CVE-2024-27000 to CVE-2024-27999
109 CVEs with public proof-of-concept exploits.
- CVE-2024-270811 PoCESPHome remote code execution via arbitrary file write
- CVE-2024-270821 PoCCacti Cross-site Scripting vulnerability when managing trees
- CVE-2024-270882 PoCses5-ext Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`
- CVE-2024-270921 PoCContent spoofing - real Hoppscotch emails
- CVE-2024-270932 PoCsMinder trusts client-provided mapping from repo name to upstream ID
- CVE-2024-271152 PoCsRemote Code Execution through File Upload in SOPlanning before 1.52.02
- CVE-2024-271303 PoCsQTS, QuTS hero
- CVE-2024-271322 PoCsInsufficient sanitization in MLflow leads to XSS when running an untrusted recipe.
- CVE-2024-271331 PoCInsufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset.
- CVE-2024-271731 PoCinsecure upload
- CVE-2024-2719828 PoCsKEVIn JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
- CVE-2024-271998 PoCsKEVIn JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
- CVE-2024-272822 PoCsAn issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to…
- CVE-2024-272853 PoCsYARD's default template vulnerable to Cross-site Scripting in generated frames.html
- CVE-2024-272871 PoCESPHome vulnerable to stored Cross-site Scripting in edit configuration file API
- CVE-2024-272924 PoCsDocassemble unauthorized access through URL manipulation
- CVE-2024-272951 PoCDirectus MySQL accent insensitive email matching
- CVE-2024-272992 PoCsphpMyFAQ SQL Injection at "Save News"
- CVE-2024-273002 PoCsphpMyFAQ Stored XSS at user email
- CVE-2024-273011 PoCPrivilege Escalation Abusing installer in SupportApp
- CVE-2024-273022 PoCsAuthorization Bypass Through User-Controlled Key in go-zero
- CVE-2024-273041 PoCpgx SQL Injection via Protocol Message Size Overflow
- CVE-2024-273164 PoCsApache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames
- CVE-2024-2734811 PoCsKEVApache HugeGraph-Server: Command execution in gremlin
- CVE-2024-273564 PoCsAn issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical…
- CVE-2024-273971 PoCnetfilter: nf_tables: use timestamp to check for set element timeout
- CVE-2024-273981 PoCBluetooth: Fix use-after-free bugs caused by sco_sock_timeout
- CVE-2024-274011 PoCfirewire: nosy: ensure user_length is taken into account when fetching packet contents
- CVE-2024-274431 PoCKEVAn issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the…
- CVE-2024-274481 PoCMailDev 2 through 2.1.0 allows Remote Code Execution via a crafted Content-ID header for an e-mail attachment, leading to…
- CVE-2024-274531 PoCIn Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of…
- CVE-2024-274603 PoCsA privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below.
- CVE-2024-274741 PoCLeantime 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF). This vulnerability allows malicious actors to perform unauthorized…
- CVE-2024-274761 PoCLeantime 3.0.6 is vulnerable to HTML Injection via /dashboard/show#/tickets/newTicket.
- CVE-2024-274772 PoCsIn Leantime 3.0.6, a Cross-Site Scripting vulnerability exists within the ticket creation and modification functionality, allowing…
- CVE-2024-274891 PoCAn issue in the DelFile() function of WMCMS v4.4 allows attackers to delete arbitrary files via a crafted POST request.
- CVE-2024-274971 PoCLinksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.
- CVE-2024-275151 PoCOsclass 5.1.2 is vulnerable to SQL Injection.
- CVE-2024-275171 PoCWebasyst 2.9.9 has a Cross-Site Scripting (XSS) vulnerability, Attackers can create blogs containing malicious code after gaining blog…
- CVE-2024-275181 PoCAn issue in SUPERAntiSyware Professional X 10.0.1262 and 10.0.1264 allows unprivileged attackers to escalate privileges via a restore of a…
- CVE-2024-275271 PoCwasm3 139076a is vulnerable to Denial of Service (DoS).
- CVE-2024-275281 PoCwasm3 139076a suffers from Invalid Memory Read, leading to DoS and potential Code Execution.
- CVE-2024-275291 PoCwasm3 139076a contains memory leaks in Read_utf8.
- CVE-2024-275301 PoCwasm3 139076a contains a Use-After-Free in ForEachModule.
- CVE-2024-275321 PoCwasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function…
- CVE-2024-275581 PoCStupid Simple CMS 1.2.4 is vulnerable to Cross Site Scripting (XSS) within the blog title of the settings.
- CVE-2024-275591 PoCStupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /save_settings.php
- CVE-2024-275611 PoCA Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the…
- CVE-2024-275631 PoCA Server-Side Request Forgery (SSRF) in the getFileFromRepo function of WonderCMS v3.1.3 allows attackers to force the application to make…
- CVE-2024-275644 PoCspictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an…
- CVE-2024-275651 PoCA Server-Side Request Forgery (SSRF) in weixin.php of ChatGPT-wechat-personal commit a0857f6 allows attackers to force the application to…
- CVE-2024-275691 PoCLBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the init_nvram function. This…
- CVE-2024-275701 PoCLBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the generate_conf_router function. This…
- CVE-2024-275711 PoCLBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the makeCurRemoteApList function. This…
- CVE-2024-275721 PoCLBT T300-T390 v2.2.1.8 were discovered to contain a stack overflow via the ApCliSsid parameter in the updateCurAPlist function. This…
- CVE-2024-276121 PoCNumbas editor before 7.3 mishandles editing of themes and extensions.
- CVE-2024-276201 PoCAn issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request to the API.
- CVE-2024-276221 PoCA remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This…
- CVE-2024-276231 PoCCMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within the Design Manager,…
- CVE-2024-276302 PoCsInsecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted…
- CVE-2024-276312 PoCsCross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via…
- CVE-2024-276322 PoCsAn issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function.
- CVE-2024-276551 PoCD-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the SOAPACTION parameter. This vulnerability allows attackers…
- CVE-2024-276561 PoCD-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Cookie parameter. This vulnerability allows attackers to…
- CVE-2024-276571 PoCD-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the User-Agent parameter. This vulnerability allows attackers…
- CVE-2024-276581 PoCD-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_4484A8(). This vulnerability allows attackers to…
- CVE-2024-276591 PoCD-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_42AF30(). This vulnerability allows attackers to…
- CVE-2024-276601 PoCD-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_41C488(). This vulnerability allows attackers to…
- CVE-2024-276611 PoCD-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_4484A8(). This vulnerability allows attackers to…
- CVE-2024-276621 PoCD-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_4110f4(). This vulnerability allows attackers to…
- CVE-2024-276651 PoCUnifiedtransform v2.X is vulnerable to Stored Cross-Site Scripting (XSS) via file upload feature in Syllabus module.
- CVE-2024-276681 PoCFlusity-CMS v2.33 is affected by: Cross Site Scripting (XSS) in 'Custom Blocks.'
- CVE-2024-276741 PoCMacro Expert through 4.9.4 allows BUILTIN\Users:(OI)(CI)(M) access to the "%PROGRAMFILES(X86)%\GrassSoft\Macro Expert" folder and thus an…
- CVE-2024-276801 PoCFlusity-CMS v2.33 is vulnerable to Cross Site Scripting (XSS) in the "Contact form."
- CVE-2024-276863 PoCsMikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via…
- CVE-2024-276891 PoCStupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via /update-article.php.
- CVE-2024-276941 PoCFlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the /system/share/ztree_category_edit.
- CVE-2024-277031 PoCCross Site Scripting vulnerability in Leantime 3.0.6 allows a remote attacker to execute arbitrary code via the to-do title parameter.
- CVE-2024-277051 PoCCross Site Scripting vulnerability in Leantime v3.0.6 allows attackers to execute arbitrary code via upload of crafted PDF file to the…
- CVE-2024-277181 PoCSQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain sensitive…
- CVE-2024-277191 PoCA cross site scripting (XSS) vulnerability in rems FAQ Management System v.1.0 allows a remote attacker to obtain sensitive information…
- CVE-2024-277432 PoCsCross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted…
- CVE-2024-277442 PoCsCross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted…
- CVE-2024-277462 PoCsSQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to…
- CVE-2024-277472 PoCsFile Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to…
- CVE-2024-277571 PoCflusity CMS through 2.45 allows tools/addons_model.php Gallery Name XSS. The reporter indicates that this product "ceased its development…
- CVE-2024-277641 PoCAn issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component.
- CVE-2024-277651 PoCDirectory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information via the…
- CVE-2024-277663 PoCsAn issue in MariaDB v.11.1 allows a remote attacker to execute arbitrary code via the lib_mysqludf_sys.so function. NOTE: this is disputed…
- CVE-2024-278041 PoCThe issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, watchOS 10.5, macOS…
- CVE-2024-278151 PoCAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tvOS 17.5, visionOS 1.2, iOS 17.5 and…
- CVE-2024-278211 PoCA path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma…
- CVE-2024-278221 PoCA logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to gain root…
- CVE-2024-278301 PoCThis issue was addressed through improved state management. This issue is fixed in tvOS 17.5, visionOS 1.2, Safari 17.5, iOS 17.5 and…
- CVE-2024-278761 PoCA race condition was addressed with improved locking. This issue is fixed in macOS Ventura 13.7, iOS 17.7 and iPadOS 17.7, visionOS 2, iOS…
- CVE-2024-279131 PoCospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon…
- CVE-2024-279141 PoCReflected Cross-Site Scripting (XSS) in search engine when debug mode is enabled in GLPI
- CVE-2024-279162 PoCs`GetRepositoryByName`, `DeleteRepositoryByName` and `GetArtifactByName` allow access of arbitrary repositories in Minder by any…
- CVE-2024-279191 PoCHTTP/2: memory exhaustion due to CONTINUATION frame flood
- CVE-2024-279212 PoCsGrav File Upload Path Traversal vulnerability
- CVE-2024-279232 PoCsRemote Code Execution by uploading a phar file using frontmatter
- CVE-2024-279271 PoCRSSHub vulnerable to SSRF in /mastodon, /zjoi, and /m4
- CVE-2024-279321 PoCDeno's improper suffix match testing for DENO_AUTH_TOKENS
- CVE-2024-279332 PoCsDeno arbitrary file descriptor close via `op_node_ipc_pipe()` leading to permission prompt bypass
- CVE-2024-279342 PoCs*const c_void / ExternalPointer unsoundness leading to use-after-free
- CVE-2024-279362 PoCsDeno interactive permission prompt spoofing via improper ANSI stripping
- CVE-2024-279546 PoCsWordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability
- CVE-2024-2795624 PoCsWordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability
- CVE-2024-279832 PoCsAn attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2…