CVE-2024-25000 to CVE-2024-25999
183 CVEs with public proof-of-concept exploits.
- CVE-2024-250033 PoCsKiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insufficient bounds…
- CVE-2024-250042 PoCsKiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insufficient bounds…
- CVE-2024-250813 PoCsSplinefont in FontForge through 20230101 allows command injection via crafted filenames.
- CVE-2024-250823 PoCsSplinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.
- CVE-2024-250922 PoCsWordPress NextMove Lite plugin <= 2.17.0 - Subscriber+ Arbitrary Plugin Installation/Activation vulnerability
- CVE-2024-250961 PoCWordPress canto plugin <= 3.0.7 - Unauth. Remote Code Execution (RCE) vulnerability
- CVE-2024-251061 PoCOpenObserve Unauthorized Access Vulnerability in Users API
- CVE-2024-251082 PoCsInsufficient authorization allowing elevated access to resources in pixelfed
- CVE-2024-251171 PoCphp-svg-lib lacks path validation on font through SVG inline styles
- CVE-2024-251222 PoCsCross-site Scripting sidekiq-unique-jobs UI server vulnerability
- CVE-2024-251242 PoCsFiber has Insecure CORS Configuration, Allowing Wildcard Origin with Credentials
- CVE-2024-251261 PoCRack ReDos in content type parsing (2nd degree polynomial)
- CVE-2024-251533 PoCsRemote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114
- CVE-2024-251641 PoCiA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files via the download…
- CVE-2024-251651 PoCA global-buffer-overflow vulnerability was found in SWFTools v0.9.2, in the function LineText at lib/swf5compiler.flex.
- CVE-2024-251671 PoCCross Site Scripting vulnerability in eblog v1.0 allows a remote attacker to execute arbitrary code via a crafted script to the argument…
- CVE-2024-251681 PoCSQL injection vulnerability in snow snow v.2.0.0 allows a remote attacker to execute arbitrary code via the dataScope parameter of the…
- CVE-2024-251691 PoCAn issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request.
- CVE-2024-251701 PoCAn issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.
- CVE-2024-251761 PoCLuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in lj_strfmt_wfnum in lj_strfmt_num.c.
- CVE-2024-251771 PoCLuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which leads to Denial of…
- CVE-2024-251781 PoCLuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler in lj_state.c.
- CVE-2024-251802 PoCsAn issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE:…
- CVE-2024-251971 PoCOpen Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dereference via the…
- CVE-2024-252001 PoCEspruino 2v20 (commit fcc9ba4) was discovered to contain a Stack Overflow via the jspeFactorFunctionCall at src/jsparse.c.
- CVE-2024-252011 PoCEspruino 2v20 (commit fcc9ba4) was discovered to contain an Out-of-bounds Read via jsvStringIteratorPrintfCallback at src/jsvar.c.
- CVE-2024-252022 PoCsCross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attackers to run…
- CVE-2024-252071 PoCBarangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Resident…
- CVE-2024-252081 PoCBarangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Resident…
- CVE-2024-252091 PoCBarangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident parameter at…
- CVE-2024-252101 PoCSimple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at…
- CVE-2024-252111 PoCSimple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at…
- CVE-2024-252121 PoCEmployee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /delete.php.
- CVE-2024-252131 PoCEmployee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /edit.php.
- CVE-2024-252141 PoCAn issue in Employee Managment System v1.0 allows attackers to bypass authentication via injecting a crafted payload into the E-mail and…
- CVE-2024-252151 PoCEmployee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php.
- CVE-2024-252161 PoCEmployee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /aprocess.php.
- CVE-2024-252171 PoCOnline Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at…
- CVE-2024-252181 PoCA cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2024-252191 PoCA cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2024-252201 PoCTask Manager App v1.0 was discovered to contain a SQL injection vulnerability via the taskID parameter at /TaskManager/EditTask.php.
- CVE-2024-252211 PoCA cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2024-252221 PoCTask Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID parameter at /TaskManager/EditProject.php.
- CVE-2024-252231 PoCSimple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID parameter at…
- CVE-2024-252241 PoCA cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2024-252251 PoCA cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2024-252272 PoCsSQL Injection vulnerability in ABO.CMS version 5.8, allows remote attackers to execute arbitrary code, cause a denial of service (DoS),…
- CVE-2024-252281 PoCVinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerifydiyResult function…
- CVE-2024-252391 PoCSQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL commands via crafted…
- CVE-2024-252501 PoCSQL Injection vulnerability in code-projects Agro-School Management System 1.0 allows attackers to run arbitrary code via the Login page.
- CVE-2024-252511 PoCcode-projects Agro-School Management System 1.0 is suffers from Incorrect Access Control.
- CVE-2024-252531 PoCDriver Booster v10.6 was discovered to contain a buffer overflow via the Host parameter under the Customize proxy module.
- CVE-2024-252541 PoCSuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter.
- CVE-2024-252551 PoCSublime Text 4 was discovered to contain a command injection vulnerability via the New Build System module. NOTE: multiple third parties…
- CVE-2024-252601 PoCelfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
- CVE-2024-252691 PoClibheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service…
- CVE-2024-252881 PoCSLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php.
- CVE-2024-252912 PoCsDeskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.
- CVE-2024-252922 PoCsCross-site scripting (XSS) vulnerability in RenderTune v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted…
- CVE-2024-252932 PoCsmjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute.
- CVE-2024-252971 PoCCross Site Scripting (XSS) vulnerability in Bludit CMS version 3.15, allows remote attackers to execute arbitrary code and obtain…
- CVE-2024-252981 PoCAn issue was discovered in REDAXO version 5.15.1, allows attackers to execute arbitrary code and obtain sensitive information via…
- CVE-2024-253012 PoCsRedaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates.php.
- CVE-2024-253021 PoCSourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter.
- CVE-2024-253041 PoCCode-projects Simple School Managment System 1.0 allows SQL Injection via the 'apass' parameter at "School/index.php."
- CVE-2024-253051 PoCCode-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/index.php.
- CVE-2024-253061 PoCCode-projects Simple School Managment System 1.0 allows SQL Injection via the 'aname' parameter at "School/index.php".
- CVE-2024-253071 PoCCode-projects Cinema Seat Reservation System 1.0 allows SQL Injection via the 'id' parameter at "/Cinema-Reservation/booking.php?id=1."
- CVE-2024-253081 PoCCode-projects Simple School Managment System 1.0 allows SQL Injection via the 'name' parameter at School/teacher_login.php.
- CVE-2024-253091 PoCCode-projects Simple School Managment System 1.0 allows SQL Injection via the 'pass' parameter at School/teacher_login.php.
- CVE-2024-253101 PoCCode-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/delete.php?id=5."
- CVE-2024-253121 PoCCode-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/sub_delete.php?id=5."
- CVE-2024-253131 PoCCode-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at…
- CVE-2024-253141 PoCCode-projects Hotel Managment System 1.0, allows SQL Injection via the 'sid' parameter in Hotel/admin/show.php?sid=2.
- CVE-2024-253151 PoCCode-projects Hotel Managment System 1.0, allows SQL Injection via the 'rid' parameter in Hotel/admin/roombook.php?rid=2.
- CVE-2024-253161 PoCCode-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?eid=2.
- CVE-2024-253181 PoCCode-projects Hotel Managment System 1.0 allows SQL Injection via the 'pid' parameter in Hotel/admin/print.php?pid=2.
- CVE-2024-253201 PoCTongda OA v2017 and up to v11.9 was discovered to contain a SQL injection vulnerability via the $AFF_ID parameter at /affair/delete.php.
- CVE-2024-253441 PoCCross Site Scripting vulnerability in ITFlow.org before commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378 allows a remtoe attacker to…
- CVE-2024-253501 PoCSQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tprice parameters.
- CVE-2024-253511 PoCSQL Injection vulnerability in /zms/admin/changeimage.php in PHPGurukul Zoo Management System 1.0 allows attackers to run arbitrary SQL…
- CVE-2024-253661 PoCBuffer Overflow vulnerability in mz-automation.de libiec61859 v.1.4.0 allows a remote attacker to cause a denial of service via the…
- CVE-2024-253691 PoCA reflected Cross-Site Scripting (XSS) vulnerability in FUEL CMS 1.5.2allows attackers to run arbitrary code via crafted string after the…
- CVE-2024-253731 PoCTenda AC10V4.0 V16.03.10.20 was discovered to contain a stack overflow via the page parameter in the sub_49B384 function.
- CVE-2024-253761 PoCAn issue discovered in Thesycon Software Solutions Gmbh & Co. KG TUSBAudio MSI-based installers before 5.68.0 allows a local attacker to…
- CVE-2024-253812 PoCsThere is a Stored XSS Vulnerability in Emlog Pro 2.2.8 Article Publishing, due to non-filtering of quoted content.
- CVE-2024-253851 PoCAn issue in flvmeta v.1.2.2 allows a local attacker to cause a denial of service via the flvmeta/src/flv.c:375:21 function in flv_close.
- CVE-2024-253981 PoCIn Srelay (the SOCKS proxy and Relay) v.0.4.8p3, a specially crafted network payload can trigger a denial of service condition and disrupt…
- CVE-2024-254101 PoCflusity-CMS 2.33 is vulnerable to Unrestricted Upload of File with Dangerous Type in update_setting.php.
- CVE-2024-254111 PoCA cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted…
- CVE-2024-254121 PoCA cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted…
- CVE-2024-254153 PoCsA remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary…
- CVE-2024-254201 PoCAn issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the admin.authorizedJIDs…
- CVE-2024-254211 PoCAn issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component.
- CVE-2024-254231 PoCAn issue in MAXON CINEMA 4D R2024.2.0 allows a local attacker to execute arbitrary code via a crafted c4d_base.xdl64 file.
- CVE-2024-254281 PoCSQL Injection vulnerability in MRCMS v3.1.2 allows attackers to run arbitrary system commands via the status parameter.
- CVE-2024-254311 PoCAn issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate…
- CVE-2024-254341 PoCA cross-site scripting (XSS) vulnerability in Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload…
- CVE-2024-254361 PoCA cross-site scripting (XSS) vulnerability in the Production module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or…
- CVE-2024-254381 PoCA cross-site scripting (XSS) vulnerability in the Submission module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or…
- CVE-2024-254421 PoCAn issue in the HuginBase::PanoramaMemento::loadPTScript function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via…
- CVE-2024-254431 PoCAn issue in the HuginBase::ImageVariable<double>::linkWith function of Hugin v2022.0.0 allows attackers to cause a heap-use-after-free via…
- CVE-2024-254451 PoCImproper handling of values in HuginBase::PTools::Transform::transform of Hugin 2022.0.0 leads to an assertion failure.
- CVE-2024-254461 PoCAn issue in the HuginBase::PTools::setDestImage function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a…
- CVE-2024-254471 PoCAn issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing…
- CVE-2024-254481 PoCAn issue in the imlib_free_image_and_decache function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a…
- CVE-2024-254501 PoCimlib2 v1.9.1 was discovered to mishandle memory allocation in the function init_imlib_fonts().
- CVE-2024-254511 PoCBento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function.
- CVE-2024-254521 PoCBento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function.
- CVE-2024-254531 PoCBento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function.
- CVE-2024-254541 PoCBento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function.
- CVE-2024-254661 PoCDirectory Traversal vulnerability in React Native Document Picker before v.9.1.1 and fixed in v.9.1.1 allows a local attacker to execute…
- CVE-2024-255021 PoCDirectory Traversal vulnerability in flusity CMS v.2.4 allows a remote attacker to execute arbitrary code and obtain sensitive information…
- CVE-2024-255032 PoCsCross Site Scripting (XSS) vulnerability in Advanced REST Client v.17.0.9 allows a remote attacker to execute arbitrary code and obtain…
- CVE-2024-255071 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the email_attach_id parameter at…
- CVE-2024-255081 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at…
- CVE-2024-255091 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at…
- CVE-2024-255101 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at…
- CVE-2024-255111 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at…
- CVE-2024-255121 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the attach_id parameter at…
- CVE-2024-255131 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at…
- CVE-2024-255141 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at…
- CVE-2024-255151 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at…
- CVE-2024-255171 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the tbTable argument at /WebUtility/MF.aspx.
- CVE-2024-255181 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at…
- CVE-2024-255191 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the idlist parameter at /WorkFlow/wf_work_print.aspx.
- CVE-2024-255201 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at…
- CVE-2024-255211 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the txt_keyword parameter at get_company.aspx.
- CVE-2024-255221 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the office_missive_id parameter at…
- CVE-2024-255231 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /filemanage/file_memo.aspx.
- CVE-2024-255241 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at…
- CVE-2024-255251 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the filename parameter at…
- CVE-2024-255261 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the project_id parameter at…
- CVE-2024-255271 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at…
- CVE-2024-255281 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at…
- CVE-2024-255291 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at…
- CVE-2024-255301 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at…
- CVE-2024-255311 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at…
- CVE-2024-255321 PoCRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the bt_id parameter at /include/get_dict.aspx.
- CVE-2024-255331 PoCError messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFileUpdate.aspx).…
- CVE-2024-255751 PoCA type confusion vulnerability vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Lock object. A specially crafted…
- CVE-2024-2560023 PoCsWordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
- CVE-2024-256081 PoCHtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19,…
- CVE-2024-256181 PoCExternal OpenID Connect Account Takeover by E-Mail Change in mastodon
- CVE-2024-256231 PoCLack of media type verification of Activity Streams objects allows impersonation of remote accounts
- CVE-2024-256252 PoCsPimcore Host Header Injection in user invitation link
- CVE-2024-256271 PoCCross-Site Scripting (XSS) via File Upload in Alf.io
- CVE-2024-256341 PoCIDOR make user can read e-mail log sent by other events
- CVE-2024-256351 PoCIDOR Vulnerability: Allowing Organization Owner to view the other Organizations API KEY and USERS
- CVE-2024-256361 PoCLack of media type verification of Activity Streams objects allows impersonation and takeover of remote accounts
- CVE-2024-256391 PoCPrompt Injection triggered XSS vulnerability in Khoj Obsidian, Desktop and Web clients
- CVE-2024-2564111 PoCsCacti RCE vulnerability when importing packages
- CVE-2024-256481 PoCA use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a ComboBox widget. A specially crafted JavaScript…
- CVE-2024-257121 PoChttp-swagger before 1.2.6 allows XSS via PUT requests, because a file that has been uploaded (via httpSwagger.WrapHandler and…
- CVE-2024-257132 PoCsyyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks.…
- CVE-2024-257232 PoCsZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the…
- CVE-2024-257341 PoCAn issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid…
- CVE-2024-257353 PoCsAn issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP…
- CVE-2024-257361 PoCAn issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /device/reboot GET…
- CVE-2024-258071 PoCCross Site Scripting (XSS) vulnerability in Lychee 3.1.6, allows remote attackers to execute arbitrary code and obtain sensitive…
- CVE-2024-258081 PoCCross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary code via the create…
- CVE-2024-258111 PoCAn access control issue in Dreamer CMS v4.0.1 allows attackers to download backup files and leak sensitive information.
- CVE-2024-258303 PoCsF-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated,…
- CVE-2024-258311 PoCF-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input sanitization. An…
- CVE-2024-258323 PoCsF-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of…
- CVE-2024-258331 PoCF-logic DataCube3 v1.0 is vulnerable to unauthenticated SQL injection, which could allow an unauthenticated malicious actor to execute…
- CVE-2024-258461 PoCIn the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload…
- CVE-2024-258521 PoCLinksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access…
- CVE-2024-258661 PoCA SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL…
- CVE-2024-258671 PoCA SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL…
- CVE-2024-258681 PoCA Cross Site Scripting (XSS) vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute…
- CVE-2024-258691 PoCAn Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute…
- CVE-2024-258911 PoCChurchCRM 5.5.0 FRBidSheets.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.
- CVE-2024-258921 PoCChurchCRM 5.5.0 ConfirmReport.php is vulnerable to Blind SQL Injection (Time-based) via the familyId GET parameter.
- CVE-2024-258931 PoCChurchCRM 5.5.0 FRCertificates.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.
- CVE-2024-258941 PoCChurchCRM 5.5.0 /EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EventCount POST parameter.
- CVE-2024-258951 PoCA reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.5.0 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2024-258961 PoCChurchCRM 5.5.0 EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EID POST parameter.
- CVE-2024-258972 PoCsChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.
- CVE-2024-258981 PoCA XSS vulnerability was found in the ChurchCRM v.5.5.0 functionality, edit your event, where malicious JS or HTML code can be inserted in…
- CVE-2024-259381 PoCA use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Barcode widget. A specially crafted JavaScript code…
- CVE-2024-259731 PoCMultiple Stored Cross-Site Scripting Vulnerabilities
- CVE-2024-259742 PoCsStored Cross-Site Scripting (XSS) within the Media Center