CVE-2024-29000 to CVE-2024-29999
75 CVEs with public proof-of-concept exploits.
- CVE-2024-290251 PoCNetty HttpPostRequestDecoder can OOM
- CVE-2024-290282 PoCsmemos vulnerable to an SSRF in /o/get/httpmeta
- CVE-2024-290292 PoCsmemos vulnerable to an SSRF in /o/get/image
- CVE-2024-290302 PoCsmemos vulnerable to an SSRF in /api/resource
- CVE-2024-290311 PoCMeshery SQL Injection vulnerability
- CVE-2024-290322 PoCs`qiskit_ibm_runtime.RuntimeDecoder` can execute arbitrary code
- CVE-2024-290381 PoCtpm2 does not detect if quote was not generated by TPM
- CVE-2024-290391 PoCMissing check in tpm2_checkquote allows attackers to misrepresent the TPM state
- CVE-2024-290422 PoCsTranslate Cache Poisoning Vulnerability
- CVE-2024-290501 PoCWindows Cryptographic Services Remote Code Execution Vulnerability
- CVE-2024-290591 PoCKEV.NET Framework Information Disclosure Vulnerability
- CVE-2024-290751 PoCActive debug code vulnerability exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is…
- CVE-2024-290902 PoCsWordPress AI Engine plugin <= 2.1.4 - Server Side Request Forgery (SSRF) vulnerability
- CVE-2024-291371 PoCWordPress Tourfic plugin <= 2.11.7 - Reflected Cross Site Scripting (XSS) vulnerability
- CVE-2024-291381 PoCWordPress Restrict User Access plugin <= 2.5 - Reflected Cross Site Scripting (XSS) vulnerability
- CVE-2024-291792 PoCsphpMyFAQ Stored Cross-site Scripting at File Attachments
- CVE-2024-291802 PoCswebpack-dev-middleware Path Traversal vulnerability
- CVE-2024-291811 PoC@strapi/plugin-content-manager leaks data via relations via the Admin Panel
- CVE-2024-291862 PoCsSlow String Operations via MultiPart Requests in Event-Driven Functions
- CVE-2024-291901 PoCMobSF SSRF Vulnerability on assetlinks_check(act_name, well_knowns)
- CVE-2024-291911 PoCGHSL-2023-205 gotortc DOM-based Cross-site Scripting vulnerability
- CVE-2024-291921 PoCGHSL-2023-206 gotortc Cross-Site Request Forgery vulnerability
- CVE-2024-291931 PoCGHSL-2023-207 gotortc DOM-based Cross-site Scripting vulnerability
- CVE-2024-291941 PoCOneUptime Vulnerable to a Privilege Escalation via Local Storage Key Manipulation
- CVE-2024-291961 PoCphpMyFAQ Path Traversal in Attachments
- CVE-2024-291971 PoCPimcore Preview Documents are not restricted to logged in users anymore
- CVE-2024-291982 PoCsGeoServer Vulnerable to Unauthenticated SSRF via TestWfsPost
- CVE-2024-292002 PoCsAPI returns timesheet entries a user should not be authorized to view
- CVE-2024-2926910 PoCsAn issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the Cmd parameter.
- CVE-2024-292711 PoCReflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.7, allows remote attackers to execute arbitrary code and…
- CVE-2024-292723 PoCsArbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute arbitrary code and…
- CVE-2024-292731 PoCThere is Stored Cross-Site Scripting (XSS) in dzzoffice 2.02.1 SC UTF8 in uploadfile to index.php, with the XSS payload in an SVG document.
- CVE-2024-292751 PoCSQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive…
- CVE-2024-292911 PoCAn issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/logs/laravel.log.…
- CVE-2024-292962 PoCsA user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a…
- CVE-2024-293381 PoCAnchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/categories/delete/2.
- CVE-2024-293661 PoCA command injection vulnerability exists in the cgibin binary in DIR-845L router firmware <= v1.01KRb03.
- CVE-2024-293681 PoCAn arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extension restrictions via…
- CVE-2024-293741 PoCA Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.
- CVE-2024-293751 PoCCSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a crafted .ibnrs file to…
- CVE-2024-293843 PoCsAn issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information via the content.js and parseCSSRules…
- CVE-2024-293851 PoCDIR-845L router <= v1.01KRb03 has an Unauthenticated remote code execution vulnerability in the cgibin binary via soapcgi_main function.
- CVE-2024-293861 PoCprojeqtor up to 11.2.0 was discovered to contain a SQL injection vulnerability via the component /view/criticalResourceExport.php.
- CVE-2024-293871 PoCprojeqtor up to 11.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /view/print.php.
- CVE-2024-293901 PoCDaily Expenses Management System version 1.0, developed by PHP Gurukul, contains a time-based blind SQL injection vulnerability in the…
- CVE-2024-293921 PoCSilverpeas Core 6.3 is vulnerable to Cross Site Scripting (XSS) via ClipboardSessionController.
- CVE-2024-294011 PoCxzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything.
- CVE-2024-294091 PoCFile Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header.
- CVE-2024-294612 PoCsAn issue in Floodlight SDN OpenFlow Controller v.1.2 allows a remote attacker to cause a denial of service via the datapath id component.
- CVE-2024-294991 PoCAnchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/users/delete/2.
- CVE-2024-295041 PoCCross Site Scripting vulnerability in Summernote v.0.8.18 and before allows a remote attacker to execute arbtirary code via a crafted…
- CVE-2024-295104 PoCsArtifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.
- CVE-2024-296711 PoCBuffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code via the POST request…
- CVE-2024-296841 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /src/dede/makehtml_homepage.php allowing a…
- CVE-2024-296861 PoCServer-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary code via a crafted…
- CVE-2024-297921 PoCWordPress Unlimited Elements for Elementor plugin <= 1.5.93 - Reflected Cross Site Scripting (XSS) vulnerability
- CVE-2024-298244 PoCsKEVAn unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the…
- CVE-2024-298471 PoCDeserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote…
- CVE-2024-298491 PoCVeeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.
- CVE-2024-298551 PoCHard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator
- CVE-2024-298631 PoCA race condition in the installer executable in Qlik Qlikview before versions May 2022 SR3 (12.70.20300) and May 2023 SR2 (12,80.20200)…
- CVE-2024-298682 PoCsApache StreamPipes, Apache StreamPipes: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Recovery Token Generation
- CVE-2024-298822 PoCsSRS DOM - XSS on JSONP callback
- CVE-2024-298891 PoCGLPI contains an SQL injection through the saved searches
- CVE-2024-298941 PoCCacti Cross-site Scripting vulnerability when using JavaScript based messaging API
- CVE-2024-298954 PoCsCacti command injection in cmd_realtime.php
- CVE-2024-299031 PoCCosign vulnerable to machine-wide denial of service via malicious artifacts
- CVE-2024-299311 PoCWordPress WP Go Maps plugin <= 9.0.29 - Reflected Cross Site Scripting (XSS) vulnerability
- CVE-2024-299434 PoCsAn attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination.…
- CVE-2024-299724 PoCs** UNSUPPORTED WHEN ASSIGNED **The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326 firmware versions…
- CVE-2024-2997313 PoCs** UNSUPPORTED WHEN ASSIGNED **The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before…
- CVE-2024-299742 PoCs** UNSUPPORTED WHEN ASSIGNED **The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware…
- CVE-2024-299752 PoCs** UNSUPPORTED WHEN ASSIGNED **The improper privilege management vulnerability in the SUID executable binary in Zyxel NAS326 firmware…
- CVE-2024-299762 PoCs** UNSUPPORTED WHEN ASSIGNED **The improper privilege management vulnerability in the command “show_allsessions” in Zyxel NAS326 firmware…
- CVE-2024-299881 PoCKEVSmartScreen Prompt Security Feature Bypass Vulnerability