CVE-2024-28000 to CVE-2024-28999
145 CVEs with public proof-of-concept exploits.
- CVE-2024-280008 PoCsWordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
- CVE-2024-280521 PoCThe WBR-6012 is a wireless SOHO router. It is a low-cost device which functions as an internet gateway for homes and small offices while…
- CVE-2024-280561 PoCAmazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the…
- CVE-2024-280661 PoCIn Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).
- CVE-2024-280853 PoCswall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals…
- CVE-2024-280882 PoCsLangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a…
- CVE-2024-281021 PoCJWCrypto vulnerable to JWT bomb Attack in `deserialize` function
- CVE-2024-281052 PoCsphpMyFAQ's File Upload Bypass at Category Image Leads to RCE
- CVE-2024-281061 PoCphpMyFAQ Stored XSS at FAQ News Content
- CVE-2024-281071 PoCphpMyFAQ SQL injections at insertentry & saveentry
- CVE-2024-281081 PoCphpMyFAQ Stored HTML Injection at contentLink
- CVE-2024-281164 PoCsServer-Side Template Injection (SSTI) with Grav CMS security sandbox bypass
- CVE-2024-281171 PoCGrav vulnerable to Server Side Template Injection (SSTI)
- CVE-2024-281181 PoCGrav vulnerable to Server Side Template Injection (SSTI)
- CVE-2024-281191 PoCGrav vulnerable to Server Side Template Injection (SSTI) via Twig escape handler
- CVE-2024-281202 PoCsAPI key leak in codeium-chrome
- CVE-2024-281222 PoCsJWX vulnerable to a denial of service attack using compressed JWE message
- CVE-2024-281571 PoCJenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-site scripting (XSS)…
- CVE-2024-281821 PoCReading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usage
- CVE-2024-281851 PoCJudge0 vulnerable to Sandbox Escape via Symbolic Link
- CVE-2024-281891 PoCJudge0 vulnerable to Sandbox Escape Patch Bypass via chown running on Symbolic Link
- CVE-2024-281921 PoCNoSQL Injection Leading to Authentication Bypass in your_spotify
- CVE-2024-281931 PoCDisclosure of Spotify API Access Tokens to Guest Users Using Public Tokens in your_spotify
- CVE-2024-281941 PoCAuthentication Bypass Because of Hardcoded JWT Secret in your_spotify
- CVE-2024-281951 PoCCross-Site Request Forgery (CSRF) vulnerability in API and login in your_spotify
- CVE-2024-281961 PoCClickjacking in your_spotify
- CVE-2024-282001 PoCN-central Authentication Bypass
- CVE-2024-282312 PoCsManipulated DATA Submessage causes a heap-buffer-overflow error
- CVE-2024-282321 PoCUsername Enumeration in CasaOS via bypass of CVE-2024-24766
- CVE-2024-282372 PoCsOctoPrint XSS via the "Snapshot Test" feature in Classic Webcam plugin settings
- CVE-2024-282391 PoCURL Redirection to Untrusted Site in OAuth2/OpenID in directus
- CVE-2024-282472 PoCsPihole Authenticated Arbitrary File Read with root privileges
- CVE-2024-282532 PoCsSpEL Injection in `PUT /api/v1/policies` in OpenMetadata
- CVE-2024-282541 PoCSpEL Injection in `GET /api/v1/events/subscriptions/validation/condition/<expr>` in OpenMetadata
- CVE-2024-282557 PoCsAuthentication Bypass in OpenMetadata
- CVE-2024-282651 PoCIBOS v4.5.5 has an arbitrary file deletion vulnerability via \system\modules\dashboard\controllers\LoginController.php.
- CVE-2024-282831 PoCThere is stack-based buffer overflow vulnerability in pc_change_act function in Linksys E1000 router firmware version v.2.1.03 and before,…
- CVE-2024-282861 PoCIn mz-automation libiec61850 v1.4.0, a NULL Pointer Dereference was detected in the mmsServer_handleFileCloseRequest.c function of…
- CVE-2024-283181 PoCgpac 2.3-DEV-rev921-g422b78ecf-master was discovered to contain a out of boundary write vulnerability via swf_get_string at…
- CVE-2024-283191 PoCgpac 2.3-DEV-rev921-g422b78ecf-master was discovered to contain an out of boundary read vulnerability via gf_dash_setup_period…
- CVE-2024-283202 PoCsInsecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows attackers to manipulate user parameters…
- CVE-2024-283222 PoCsSQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allows attackers to…
- CVE-2024-283231 PoCThe bwdates-report-result.php file in Phpgurukul User Registration & Login and User Management System 3.1 contains a potential security…
- CVE-2024-283381 PoCA login bypass in TOTOLINK A8000RU V7.1cu.643_B20200521 allows attackers to login to Administrator accounts via providing a crafted…
- CVE-2024-283441 PoCAn Open Redirect vulnerability was found in Sipwise C5 NGCP Dashboard below mr11.5.1. The Open Redirect vulnerability allows attackers to…
- CVE-2024-283451 PoCAn issue discovered in Sipwise C5 NGCP Dashboard below mr11.5.1 allows a low privileged user to access the Journal endpoint by directly…
- CVE-2024-283831 PoCTenda AX12 v1.0 v22.03.01.16 was discovered to contain a stack overflow via the ssid parameter in the sub_431CF0 function.
- CVE-2024-2839725 PoCsAn issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call.
- CVE-2024-284171 PoCWebedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.
- CVE-2024-284181 PoCWebedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php
- CVE-2024-284212 PoCsSQL Injection vulnerability in Razor 0.8.0 allows a remote attacker to escalate privileges via the ChannelModel::updateapk method of the…
- CVE-2024-284291 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/archives_do.php
- CVE-2024-284301 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_edit.php.
- CVE-2024-284311 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_del.php.
- CVE-2024-284321 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_edit.php.
- CVE-2024-284341 PoCThe CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg file can trigger the…
- CVE-2024-284411 PoCFile Upload vulnerability in magicflue v.7.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the…
- CVE-2024-284421 PoCDirectory Traversal vulnerability in Yealink VP59 v.91.15.0.118 allows a physically proximate attacker to obtain sensitive information via…
- CVE-2024-284581 PoCNull Pointer Dereference vulnerability in swfdump in swftools 0.9.2 allows attackers to crash the appliation via the function…
- CVE-2024-285351 PoCTenda AC18 V15.03.05.05 has a stack overflow vulnerability in the mitInterface parameter of fromAddressNat function.
- CVE-2024-285371 PoCTenda AC18 V15.03.05.05 has a stack overflow vulnerability in the page parameter of fromNatStaticSetting function.
- CVE-2024-285451 PoCTenda AC18 V15.03.05.05 contains a command injection vulnerablility in the deviceName parameter of formsetUsbUnload function.
- CVE-2024-285471 PoCTenda AC18 V15.03.05.05 has a stack overflow vulnerability in the firewallEn parameter of formSetFirewallCfg function.
- CVE-2024-285501 PoCTenda AC18 V15.03.05.05 has a stack overflow vulnerability in the filePath parameter of formExpandDlnaFile function.
- CVE-2024-285511 PoCTenda AC18 V15.03.05.05 has a stack overflow vulnerability in the ssid parameter of form_fast_setting_wifi_set function.
- CVE-2024-285531 PoCTenda AC18 V15.03.05.05 has a stack overflow vulnerability in the entrys parameter fromAddressNat function.
- CVE-2024-285561 PoCSQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate…
- CVE-2024-285571 PoCSQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate…
- CVE-2024-285581 PoCSQL Injection vulnerability in sourcecodester Petrol pump management software v1.0, allows remote attackers to execute arbitrary code,…
- CVE-2024-285621 PoCBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the…
- CVE-2024-285631 PoCBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the…
- CVE-2024-285641 PoCBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the…
- CVE-2024-285651 PoCBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the…
- CVE-2024-285661 PoCBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the…
- CVE-2024-285671 PoCBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the…
- CVE-2024-285681 PoCBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the…
- CVE-2024-285691 PoCBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the…
- CVE-2024-285701 PoCBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the…
- CVE-2024-285711 PoCBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the…
- CVE-2024-285721 PoCBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the…
- CVE-2024-285731 PoCBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the…
- CVE-2024-285741 PoCBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the…
- CVE-2024-285751 PoCBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the…
- CVE-2024-285761 PoCBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the…
- CVE-2024-285771 PoCNull Pointer Dereference vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service…
- CVE-2024-285781 PoCBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Load()…
- CVE-2024-285791 PoCBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service (DoS) via the…
- CVE-2024-285801 PoCBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the…
- CVE-2024-285811 PoCBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the…
- CVE-2024-285821 PoCBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the…
- CVE-2024-285831 PoCBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the…
- CVE-2024-285841 PoCNull Pointer Dereference vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to cause a denial of service…
- CVE-2024-285891 PoCAn issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attackers to execute…
- CVE-2024-285952 PoCsSQL Injection vulnerability in Employee Management System v1.0 allows attackers to run arbitrary SQL commands via the admin_id parameter…
- CVE-2024-286233 PoCsRiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_section.
- CVE-2024-286391 PoCBuffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022, allow remote attackers to…
- CVE-2024-286651 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_add.php
- CVE-2024-286661 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/media_add.php
- CVE-2024-286671 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/templets_one_edit.php
- CVE-2024-286681 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/mychannel_add.php
- CVE-2024-286691 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/freelist_edit.php.
- CVE-2024-286701 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/freelist_main.php.
- CVE-2024-286711 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/stepselect_main.php.
- CVE-2024-286721 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/media_edit.php.
- CVE-2024-286731 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/mychannel_edit.php.
- CVE-2024-286751 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/diy_edit.php
- CVE-2024-286761 PoCDedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via /dede/article_edit.php.
- CVE-2024-286771 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/article_keywords_main.php.
- CVE-2024-286781 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component…
- CVE-2024-286791 PoCDedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via Photo Collection.
- CVE-2024-286801 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/diy_add.php.
- CVE-2024-286811 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/plus_edit.php.
- CVE-2024-286821 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/sys_cache_up.php.
- CVE-2024-286831 PoCDedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via create file.
- CVE-2024-286841 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/module_main.php
- CVE-2024-287131 PoCAn issue in Mblog Blog system v.3.5.0 allows an attacker to execute arbitrary code via a crafted file to the theme management feature.
- CVE-2024-287141 PoCSQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the groupid parameter.
- CVE-2024-287151 PoCCross Site Scripting vulnerability in DOraCMS v.2.18 and before allows a remote attacker to execute arbitrary code via the markdown0…
- CVE-2024-287321 PoCAn issue was discovered in OFPMatch in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to cause a denial of service…
- CVE-2024-287341 PoCCross Site Scripting vulnerability in Unit4 Financials by Coda prior to 2023Q4 allows a remote attacker to run arbitrary code via a…
- CVE-2024-287351 PoCUnit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows…
- CVE-2024-287391 PoCAn issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.
- CVE-2024-287402 PoCsCross Site Scripting vulnerability in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via the…
- CVE-2024-287412 PoCsCross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php…
- CVE-2024-287522 PoCsApache CXF SSRF Vulnerability using the Aegis databinding
- CVE-2024-287561 PoCThe SolarEdge mySolarEdge application before 2.20.1 for Android has a certificate verification issue that allows a Machine-in-the-middle…
- CVE-2024-287572 PoCslibexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via…
- CVE-2024-287621 PoCIBM Db2 denial of service
- CVE-2024-287841 PoCIBM QRadar cross-site scripting
- CVE-2024-288031 PoCCross-site scripting (XSS) vulnerability in Italtel S.p.A. i-MCS NFV v.12.1.0-20211215 allows unauthenticated remote attackers to inject…
- CVE-2024-288041 PoCAn issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Stored Cross-site scripting (XSS) can occur via POST.
- CVE-2024-288472 PoCsSpEL Injection in `PUT /api/v1/events/subscriptions` in OpenMetadata
- CVE-2024-288481 PoCSpEL Injection in `GET /api/v1/policies/validation/condition/<expr>` in OpenMetadata
- CVE-2024-288492 PoCsProxy-Authorization header kept across hosts in follow-redirects
- CVE-2024-288521 PoCAmpache has multiple reflective XSS vulnerabilities
- CVE-2024-288542 PoCsSlow loris vulnerability with default configuration in tls-listener
- CVE-2024-288592 PoCsGadget chain in Symfony 1 due to vulnerable Swift Mailer dependency
- CVE-2024-288612 PoCsGadget chain in Symfony 1 due to uncontrolled unserialized input in sfNamespacedParameterHolder
- CVE-2024-288631 PoCnode-tar vulnerable to denial of service while parsing a tar file due to lack of folders count validation
- CVE-2024-288881 PoCA use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a checkbox field object. A specially crafted…
- CVE-2024-289551 PoCAffected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the device can examine…
- CVE-2024-289861 PoCKEVSolarWinds Web Help Desk Java Deserialization Remote Code Execution Vulnerability
- CVE-2024-289877 PoCsKEVSolarWinds Web Help Desk Hardcoded Credential Vulnerability
- CVE-2024-2899514 PoCsKEVSolarWinds Serv-U L Directory Transversal Vulnerability
- CVE-2024-289992 PoCsSolarWinds Platform Race Condition Vulnerability