CVE-2024-2000 to CVE-2024-2999
412 CVEs with public proof-of-concept exploits.
- CVE-2024-20071 PoCOpenBMB XAgent Privileged Mode sandbox
- CVE-2024-20141 PoCPanabit Panalog sprog_upstatus.php sql injection
- CVE-2024-20151 PoCZhiCms mcontroller.php getindexdata sql injection
- CVE-2024-20161 PoCZhiCms setcontroller.php index code injection
- CVE-2024-20211 PoCNetentsec NS-ASG Application Security Gateway list_localuser.php sql injection
- CVE-2024-20221 PoCNetentsec NS-ASG Application Security Gateway list_ipAddressPolicy.php sql injection
- CVE-2024-20401 PoCHimer - Social Questions and Answers < 2.1.1 - Arbitrary Group Joining via CSRF
- CVE-2024-20442 PoCsUnsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4
- CVE-2024-20533 PoCsArtica Proxy Unauthenticated LFI Protection Bypass Vulnerability
- CVE-2024-20544 PoCsArtica Proxy Unauthenticated PHP Deserialization Vulnerability
- CVE-2024-20552 PoCsArtica Proxy Unauthenticated File Manager Vulnerability
- CVE-2024-20562 PoCsArtica Proxy Loopback Services Remotely Accessible Unauthenticated
- CVE-2024-20571 PoCLangChain langchain_community TFIDFRetriever tfidf.py load_local server-side request forgery
- CVE-2024-20581 PoCSourceCodester Petrol Pump Management Software product.php unrestricted upload
- CVE-2024-20591 PoCSourceCodester Petrol Pump Management Software service_crud.php unrestricted upload
- CVE-2024-20601 PoCSourceCodester Petrol Pump Management Software login_crud.php sql injection
- CVE-2024-20611 PoCSourceCodester Petrol Pump Management Software edit_supplier.php sql injection
- CVE-2024-20621 PoCSourceCodester Petrol Pump Management Software edit_categories.php sql injection
- CVE-2024-20631 PoCSourceCodester Petrol Pump Management Software profile_crud.php cross site scripting
- CVE-2024-20641 PoCrahman SelectCours Template CacheController.java getCacheNames injection
- CVE-2024-20651 PoCSourceCodester Barangay Population Monitoring System update-resident.php cross site scripting
- CVE-2024-20661 PoCSourceCodester Computer Inventory System add-computer.php cross site scripting
- CVE-2024-20671 PoCSourceCodester Computer Inventory System delete-computer.php sql injection
- CVE-2024-20681 PoCSourceCodester Computer Inventory System update-computer.php cross site scripting
- CVE-2024-20691 PoCSourceCodester FAQ Management System delete-faq.php sql injection
- CVE-2024-20701 PoCSourceCodester FAQ Management System add-faq.php cross site scripting
- CVE-2024-20711 PoCSourceCodester FAQ Management System Update FAQ cross site scripting
- CVE-2024-20721 PoCSourceCodester Flashcard Quiz App update-flashcard.php cross site scripting
- CVE-2024-20731 PoCSourceCodester Block Inserter for Dynamic Content view_post.php sql injection
- CVE-2024-20742 PoCsMini-Tmall 1 sql injection
- CVE-2024-20751 PoCSourceCodester Daily Habit Tracker update-tracker.php cross site scripting
- CVE-2024-20761 PoCCodeAstro House Rental Management System tenant.php missing authentication
- CVE-2024-20771 PoCSourceCodester Simple Online Bidding System index.php sql injection
- CVE-2024-20831 PoCDirectory Traversal in zenml-io/zenml
- CVE-2024-21011 PoCWordPress Plugin Salon Booking System < 9.6.3 - Unauthenticated Stored Cross-Site Scripting (XSS)
- CVE-2024-21021 PoCSalon booking system < 9.6.3 - Unauthenticated Stored XSS
- CVE-2024-21181 PoCSocial Media Share Buttons < 2.8.9 - Admin+ Stored XSS via settings
- CVE-2024-21331 PoCBdtask Isshue Multi Store eCommerce Shopping Cart Solution Manage Sale Page manage_invoice cross site scripting
- CVE-2024-21341 PoCBdtask Hospita AutoManager Investigation Report cross-site request forgery
- CVE-2024-21351 PoCBdtask Hospita AutoManager Hospital Activities Page form cross site scripting
- CVE-2024-21451 PoCSourceCodester Online Mobile Management Store update-tracker.php cross site scripting
- CVE-2024-21461 PoCSourceCodester Online Mobile Management Store ?p=products cross site scripting
- CVE-2024-21471 PoCSourceCodester Online Mobile Management Store login.php sql injection
- CVE-2024-21481 PoCSourceCodester Online Mobile Management Store Users.php unrestricted upload
- CVE-2024-21491 PoCCodeAstro Membership Management System settings.php sql injection
- CVE-2024-21501 PoCSourceCodester Insurance Management System file inclusion
- CVE-2024-21511 PoCSourceCodester Online Mobile Management Store Product Price logic error
- CVE-2024-21521 PoCSourceCodester Online Mobile Management Store manage_product.php sql injection
- CVE-2024-21531 PoCSourceCodester Online Mobile Management Store view_order.php sql injection
- CVE-2024-21541 PoCSourceCodester Online Mobile Management Store view_product.php sql injection
- CVE-2024-21551 PoCSourceCodester Best POS Management System index.php file inclusion
- CVE-2024-21561 PoCSourceCodester Best POS Management System admin_class.php sql injection
- CVE-2024-21591 PoCSassy Social Share < 3.3.61 - Contributor+ Stored XSS
- CVE-2024-21681 PoCSourceCodester Online Tours & Travels Management System HTTP POST Request expense_category.php sql injection
- CVE-2024-21731 PoCOut of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to perform out of bounds memory…
- CVE-2024-21741 PoCInappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap…
- CVE-2024-21761 PoCUse after free in FedCM in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2024-21772 PoCsImproper Restriction of Rendered UI Layers or Frames in GitLab
- CVE-2024-21801 PoCZemana AntiLogger v2.74.204.664 - Kernel Memory Leak
- CVE-2024-21891 PoCSocial Icons Widget & Block < 4.2.18 - Admin+ Stored XSS
- CVE-2024-21911 PoCImproper Access Control in GitLab
- CVE-2024-21931 PoCSpeculative Race Condition impacts modern CPU architectures that support speculative execution, also known as GhostRace.
- CVE-2024-22011 PoCCVE-2024-2201
- CVE-2024-22181 PoCLuckyWP Table of Contents <= 2.1.4 - Admin+ Stored XSS
- CVE-2024-22201 PoCButton contact VR <= 4.7 - Admin+ Stored XSS
- CVE-2024-22311 PoCHimer - Social Questions and Answers < 2.1.1 - Subscriber+ Private Group Joining via IDOR
- CVE-2024-22321 PoCHimer - Social Questions and Answers < 2.1.3 - CSRF While Sending the Invites
- CVE-2024-22331 PoCHimer - Social Questions and Answers < 2.1.1 - Multiple CSRF on the Group Section
- CVE-2024-22341 PoCHimer - Social Questions and Answers < 2.1.1 - Contributor+ Stored XSS
- CVE-2024-22351 PoCHimer - Social Questions and Answers < 2.1.1 - Bypass Poll Voting Restrictions via CSRF
- CVE-2024-22421 PoCContact Form 7 <= 5.9 - Reflected Cross-Site Scripting
- CVE-2024-22572 PoCsPassword Policy Bypass Vulnerability in Digisol Router
- CVE-2024-22621 PoCWooCommerce Product Filter < 1.4.4 - Filter Deletion via CSRF
- CVE-2024-22631 PoCWooCommerce Product Filter < 1.4.4 - Reflected XSS
- CVE-2024-22641 PoCkeerti1924 PHP-MYSQL-User-Login-System login.php sql injection
- CVE-2024-22651 PoCkeerti1924 PHP-MYSQL-User-Login-System login.sql inclusion of sensitive information in source code
- CVE-2024-22661 PoCkeerti1924 Secret-Coder-PHP-Project Login Page login.php cross site scripting
- CVE-2024-22671 PoCkeerti1924 Online-Book-Store-Website shop.php logic error
- CVE-2024-22681 PoCkeerti1924 Online-Book-Store-Website unrestricted upload
- CVE-2024-22691 PoCkeerti1924 Online-Book-Store-Website search.php sql injection
- CVE-2024-22701 PoCkeerti1924 Online-Book-Store-Website signup.php cross site scripting
- CVE-2024-22711 PoCkeerti1924 Online-Book-Store-Website HTTP POST Request shop.php sql injection
- CVE-2024-22721 PoCkeerti1924 Online-Book-Store-Website HTTP POST Request home.php sql injection
- CVE-2024-22741 PoCBdtask G-Prescription Gynaecology & OBS Consultation Software Prescription Dashboard Index cross site scripting
- CVE-2024-22751 PoCBdtask G-Prescription Gynaecology & OBS Consultation Software OBS Patient/Gynee Prescription cross site scripting
- CVE-2024-22761 PoCBdtask G-Prescription Gynaecology & OBS Consultation Software Edit Venue Page cross site scripting
- CVE-2024-22771 PoCBdtask G-Prescription Gynaecology & OBS Consultation Software Password Reset change_password_save cross-site request forgery
- CVE-2024-22781 PoCWooCommerce Product Filter < 1.4.4 - Admin+ Stored XSS
- CVE-2024-22791 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2024-22811 PoCboyiddha Automated-Mess-Management-System Setting index.php access control
- CVE-2024-22821 PoCboyiddha Automated-Mess-Management-System Login Page index.php sql injection
- CVE-2024-22831 PoCboyiddha Automated-Mess-Management-System view.php sql injection
- CVE-2024-22841 PoCboyiddha Automated-Mess-Management-System Chat Book chat.php cross site scripting
- CVE-2024-23091 PoCWP Staging < 3.4.0, 5.4.0 (Pro Version) - Admin+ Stored XSS
- CVE-2024-23101 PoCWP Google Review Slider < 13.6 - Admin+ Stored XSS
- CVE-2024-23161 PoCBdtask Hospital AutoManager Update Bill Page cross-site request forgery
- CVE-2024-23171 PoCBdtask Hospital AutoManager Prescription Page improper authorization
- CVE-2024-23181 PoCZKTeco ZKBio Media Service Port 9999 download path traversal
- CVE-2024-23221 PoCWooCommerce Cart Abandonment Recovery < 1.2.27 - Templates/Abandoned Orders Deletion via CSRF
- CVE-2024-23291 PoCNetentsec NS-ASG Application Security Gateway sql injection
- CVE-2024-23302 PoCsNetentsec NS-ASG Application Security Gateway index.php sql injection
- CVE-2024-23311 PoCSourceCodester Tourist Reservation System System.cpp ad_writedata buffer overflow
- CVE-2024-23321 PoCSourceCodester Online Mobile Management Store HTTP GET Request manage_category.php sql injection
- CVE-2024-23331 PoCCodeAstro Membership Management System add_members.php sql injection
- CVE-2024-23401 PoCAvada <= 7.11.6 - Unauthenticated Sensitive Information Exposure via Form Uploads Directory Listing
- CVE-2024-23441 PoCAvada <= 7.11.6 - Authenticated (Admin+) SQL Injection via entry
- CVE-2024-23511 PoCCodeAstro Ecommerce Site Search action.php sql injection
- CVE-2024-23521 PoC1Panel swap baseApi.UpdateDeviceSwap command injection
- CVE-2024-23531 PoCTotolink X6000R shttpd cstecgi.cgi setDiagnosisCfg os command injection
- CVE-2024-23541 PoCDreamer CMS toEdit cross-site request forgery
- CVE-2024-23551 PoCkeerti1924 Secret-Coder-PHP-Project secret_coder.sql inclusion of sensitive information in source code
- CVE-2024-23631 PoCAOL AIM Triton Invite denial of service
- CVE-2024-23641 PoCMusicshelf Backup androidmanifest.xml backup
- CVE-2024-23651 PoCMusicshelf SHA-1 PinningTrustManager.java weak password hash
- CVE-2024-23691 PoCPage Builder Gutenberg Blocks < 3.1.7 - Contributor+ Stored XSS
- CVE-2024-23751 PoCWPQA < 6.1.1 - Contributor+ Stored XSS
- CVE-2024-23761 PoCWPQA < 6.1.1 - Arbitrary Category and Tag Follow/Unfollow via CSRF
- CVE-2024-23871 PoCAdvanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms <= 1.82.0 - SQL Injection to…
- CVE-2024-23896 PoCsFlowmon Unauthenticated Command Injection Vulnerability
- CVE-2024-23911 PoCEVE-NG Lab cross site scripting
- CVE-2024-23931 PoCSourceCodester CRUD without Page Reload add_user.php sql injection
- CVE-2024-23941 PoCSourceCodester Employee Management System add-admin.php unrestricted upload
- CVE-2024-24021 PoCBetter Comments < 1.5.6 - Admin+ Stored XSS
- CVE-2024-24041 PoCBetter Comments < 1.5.6 - Subscriber+ Stored XSS
- CVE-2024-24051 PoCFloat menu < 6.0.1 - Menu Deletion via CSRF
- CVE-2024-24061 PoCGacjie Server Upload.php index unrestricted upload
- CVE-2024-24082 PoCsPHP is vulnerable to the Marvin Attack
- CVE-2024-24181 PoCSourceCodester Best POS Management System view_order.php sql injection
- CVE-2024-24281 PoCThe Ultimate Video Player For WordPress < 2.2.3 - Contributor+ Stored XSS
- CVE-2024-24291 PoCSalon booking system <= 9.6.5 - Settings Update via CSRF
- CVE-2024-24301 PoCWebsite Content in Page or Post < 2024.04.09 - Contributor+ Stored Cross-Site Scripting
- CVE-2024-24321 PoCGlobalProtect App: Local Privilege Escalation (PE) Vulnerability
- CVE-2024-24341 PoCImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
- CVE-2024-24391 PoCSalon booking system <= 9.6.5 - Editor+ Stored XSS
- CVE-2024-24411 PoCVikBooking < 1.6.8 - Insecure Direct Object References
- CVE-2024-24441 PoCInline Related Posts < 3.5.0 - Admin+ Stored XSS
- CVE-2024-24541 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2024-24661 PoCTLS certificate check bypass with mbedTLS
- CVE-2024-24701 PoCSimple Ajax Chat < 20240412 - Admin+ Stored XSS
- CVE-2024-24732 PoCsWPS Hide Login <= 1.9.15.2 - Login Page Disclosure
- CVE-2024-24781 PoCBradWenqiang HR Background Management register selectAll sql injection
- CVE-2024-24791 PoCMHA Sistemas arMHAzena Cadastro Page cross site scripting
- CVE-2024-24801 PoCMHA Sistemas arMHAzena Executa Page sql injection
- CVE-2024-24811 PoCSurya2Developer Hostel Management System manage-students.php access control
- CVE-2024-24821 PoCSurya2Developer Hostel Management Service HTTP POST Request check_availability.php observable response discrepancy
- CVE-2024-24831 PoCSurya2Developer Hostel Management Service Password Change change-password.php cross-site request forgery
- CVE-2024-24851 PoCTenda AC18 SetSpeedWan formSetSpeedWan stack-based overflow
- CVE-2024-24861 PoCTenda AC18 QuickIndex formQuickIndex stack-based overflow
- CVE-2024-24871 PoCTenda AC18 SetOnlineDevName formSetDeviceName stack-based overflow
- CVE-2024-24881 PoCTenda AC18 SetPptpServerCfg formSetPPTPServer stack-based overflow
- CVE-2024-24891 PoCTenda AC18 SetNetControlList formSetQosBand stack-based overflow
- CVE-2024-24901 PoCTenda AC18 openSchedWifi setSchedWifi stack-based overflow
- CVE-2024-24971 PoCRaspAP raspap-webgui HTTP POST Request provider.php code injection
- CVE-2024-25051 PoCGamiPress < 6.8.9 - Broken Access Control
- CVE-2024-25092 PoCsGutenberg Blocks by Kadence Blocks < 3.2.26 - Contributor+ Stored XSS
- CVE-2024-25141 PoCMAGESH-K21 Online-College-Event-Hall-Reservation-System login.php sql injection
- CVE-2024-25151 PoCMAGESH-K21 Online-College-Event-Hall-Reservation-System home.php cross site scripting
- CVE-2024-25161 PoCMAGESH-K21 Online-College-Event-Hall-Reservation-System home.php sql injection
- CVE-2024-25171 PoCMAGESH-K21 Online-College-Event-Hall-Reservation-System book_history.php sql injection
- CVE-2024-25181 PoCMAGESH-K21 Online-College-Event-Hall-Reservation-System book_history.php cross site scripting
- CVE-2024-25191 PoCMAGESH-K21 Online-College-Event-Hall-Reservation-System navbar.php cross site scripting
- CVE-2024-25201 PoCMAGESH-K21 Online-College-Event-Hall-Reservation-System bookdate.php sql injection
- CVE-2024-25211 PoCMAGESH-K21 Online-College-Event-Hall-Reservation-System bookdate.php cross site scripting
- CVE-2024-25221 PoCMAGESH-K21 Online-College-Event-Hall-Reservation-System booktime.php sql injection
- CVE-2024-25231 PoCMAGESH-K21 Online-College-Event-Hall-Reservation-System booktime.php cross site scripting
- CVE-2024-25241 PoCMAGESH-K21 Online-College-Event-Hall-Reservation-System receipt.php sql injection
- CVE-2024-25251 PoCMAGESH-K21 Online-College-Event-Hall-Reservation-System receipt.php cross site scripting
- CVE-2024-25261 PoCMAGESH-K21 Online-College-Event-Hall-Reservation-System rooms.php cross site scripting
- CVE-2024-25271 PoCMAGESH-K21 Online-College-Event-Hall-Reservation-System rooms.php sql injection
- CVE-2024-25281 PoCMAGESH-K21 Online-College-Event-Hall-Reservation-System update-rooms.php sql injection
- CVE-2024-25291 PoCMAGESH-K21 Online-College-Event-Hall-Reservation-System rooms.php unrestricted upload
- CVE-2024-25301 PoCMAGESH-K21 Online-College-Event-Hall-Reservation-System update-rooms.php cross site scripting
- CVE-2024-25311 PoCMAGESH-K21 Online-College-Event-Hall-Reservation-System update-rooms.php unrestricted upload
- CVE-2024-25321 PoCMAGESH-K21 Online-College-Event-Hall-Reservation-System update-users.php sql injection
- CVE-2024-25331 PoCMAGESH-K21 Online-College-Event-Hall-Reservation-System update-users.php cross site scripting
- CVE-2024-25341 PoCMAGESH-K21 Online-College-Event-Hall-Reservation-System users.php sql injection
- CVE-2024-25351 PoCMAGESH-K21 Online-College-Event-Hall-Reservation-System users.php cross site scripting
- CVE-2024-25381 PoCPermalink Manager <= 2.4.3.1 - Missing Authorization to Authenticated(Author+) Arbitrary Post Slug Modification
- CVE-2024-25431 PoCPlugin Permalink <= 2.4.3.1 - Missing Authorization via get_uri_editor
- CVE-2024-25461 PoCTenda AC18 fromSetWirelessRepeat stack-based overflow
- CVE-2024-25471 PoCTenda AC18 R7WebsSecurityHandler stack-based overflow
- CVE-2024-25531 PoCSourceCodester Product Review Rating System Rate Product cross site scripting
- CVE-2024-25541 PoCSourceCodester Employee Task Management System update-employee.php sql injection
- CVE-2024-25551 PoCSourceCodester Employee Task Management System update-admin.php sql injection
- CVE-2024-25561 PoCSourceCodester Employee Task Management System attendance-info.php sql injection
- CVE-2024-25571 PoCkishor-23 Food Waste Management System admin.php improper authorization
- CVE-2024-25581 PoCTenda AC18 execCommand formexeCommand stack-based overflow
- CVE-2024-25591 PoCTenda AC18 SysToolReboot fromSysToolReboot cross-site request forgery
- CVE-2024-25601 PoCTenda AC18 SysToolRestoreSet fromSysToolRestoreSet cross-site request forgery
- CVE-2024-25611 PoC74CMS Company Logo Index.php#sendCompanyLogo unrestricted upload
- CVE-2024-25621 PoCPandaXGO PandaX role_menu.go InsertRole sql injection
- CVE-2024-25631 PoCPandaXGO PandaX upload.go DeleteImage path traversal
- CVE-2024-25641 PoCPandaXGO PandaX user.go ExportUser path traversal
- CVE-2024-25651 PoCPandaXGO PandaX File Extension upload.go unrestricted upload
- CVE-2024-25661 PoCFujian Kelixin Communication Command and Dispatch Platform get_extension_yl.php sql injection
- CVE-2024-25671 PoCjurecapuder AndroidWeatherApp Backup File androidmanifest.xml backup
- CVE-2024-25681 PoCheyewei JFinalCMS Custom Data Page sql injection
- CVE-2024-25691 PoCSourceCodester Employee Task Management System admin-manage-user.php redirect
- CVE-2024-25701 PoCSourceCodester Employee Task Management System edit-task.php redirect
- CVE-2024-25711 PoCSourceCodester Employee Task Management System manage-admin.php redirect
- CVE-2024-25721 PoCSourceCodester Employee Task Management System task-details.php redirect
- CVE-2024-25731 PoCSourceCodester Employee Task Management System task-info.php redirect
- CVE-2024-25741 PoCSourceCodester Employee Task Management System edit-task.php authorization
- CVE-2024-25751 PoCSourceCodester Employee Task Management System task-details.php authorization
- CVE-2024-25761 PoCSourceCodester Employee Task Management System update-admin.php authorization
- CVE-2024-25771 PoCSourceCodester Employee Task Management System update-employee.php authorization
- CVE-2024-25811 PoCTenda AC10 SetStaticRouteCfg fromSetRouteStatic stack-based overflow
- CVE-2024-25831 PoCShortcodes Ultimate < 7.0.5 - Contributor+ Stored XSS
- CVE-2024-26031 PoCSalon booking system <= 9.6.5 - Editor+ Stored XSS via Email Settings
- CVE-2024-26041 PoCSourceCodester File Manager App update-file.php unrestricted upload
- CVE-2024-26061 PoCPassing invalid data could have led to invalid wasm values being created, such as arbitrary integers turning into pointer values. This…
- CVE-2024-26081 PoC`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer…
- CVE-2024-26091 PoCThe permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious…
- CVE-2024-26101 PoCUsing a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies.…
- CVE-2024-26111 PoCA missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This…
- CVE-2024-26201 PoCFujian Kelixin Communication Command and Dispatch Platform down_file.php sql injection
- CVE-2024-26212 PoCsFujian Kelixin Communication Command and Dispatch Platform pwd_update.php sql injection
- CVE-2024-26221 PoCFujian Kelixin Communication Command and Dispatch Platform editemedia.php sql injection
- CVE-2024-26241 PoCPath Traversal and Arbitrary File Upload Vulnerability in parisneo/lollms-webui
- CVE-2024-26391 PoCBdtask Wholesale Inventory Management System session fixiation
- CVE-2024-26401 PoCWatu Quiz < 3.4.1.2 - Author+ Stored XSS
- CVE-2024-26411 PoCRuijie RG-NBS2009G-P Password passwdManage.htm improper authorization
- CVE-2024-26421 PoCRuijie RG-NBS2009G-P EXCU_SHELL command injection
- CVE-2024-26431 PoCMy Sticky Bar < 2.6.8 - Admin+ Stored XSS
- CVE-2024-26441 PoCNetentsec NS-ASG Application Security Gateway addfirewall.php sql injection
- CVE-2024-26451 PoCNetentsec NS-ASG Application Security Gateway resetpwd.php xpath injection
- CVE-2024-26461 PoCNetentsec NS-ASG Application Security Gateway sql injection
- CVE-2024-26471 PoCNetentsec NS-ASG Application Security Gateway singlelogin.php sql injection
- CVE-2024-26481 PoCNetentsec NS-ASG Application Security Gateway naccheck.php xpath injection
- CVE-2024-26491 PoCNetentsec NS-ASG Application Security Gateway deleteonlineuser.php sql injection
- CVE-2024-26511 PoCInefficient Regular Expression Complexity in GitLab
- CVE-2024-26531 PoCCVE-2024-2653
- CVE-2024-26673 PoCsInstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.22 - Unauthenticated Arbitrary File Upload
- CVE-2024-26681 PoCCampcodes Online Job Finder System controller.php sql injection
- CVE-2024-26691 PoCCampcodes Online Job Finder System GET Parameter controller.php sql injection
- CVE-2024-26701 PoCCampcodes Online Job Finder System index.php sql injection
- CVE-2024-26711 PoCCampcodes Online Job Finder System index.php sql injection
- CVE-2024-26721 PoCCampcodes Online Job Finder System controller.php sql injection
- CVE-2024-26731 PoCCampcodes Online Job Finder System login.php sql injection
- CVE-2024-26741 PoCCampcodes Online Job Finder System index.php sql injection
- CVE-2024-26751 PoCCampcodes Online Job Finder System index.php sql injection
- CVE-2024-26761 PoCCampcodes Online Job Finder System controller.php sql injection
- CVE-2024-26771 PoCCampcodes Online Job Finder System controller.php sql injection
- CVE-2024-26781 PoCCampcodes Online Job Finder System controller.php sql injection
- CVE-2024-26791 PoCCampcodes Online Job Finder System index.php cross site scripting
- CVE-2024-26801 PoCCampcodes Online Job Finder System index.php cross site scripting
- CVE-2024-26811 PoCCampcodes Online Job Finder System index.php cross site scripting
- CVE-2024-26821 PoCCampcodes Online Job Finder System controller.php cross site scripting
- CVE-2024-26831 PoCCampcodes Online Job Finder System index.php cross site scripting
- CVE-2024-26841 PoCCampcodes Online Job Finder System index.php cross site scripting
- CVE-2024-26851 PoCCampcodes Online Job Finder System index.php cross site scripting
- CVE-2024-26861 PoCCampcodes Online Job Finder System controller.php cross site scripting
- CVE-2024-26871 PoCCampcodes Online Job Finder System index.php sql injection
- CVE-2024-26901 PoCSourceCodester Online Discussion Forum Site uupdate.php unrestricted upload
- CVE-2024-26961 PoCSwift Framework < 2024.04.30 - Admin+ Stored XSS via Settings
- CVE-2024-26971 PoCSwift Framework < 2024.0.0 - Contributor+ Stored XSS via Shortcode
- CVE-2024-27031 PoCTenda AC10U SetOnlineDevName formSetDeviceName stack-based overflow
- CVE-2024-27041 PoCTenda AC10U SetFirewallCfg formSetFirewallCfg stack-based overflow
- CVE-2024-27051 PoCTenda AC10U SetNetControlList formSetQosBand stack-based overflow
- CVE-2024-27061 PoCTenda AC10U WifiWpsStart formWifiWpsStart stack-based overflow
- CVE-2024-27071 PoCTenda AC10U WriteFacMac formWriteFacMac os command injection
- CVE-2024-27081 PoCTenda AC10U execCommand formexeCommand stack-based overflow
- CVE-2024-27091 PoCTenda AC10U SetStaticRouteCfg fromSetRouteStatic stack-based overflow
- CVE-2024-27101 PoCTenda AC10U openSchedWifi setSchedWifi stack-based overflow
- CVE-2024-27111 PoCTenda AC10U addWifiMacFilter stack-based overflow
- CVE-2024-27121 PoCCampcodes Complete Online DJ Booking System user-search.php sql injection
- CVE-2024-27131 PoCCampcodes Complete Online DJ Booking System booking-search.php sql injection
- CVE-2024-27141 PoCCampcodes Complete Online DJ Booking System booking-bwdates-reports-details.php sql injection
- CVE-2024-27151 PoCCampcodes Complete Online DJ Booking System user-search.php cross site scripting
- CVE-2024-27161 PoCCampcodes Complete Online DJ Booking System contactus.php cross site scripting
- CVE-2024-27171 PoCCampcodes Complete Online DJ Booking System booking-search.php cross site scripting
- CVE-2024-27181 PoCCampcodes Complete Online DJ Booking System booking-bwdates-reports-details.php cross site scripting
- CVE-2024-27191 PoCCampcodes Complete Online DJ Booking System admin-profile.php cross site scripting
- CVE-2024-27201 PoCCampcodes Complete Online DJ Booking System aboutus.php cross site scripting
- CVE-2024-27291 PoCOtter Blocks < 2.6.6 - Contributor+ Stored XSS
- CVE-2024-27301 PoCPredictable Page Indexing Might Lead to Sensitive Data Exposure in Mautic
- CVE-2024-27311 PoCImproper Access Control Issues Lead to Sensitive Data Exposure in Mautic
- CVE-2024-27391 PoCAdvance Search <= 1.1.6 - Shortcode Deletion via CSRF
- CVE-2024-27431 PoCIncorrect Authorization in GitLab
- CVE-2024-27441 PoCNextgen Gallery < 3.59.1 - Admin+ Stored XSS
- CVE-2024-27491 PoCVikBooking < 1.6.8 - Broken Access Control
- CVE-2024-27541 PoCSourceCodester Complete E-Commerce Site users_photo.php unrestricted upload
- CVE-2024-27571 PoCPHP mb_encode_mimeheader runs endlessly for some inputs
- CVE-2024-27611 PoCGenesis Blocks < 3.1.3 - Contributor+ Stored XSS
- CVE-2024-27621 PoCFooGallery < 2.4.15 - Author+ Stored XSS
- CVE-2024-27631 PoCTenda AC10U setcfm formSetCfm stack-based overflow
- CVE-2024-27641 PoCTenda AC10U SetPptpServerCfg formSetPPTPServer stack-based overflow
- CVE-2024-27661 PoCCampcodes Complete Online Beauty Parlor Management System index.php sql injection
- CVE-2024-27671 PoCCampcodes Complete Online Beauty Parlor Management System forgot-password.php sql injection
- CVE-2024-27681 PoCCampcodes Complete Online Beauty Parlor Management System edit-services.php sql injection
- CVE-2024-27691 PoCCampcodes Complete Online Beauty Parlor Management System admin-profile.php sql injection
- CVE-2024-27701 PoCCampcodes Complete Online Beauty Parlor Management System contact-us.php sql injection
- CVE-2024-27712 PoCsContact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Settings Update…
- CVE-2024-27731 PoCCampcodes Online Marriage Registration System search.php cross site scripting
- CVE-2024-27741 PoCCampcodes Online Marriage Registration System search.php sql injection
- CVE-2024-27751 PoCCampcodes Online Marriage Registration System user-profile.php cross site scripting
- CVE-2024-27761 PoCCampcodes Online Marriage Registration System search.php sql injection
- CVE-2024-27771 PoCCampcodes/PHPGurukul Online Marriage Registration System application-bwdates-reports-details.php sql injection
- CVE-2024-27781 PoCCampcodes Online Marriage Registration System search.php cross site scripting
- CVE-2024-27791 PoCCampcodes Online Marriage Registration System application-bwdates-reports-details.php cross site scripting
- CVE-2024-27801 PoCCampcodes Online Marriage Registration System admin-profile.php cross site scripting
- CVE-2024-27822 PoCsContact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Setting…
- CVE-2024-28001 PoCUncontrolled Resource Consumption in GitLab
- CVE-2024-28051 PoCTenda AC15 SetSpeedWan formSetSpeedWan stack-based overflow
- CVE-2024-28061 PoCTenda AC15 addWifiMacFilter stack-based overflow
- CVE-2024-28071 PoCTenda AC15 expandDlnaFile formExpandDlnaFile stack-based overflow
- CVE-2024-28081 PoCTenda AC15 QuickIndex formQuickIndex stack-based overflow
- CVE-2024-28091 PoCTenda AC15 SetFirewallCfg formSetFirewallCfg stack-based overflow
- CVE-2024-28101 PoCTenda AC15 WifiWpsOOB formWifiWpsOOB stack-based overflow
- CVE-2024-28111 PoCTenda AC15 WifiWpsStart formWifiWpsStart stack-based overflow
- CVE-2024-28121 PoCTenda AC15 WriteFacMac formWriteFacMac os command injection
- CVE-2024-28131 PoCTenda AC15 fast_setting_wifi_set form_fast_setting_wifi_set stack-based overflow
- CVE-2024-28141 PoCTenda AC15 DhcpListClient fromDhcpListClient stack-based overflow
- CVE-2024-28151 PoCTenda AC15 Cookie execCommand R7WebsSecurityHandler stack-based overflow
- CVE-2024-28161 PoCTenda AC15 SysToolReboot fromSysToolReboot cross-site request forgery
- CVE-2024-28171 PoCTenda AC15 SysToolRestoreSet fromSysToolRestoreSet cross-site request forgery
- CVE-2024-28201 PoCDedeCMS baidunews.php cross-site request forgery
- CVE-2024-28211 PoCDedeCMS friendlink_edit.php cross-site request forgery
- CVE-2024-28221 PoCDedeCMS vote_edit.php cross-site request forgery
- CVE-2024-28231 PoCDedeCMS mda_main.php cross-site request forgery
- CVE-2024-28241 PoCMatthias-Wandel jhead exif.c PrintFormatNumber heap-based overflow
- CVE-2024-28251 PoClakernote EasyAdmin saveReportFile path traversal
- CVE-2024-28261 PoClakernote EasyAdmin saveReportFile xml external entity reference
- CVE-2024-28271 PoClakernote EasyAdmin saveReportFile server-side request forgery
- CVE-2024-28281 PoClakernote EasyAdmin IndexController.java thumbnail server-side request forgery
- CVE-2024-28291 PoCInefficient Regular Expression Complexity in GitLab
- CVE-2024-28321 PoCCampcodes Online Shopping System offersmail.php cross site scripting
- CVE-2024-28361 PoCSuper Socializer < 7.13.64 - Editor+ Stored XSS
- CVE-2024-28371 PoCWP Chat App < 3.6.4 - Admin+ Stored XSS
- CVE-2024-28431 PoCWooCommerce Customers Manager < 30.1 - User Deletion via CSRF
- CVE-2024-28491 PoCSourceCodester Simple File Manager unrestricted upload
- CVE-2024-28501 PoCTenda AC15 saveParentControlInfo stack-based overflow
- CVE-2024-28511 PoCTenda AC15 setsambacfg formSetSambaConf os command injection
- CVE-2024-28521 PoCTenda AC15 saveParentControlInfo stack-based overflow
- CVE-2024-28531 PoCTenda AC10U setsambacfg formSetSambaConf os command injection
- CVE-2024-28541 PoCTenda AC18 setsambacfg formSetSambaConf os command injection
- CVE-2024-28551 PoCTenda AC15 SetSysTimeCfg fromSetSysTime stack-based overflow
- CVE-2024-28562 PoCsTenda AC10 SetSysTimeCfg fromSetSysTime stack-based overflow
- CVE-2024-28571 PoCSimple Buttons Creator <= 1.04 - Unauthenticated Stored XSS
- CVE-2024-28581 PoCSimple Buttons Creator <= 1.04 - Aribtrary Button Deletion via CSRF
- CVE-2024-28621 PoCPassword reset vulnerability without authorization on LG LED Assistant
- CVE-2024-28631 PoCPath traversal via file upload on LG LED Assistant
- CVE-2024-28691 PoCEasy Property Listings <= 3.5.3 - Admin+ Stored XSS
- CVE-2024-28701 PoCSwift Framework < 2024.04.30 - Reflected XSS
- CVE-2024-28721 PoCSwift Framework < 2024.04.30 - Contributor+ Stored XSS
- CVE-2024-28741 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2024-287614 PoCsIcegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection
- CVE-2024-28781 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2024-28793 PoCsThe LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.11 and 7.10.0 due…
- CVE-2024-28801 PoCImproper Access Control in GitLab
- CVE-2024-28841 PoCOut of bounds read in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially perform out of bounds memory…
- CVE-2024-28861 PoCUse after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/write via a…
- CVE-2024-28876 PoCsType Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted…
- CVE-2024-28911 PoCTenda AC7 QuickIndex formQuickIndex stack-based overflow
- CVE-2024-28921 PoCTenda AC7 setcfm formSetCfm stack-based overflow
- CVE-2024-28931 PoCTenda AC7 SetOnlineDevName formSetDeviceName stack-based overflow
- CVE-2024-28941 PoCTenda AC7 SetNetControlList formSetQosBand stack-based overflow
- CVE-2024-28951 PoCTenda AC7 WifiWpsOOB formWifiWpsOOB stack-based overflow
- CVE-2024-28961 PoCTenda AC7 WifiWpsStart formWifiWpsStart stack-based overflow
- CVE-2024-28971 PoCTenda AC7 WriteFacMac formWriteFacMac os command injection
- CVE-2024-28981 PoCTenda AC7 SetStaticRouteCfg fromSetRouteStatic stack-based overflow
- CVE-2024-28991 PoCTenda AC7 WifiExtraSet fromSetWirelessRepeat stack-based overflow
- CVE-2024-29001 PoCTenda AC7 saveParentControlInfo stack-based overflow
- CVE-2024-29011 PoCTenda AC7 openSchedWifi setSchedWifi stack-based overflow
- CVE-2024-29021 PoCTenda AC7 WifiGuestSet fromSetWifiGusetBasic stack-based overflow
- CVE-2024-29031 PoCTenda AC7 GetParentControlInfo stack-based overflow
- CVE-2024-29071 PoCAGCA – Custom Dashboard & Login Page < 7.2.2 - Admin+ Stored XSS via Image URL
- CVE-2024-29081 PoCCall Now Button < 1.4.7 - Admin+ Stored XSS
- CVE-2024-29091 PoCRuijie RG-EG350 HTTP POST Request setAction os command injection
- CVE-2024-29101 PoCRuijie RG-EG350 HTTP POST Request vpnAction os command injection
- CVE-2024-29111 PoCTianjin PubliCMS cross-site request forgery
- CVE-2024-29161 PoCCampcodes House Rental Management System ajax.php sql injection
- CVE-2024-29171 PoCCampcodes House Rental Management System index.php file inclusion
- CVE-2024-29282 PoCsLocal File Inclusion (LFI) via URI Fragment Parsing in mlflow/mlflow
- CVE-2024-29301 PoCSourceCodester Music Gallery Site unrestricted upload
- CVE-2024-29321 PoCSourceCodester Online Chatting System update_room.php sql injection
- CVE-2024-29341 PoCSourceCodester Todo List in Kanban Board delete-todo.php sql injection
- CVE-2024-29351 PoCSourceCodester Todo List in Kanban Board Add ToDo cross site scripting
- CVE-2024-29381 PoCCampcodes Online Examination System updateCourse.php sql injection
- CVE-2024-29391 PoCCampcodes Online Examination System updateExaminee.php cross site scripting
- CVE-2024-29401 PoCCampcodes Online Examination System updateCourse.php cross site scripting
- CVE-2024-29411 PoCCampcodes Online Examination System loginExe.php sql injection
- CVE-2024-29421 PoCCampcodes Online Examination System deleteQuestionExe.php sql injection
- CVE-2024-29431 PoCCampcodes Online Examination System deleteExamExe.php sql injection
- CVE-2024-29441 PoCCampcodes Online Examination System deleteCourseExe.php sql injection
- CVE-2024-29451 PoCCampcodes Online Examination System updateExaminee.php sql injection
- CVE-2024-296117 PoCsThe iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when…
- CVE-2024-29721 PoCFloating Chat Widget < 3.1.9 - Editor+ Stored XSS
- CVE-2024-29761 PoCTenda F1203 execCommand R7WebsSecurityHandler stack-based overflow
- CVE-2024-29771 PoCTenda F1203 QuickIndex formQuickIndex stack-based overflow
- CVE-2024-29781 PoCTenda F1203 setcfm formSetCfm stack-based overflow
- CVE-2024-29791 PoCTenda F1203 openSchedWifi setSchedWifi stack-based overflow
- CVE-2024-29801 PoCTenda FH1202 execCommand formexeCommand stack-based overflow
- CVE-2024-29811 PoCTenda FH1202 fast_setting_wifi_set form_fast_setting_wifi_set stack-based overflow
- CVE-2024-29821 PoCTenda FH1202 WriteFacMac formWriteFacMac command injection
- CVE-2024-29831 PoCTenda FH1202 SetClientState formSetClientState stack-based overflow
- CVE-2024-29841 PoCTenda FH1202 setcfm formSetCfm stack-based overflow
- CVE-2024-29851 PoCTenda FH1202 QuickIndex formQuickIndex stack-based overflow
- CVE-2024-29861 PoCTenda FH1202 SetSpeedWan formSetSpeedWan stack-based overflow
- CVE-2024-29871 PoCTenda FH1202 GetParentControlInfo stack-based overflow
- CVE-2024-29881 PoCTenda FH1203 fromRouteStatic fromSetRouteStatic stack-based overflow
- CVE-2024-29891 PoCTenda FH1203 NatStaticSetting fromNatStaticSetting stack-based overflow
- CVE-2024-29901 PoCTenda FH1203 execCommand formexeCommand stack-based overflow
- CVE-2024-29911 PoCTenda FH1203 WriteFacMac formWriteFacMac command injection
- CVE-2024-29921 PoCTenda FH1203 setcfm formSetCfm stack-based overflow
- CVE-2024-29931 PoCTenda FH1203 QuickIndex formQuickIndex stack-based overflow
- CVE-2024-29941 PoCTenda FH1203 GetParentControlInfo stack-based overflow
- CVE-2024-29951 PoCNUUO Camera deletefile.php denial of service
- CVE-2024-29961 PoCBdtask Multi-Store Inventory Management System Page Title cross site scripting
- CVE-2024-29972 PoCsBdtask Multi-Store Inventory Management System cross site scripting
- CVE-2024-29981 PoCBdtask Multi-Store Inventory Management System Store Update Page cross site scripting
- CVE-2024-29991 PoCCampcodes Online Art Gallery Management System adminHome.php sql injection