to run arbitrary code via parameters…
- CVE-2024-240591 PoCspringboot-manager v1.6 is vulnerable to Arbitrary File Upload. The system does not filter the suffixes of uploaded files.
- CVE-2024-240601 PoCspringboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/user.
- CVE-2024-240611 PoCspringboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sysContent/add.
- CVE-2024-240621 PoCspringboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/role.
- CVE-2024-240921 PoCSQL Injection vulnerability in Code-projects.org Scholars Tracking System 1.0 allows attackers to run arbitrary code via login.php.
- CVE-2024-240931 PoCSQL Injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via Personal Information…
- CVE-2024-240951 PoCCode-projects Simple Stock System 1.0 is vulnerable to SQL Injection.
- CVE-2024-240961 PoCCode-projects Computer Book Store 1.0 is vulnerable to SQL Injection via BookSBIN.
- CVE-2024-240971 PoCCross Site Scripting (XSS) vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via the News…
- CVE-2024-240981 PoCCode-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection via the News Feed.
- CVE-2024-240991 PoCCode-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Employment Status Information Update.
- CVE-2024-241001 PoCCode-projects Computer Book Store 1.0 is vulnerable to SQL Injection via PublisherID.
- CVE-2024-241011 PoCCode-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility Information Update.
- CVE-2024-241051 PoCSQL Injection vulnerability in Code-projects Computer Science Time Table System 1.0 allows attackers to run arbitrary code via…
- CVE-2024-241122 PoCsxmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.
- CVE-2024-241151 PoCA stored cross-site scripting (XSS) vulnerability in the Edit Page function of Cotonti CMS v0.9.24 allows authenticated attackers to…
- CVE-2024-241161 PoCAn issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.
- CVE-2024-241301 PoCMail2World v12 Business Control Center was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Usr…
- CVE-2024-241312 PoCsSuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php.
- CVE-2024-241342 PoCsSourcecodester Online Food Menu 1.0 is vulnerable to Cross Site Scripting (XSS) via the 'Menu Name' and 'Description' fields in the Update…
- CVE-2024-241352 PoCsProduct Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to…
- CVE-2024-241362 PoCsThe 'Your Name' field in the Submit Score section of Sourcecodester Math Game with Leaderboard v1.0 is vulnerable to Cross-Site Scripting…
- CVE-2024-241391 PoCSourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.
- CVE-2024-241402 PoCsSourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'
- CVE-2024-241412 PoCsSourcecodester School Task Manager App 1.0 allows SQL Injection via the 'task' parameter.
- CVE-2024-241422 PoCsSourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.
- CVE-2024-241461 PoCA memory leak issue discovered in parseSWF_DEFINEBUTTON in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF…
- CVE-2024-241471 PoCA memory leak issue discovered in parseSWF_FILLSTYLEARRAY in libming v0.4.8 allows attackers to cause s denial of service via a crafted…
- CVE-2024-241481 PoCA memory leak issue discovered in parseSWF_FREECHARACTER in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF…
- CVE-2024-241491 PoCA memory leak issue discovered in parseSWF_GLYPHENTRY in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF…
- CVE-2024-241501 PoCA memory leak issue discovered in parseSWF_TEXTRECORD in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF…
- CVE-2024-241551 PoCBento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot…
- CVE-2024-241561 PoCCross Site Scripting (XSS) vulnerability in Gnuboard g6 before Github commit 58c737a263ac0c523592fd87ff71b9e3c07d7cf5, allows remote…
- CVE-2024-241571 PoCGnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site Scripting (XSS)…
- CVE-2024-241601 PoCMRCMS 3.0 contains a Cross-Site Scripting (XSS) vulnerability via /admin/system/saveinfo.do.
- CVE-2024-241611 PoCMRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered.
- CVE-2024-241861 PoCJsish v3.5.0 (commit 42c694c) was discovered to contain a stack-overflow via the component IterGetKeysCallback at /jsish/src/jsiValue.c.
- CVE-2024-241881 PoCJsish v3.5.0 was discovered to contain a heap-buffer-overflow in ./src/jsiUtils.c.
- CVE-2024-242161 PoCZentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of…
- CVE-2024-242461 PoCHeap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count() function at…
- CVE-2024-242921 PoCA Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary code via the aim function in the aim.js…
- CVE-2024-243001 PoC4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardless of how many…
- CVE-2024-243011 PoCCommand Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with…
- CVE-2024-243211 PoCAn issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the…
- CVE-2024-243251 PoCTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the…
- CVE-2024-243261 PoCTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable parameter in the…
- CVE-2024-243271 PoCTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the…
- CVE-2024-243282 PoCsTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the…
- CVE-2024-243292 PoCsTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the…
- CVE-2024-243301 PoCTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enable parameter in…
- CVE-2024-243311 PoCTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the…
- CVE-2024-243321 PoCTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the url parameter in the…
- CVE-2024-243331 PoCTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the…
- CVE-2024-243861 PoCAn issue in VitalPBX v.3.2.4-5 allows an attacker to execute arbitrary code via a crafted payload to the /var/lib/vitalpbx/scripts folder.
- CVE-2024-243962 PoCsCross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute…
- CVE-2024-243971 PoCCross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute…
- CVE-2024-243982 PoCsDirectory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute…
- CVE-2024-243991 PoCAn arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this…
- CVE-2024-244012 PoCsSQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the…
- CVE-2024-244021 PoCAn issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd…
- CVE-2024-244092 PoCsPrivilege Escalation
- CVE-2024-244161 PoCThe Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer…
- CVE-2024-244171 PoCThe Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer…
- CVE-2024-244181 PoCThe Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer…
- CVE-2024-244191 PoCThe Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer…
- CVE-2024-244201 PoCA reachable assertion in the decode_linked_ti_ie function of Magma <= 1.8.0 (fixed in v1.9 commit…
- CVE-2024-244211 PoCA type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486)…
- CVE-2024-244221 PoCThe Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a stack…
- CVE-2024-244231 PoCThe Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer…
- CVE-2024-244281 PoCA reachable assertion in the oai_nas_5gmm_decode function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a…
- CVE-2024-244291 PoCA reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2024-244301 PoCA reachable assertion in the mme_ue_find_by_imsi function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a…
- CVE-2024-244311 PoCA reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a…
- CVE-2024-244321 PoCA reachable assertion in the ogs_kdf_hash_mme function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a…
- CVE-2024-244501 PoCStack-based memcpy buffer overflow in the ngap_handle_pdu_session_resource_setup_response routine in OpenAirInterface CN5G AMF <= 2.0.0…
- CVE-2024-244511 PoCA stack overflow in the sctp_server::sctp_receiver_thread component of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows…
- CVE-2024-244681 PoCCross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the…
- CVE-2024-244691 PoCCross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the delete_post .php.
- CVE-2024-244701 PoCCross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the update_post.php…
- CVE-2024-244821 PoCAprktool before 2.9.3 on Windows allows ../ and /.. directory traversal.
- CVE-2024-244881 PoCAn issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive information via the password…
- CVE-2024-244942 PoCsCross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise,…
- CVE-2024-244952 PoCsSQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via…
- CVE-2024-244961 PoCAn issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php,…
- CVE-2024-245061 PoCCross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute…
- CVE-2024-245111 PoCCross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the Input Title component.
- CVE-2024-245121 PoCCross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the input subtitle component.
- CVE-2024-245201 PoCAn issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.
- CVE-2024-245241 PoCCross Site Request Forgery (CSRF) vulnerability in flusity-CMS v.2.33, allows remote attackers to execute arbitrary code via the…
- CVE-2024-245431 PoCBuffer Overflow vulnerability in the function setSchedWifi in Tenda AC9 v.3.0, firmware version v.15.03.06.42_multi allows a remote…
- CVE-2024-245492 PoCsApache Tomcat: HTTP/2 header handling DoS
- CVE-2024-245501 PoCBludit - Remote Code Execution (RCE) through File API
- CVE-2024-245511 PoCBludit - Remote Code Execution (RCE) through Image API
- CVE-2024-245591 PoCVyper SHA3 code generation bug
- CVE-2024-245602 PoCsVyper external calls can overflow return data to return input buffer
- CVE-2024-245612 PoCsVyper bounds check on built-in `slice()` function can be overflowed
- CVE-2024-245632 PoCsVyper array negative index vulnerability
- CVE-2024-245642 PoCsVyper extract32 can ready dirty memory
- CVE-2024-245653 PoCsCrateDB database has an arbitrary file read vulnerability
- CVE-2024-245663 PoCsLobe Chat unauthorized access to plugins
- CVE-2024-245671 PoCraw_call `value=` kwargs not disabled for static and delegate calls
- CVE-2024-245691 PoC`ZipSecurity#isBelowCurrentDirectory` is vulnerable to partial-path traversal vulnerability
- CVE-2024-245711 PoCfacileManager Systemic Cross-Site Scripting (XSS)
- CVE-2024-245721 PoCfacileManager Authenticated Variable Manipulation leading to SQL Injection
- CVE-2024-245731 PoCfacileManager Privilege Escalation via Mass Assignment
- CVE-2024-245742 PoCsphpMyFAQ vulnerable to stored XSS on attachments filename
- CVE-2024-245768 PoCsRusts's `std::process::Command` did not properly escape arguments of batch files on Windows
- CVE-2024-245782 PoCsRaspberryMatic Unauthenticated Remote Code Execution vulnerability through HMServer File Upload
- CVE-2024-245908 PoCsDeserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a…
- CVE-2024-246841 PoCMultiple stack-based buffer overflow vulnerabilities exist in the readOFF functionality of libigl v2.5.0. A specially crafted .off file…
- CVE-2024-246851 PoCMultiple stack-based buffer overflow vulnerabilities exist in the readOFF functionality of libigl v2.5.0. A specially crafted .off file…
- CVE-2024-246861 PoCMultiple stack-based buffer overflow vulnerabilities exist in the readOFF functionality of libigl v2.5.0. A specially crafted .off file…
- CVE-2024-247241 PoCGibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code…
- CVE-2024-247253 PoCsGibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the…
- CVE-2024-247361 PoCThe POP3 service in YahooPOPs (aka YPOPs!) 1.6 allows a remote denial of service (reboot) via a long string to TCP port 110, a related…
- CVE-2024-247472 PoCsMinIO unsafe default: Access keys inherit `admin` of root user, allowing privilege escalation
- CVE-2024-247522 PoCsBref Uploaded Files Not Deleted in Event-Driven Functions
- CVE-2024-247532 PoCsBref Multiple Value Headers Not Supported in ApiGatewayFormatV2
- CVE-2024-247542 PoCsBref Body Parsing Inconsistency in Event-Driven Functions
- CVE-2024-247561 PoCCrafatar path traversal vulnerability
- CVE-2024-247593 PoCsMindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding
- CVE-2024-247601 PoCMailcow Docker Container Exposure to Local Network
- CVE-2024-247622 PoCspython-multipart vulnerable to content-type header Regular expression Denial of Service
- CVE-2024-247631 PoCJumpServer Open Redirect Vulnerability
- CVE-2024-247651 PoCCasaOS-UserService allows unauthorized access to any file
- CVE-2024-247671 PoCCasaOS Improper Restriction of Excessive Authentication Attempts vulnerability
- CVE-2024-247771 PoCA cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of the LevelOne WBR-6012 R0.40e6. A…
- CVE-2024-247861 PoCInfinite loop in JSON unmarshaling in google.golang.org/protobuf
- CVE-2024-247871 PoCArbitrary code execution during build on Darwin in cmd/go
- CVE-2024-247931 PoCA use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially…
- CVE-2024-247941 PoCA use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially…
- CVE-2024-248061 PoCImproper Domain Lookup that potentially leads to SSRF attacks in libuv
- CVE-2024-248081 PoCpyLoad open redirect vulnerability due to improper validation of the is_safe_url function
- CVE-2024-248094 PoCsTraccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type
- CVE-2024-248141 PoCDenial of service when manipulating mod_auth_openidc_session_chunks cookie in mod_auth_openidc
- CVE-2024-248161 PoCCross-site scripting (XSS) vulnerability in samples with enabled the preview feature
- CVE-2024-248181 PoCEspoCRM weakness in "Forgot password"
- CVE-2024-248243 PoCsgraylog2-server vulnerable to instantiation of arbitrary classes triggered by API request
- CVE-2024-248301 PoCOpenObserve Privilege Escalation Vulnerability in Users API
- CVE-2024-248821 PoCWordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerability
- CVE-2024-2491959 PoCsKEVInformation disclosure
- CVE-2024-249261 PoCWordPress Brooklyn Theme <= 4.9.7.6 is vulnerable to PHP Object Injection
- CVE-2024-249451 PoCA stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute…