CVE-2024-26000 to CVE-2024-26999
41 CVEs with public proof-of-concept exploits.
- CVE-2024-260262 PoCsBIG-IP Central Manager SQL Injection
- CVE-2024-261342 PoCsCBOR2 decoder has potential buffer overflow
- CVE-2024-261351 PoCMeshCentral cross-site websocket hijacking (CSWSH) vulnerability
- CVE-2024-261441 PoCPossible Sensitive Session Information Leak in Active Storage
- CVE-2024-261492 PoCsVyper _abi_decode Memory Overflow
- CVE-2024-261511 PoCPotentially untrusted input is rendered as HTML in final output
- CVE-2024-261522 PoCsLabel Studio vulnerable to Cross-site Scripting if `<Choices>` or `<Labels>` are used in labeling config
- CVE-2024-261601 PoCWindows Cloud Files Mini Filter Driver Information Disclosure Vulnerability
- CVE-2024-262091 PoCMicrosoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
- CVE-2024-262181 PoCWindows Kernel Elevation of Privilege Vulnerability
- CVE-2024-2622910 PoCsWindows CSC Service Elevation of Privilege Vulnerability
- CVE-2024-262302 PoCsWindows Telephony Server Elevation of Privilege Vulnerability
- CVE-2024-262561 PoCLibarchive Remote Code Execution Vulnerability
- CVE-2024-262841 PoCUtilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, if the victim had…
- CVE-2024-262911 PoCAuthenticated Arbitrary File Read affecting Avid NEXIS
- CVE-2024-263041 PoCThere is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated remote code…
- CVE-2024-263311 PoCReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind the cookie value…
- CVE-2024-263331 PoCswftools v0.9.2 was discovered to contain a segmentation violation via the function free_lines at swftools/lib/modules/swfshape.c.
- CVE-2024-263341 PoCswftools v0.9.2 was discovered to contain a segmentation violation via the function compileSWFActionCode at…
- CVE-2024-263351 PoCswftools v0.9.2 was discovered to contain a segmentation violation via the function state_free at swftools/src/swfc-history.c.
- CVE-2024-263371 PoCswftools v0.9.2 was discovered to contain a segmentation violation via the function s_font at swftools/src/swfc.c.
- CVE-2024-263391 PoCswftools v0.9.2 was discovered to contain a strcpy parameter overlap via /home/swftools/src/swfc+0x48318a.
- CVE-2024-263421 PoCA Null pointer dereference in usr/sbin/httpd in ASUS AC68U 3.0.0.4.384.82230 allows remote attackers to trigger DoS via network packet.
- CVE-2024-263491 PoCflusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_translation.php
- CVE-2024-263521 PoCflusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_places.php
- CVE-2024-264451 PoCflusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_place.php
- CVE-2024-264751 PoCAn issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of service via the…
- CVE-2024-264771 PoCAn issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the api parameter of the…
- CVE-2024-264901 PoCA cross-site scripting (XSS) vulnerability in the Addon JD Simple module of flusity-CMS v2.33 allows attackers to execute arbitrary web…
- CVE-2024-264911 PoCA cross-site scripting (XSS) vulnerability in the Addon JD Flusity 'Media Gallery with description' module of flusity-CMS v2.33 allows…
- CVE-2024-264922 PoCsAn issue in Online Diagnostic Lab Management System 1.0 allows a remote attacker to gain control of a 'Staff' user account via a crafted…
- CVE-2024-264951 PoCCross Site Scripting (XSS) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and…
- CVE-2024-265031 PoCUnrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to run arbitrary code…
- CVE-2024-265211 PoCHTML Injection vulnerability in CE Phoenix v1.0.8.20 and before allows a remote attacker to execute arbitrary code, escalate privileges,…
- CVE-2024-265291 PoCAn issue in mz-automation libiec61850 v.1.5.3 and before, allows a remote attacker to cause a denial of service (DoS) via the…
- CVE-2024-265401 PoCA heap-based buffer overflow in Clmg before 3.3.3 can occur via a crafted file to cimg_library::CImg<unsigned char>::_load_analyze.
- CVE-2024-265421 PoCCross Site Scripting vulnerability in Bonitasoft, S.A v.7.14. and fixed in v.9.0.2, 8.0.3, 7.15.7, 7.14.8 allows attackers to execute…
- CVE-2024-265571 PoCCodiad v2.8.4 allows reflected XSS via the components/market/dialog.php type parameter.
- CVE-2024-265741 PoCInsecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code via a crafted script…
- CVE-2024-265812 PoCsnetfilter: nft_set_rbtree: skip end interval element from gc
- CVE-2024-268171 PoCamdkfd: use calloc instead of kzalloc to avoid integer overflow