CVE-2024-30000 to CVE-2024-30999
113 CVEs with public proof-of-concept exploits.
- CVE-2024-300381 PoCWin32k Elevation of Privilege Vulnerability
- CVE-2024-300431 PoCMicrosoft SharePoint Server Information Disclosure Vulnerability
- CVE-2024-300512 PoCsKEVWindows DWM Core Library Elevation of Privilege Vulnerability
- CVE-2024-300521 PoCVisual Studio Remote Code Execution Vulnerability
- CVE-2024-300561 PoCMicrosoft Edge (Chromium-based) Information Disclosure Vulnerability
- CVE-2024-300786 PoCsWindows Wi-Fi Driver Remote Code Execution Vulnerability
- CVE-2024-300855 PoCsWindows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
- CVE-2024-3008810 PoCsKEVWindows Kernel Elevation of Privilege Vulnerability
- CVE-2024-300901 PoCMicrosoft Streaming Service Elevation of Privilege Vulnerability
- CVE-2024-301632 PoCsInvision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php…
- CVE-2024-301672 PoCs/cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary commands as root via a…
- CVE-2024-301881 PoCApache DolphinScheduler: Resource File Read And Write Vulnerability
- CVE-2024-301941 PoCWordPress Sunshine Photo Cart plugin <= 3.1.1 - Reflected Cross Site Scripting (XSS) vulnerability
- CVE-2024-302121 PoCMicrochip Harmony 3 Core library allows read and write access to RAM via a SCSI READ or WRITE command
- CVE-2024-302481 PoCPiccolo Admin's raw SVG loading may lead to complete data compromise from admin page
- CVE-2024-302552 PoCsHTTP/2: CPU exhaustion due to CONTINUATION frame flood
- CVE-2024-302581 PoCFastDDS crash when publisher send malformed packet
- CVE-2024-302591 PoCFastDDS heap buffer overflow when publisher sends malformed packet
- CVE-2024-302641 PoCtypebot.io: `GHSL-2024-040`
- CVE-2024-302692 PoCsDataEase has database configuration information exposure vulnerability
- CVE-2024-302702 PoCsmailcow Path Traversal and Arbitrary Code Execution Vulnerability
- CVE-2024-304641 PoCWordPress Social Icons Widget & Block by WPZOOM plugin <= 4.2.15 - Broken Access Control vulnerability
- CVE-2024-304851 PoCWordPress Finale Lite plugin <= 2.18.0 - Subscriber+ Arbitrary Plugin Installation/Activation vulnerability
- CVE-2024-304901 PoCWordPress ProfileGrid plugin <= 5.7.8 - SQL Injection vulnerability
- CVE-2024-304981 PoCWordPress CRM Perks Forms plugin <= 1.1.4 - Unauthenticated SQL Injection vulnerability
- CVE-2024-305021 PoCWordPress WP Travel Engine plugin <= 5.7.9 - Unauth. Blind SQL Injection vulnerability
- CVE-2024-305682 PoCsNetgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.
- CVE-2024-305691 PoCAn information leak in currentsetting.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any…
- CVE-2024-305701 PoCAn information leak in debuginfo.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any…
- CVE-2024-305721 PoCNetgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the ntp_server parameter.
- CVE-2024-305831 PoCTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the mitInterface parameter of the fromAddressNat function.
- CVE-2024-305841 PoCTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function.
- CVE-2024-305851 PoCTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.
- CVE-2024-305861 PoCTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function.
- CVE-2024-305871 PoCTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.
- CVE-2024-305881 PoCTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.
- CVE-2024-305891 PoCTenda FH1202 v1.2.0.14(408) firmware has a stack overflow vulnerability in the entrys parameter of the fromAddressNat function.
- CVE-2024-305901 PoCTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.
- CVE-2024-305911 PoCTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function.
- CVE-2024-305921 PoCTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the page parameter of the fromAddressNat function.
- CVE-2024-305931 PoCTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability located in the deviceName parameter of the formSetDeviceName function.
- CVE-2024-305941 PoCTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function.
- CVE-2024-305951 PoCTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the addWifiMacFilter function.
- CVE-2024-305961 PoCTenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the formSetDeviceName function.
- CVE-2024-305971 PoCTenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function.
- CVE-2024-305981 PoCTenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function.
- CVE-2024-305991 PoCTenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function.
- CVE-2024-306001 PoCTenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.
- CVE-2024-306011 PoCTenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function.
- CVE-2024-306021 PoCTenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.
- CVE-2024-306031 PoCTenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.
- CVE-2024-306041 PoCTenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the list1 parameter of the fromDhcpListClient function.
- CVE-2024-306061 PoCTenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the page parameter of the fromDhcpListClient function.
- CVE-2024-306071 PoCTenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.
- CVE-2024-306121 PoCTenda AC10U v15.03.06.48 has a stack overflow vulnerability in the deviceId, limitSpeed, limitSpeedUp parameter from formSetClientState…
- CVE-2024-306161 PoCChamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sensitive profiles…
- CVE-2024-306171 PoCA Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to initiate a request…
- CVE-2024-306181 PoCA Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary JavaScript in a web…
- CVE-2024-306201 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the serviceName parameter in the function fromAdvSetMacMtuWan.
- CVE-2024-306211 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the serverName parameter in the function fromAdvSetMacMtuWan.
- CVE-2024-306221 PoCTenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the mitInterface parameter from fromAddressNat function.
- CVE-2024-306231 PoCTenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the page parameter from fromDhcpListClient function.
- CVE-2024-306241 PoCTenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the urls parameter from saveParentControlInfo function.
- CVE-2024-306251 PoCTenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the entrys parameter from fromAddressNat function.
- CVE-2024-306261 PoCTenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedEndTime parameter from setSchedWifi function.
- CVE-2024-306271 PoCTenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the deviceId parameter from saveParentControlInfo function.
- CVE-2024-306281 PoCTenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the page parameter from fromAddressNat function.
- CVE-2024-306291 PoCTenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the list1 parameter from fromDhcpListClient function.
- CVE-2024-306301 PoCTenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the time parameter from saveParentControlInfo function.
- CVE-2024-306311 PoCTenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the schedStartTime parameter from setSchedWifi function.
- CVE-2024-306321 PoCTenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the security_5g parameter from formWifiBasicSet function.
- CVE-2024-306331 PoCTenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the security parameter from the formWifiBasicSet function.
- CVE-2024-306341 PoCTenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the mitInterface parameter in the fromAddressNat function.
- CVE-2024-306351 PoCTenda F1202 v1.2.0.20(408) has a stack overflow vulnerability located in the funcpara1 parameter in the formSetCfm function.
- CVE-2024-306361 PoCTenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the PPPOEPassword parameter in the formQuickIndex function.
- CVE-2024-306371 PoCTenda F1202 v1.2.0.20(408) has a command injection vulnerablility in the formWriteFacMac function in the mac parameter.
- CVE-2024-306381 PoCTenda F1202 v1.2.0.20(408) has a stack overflow vulnerability via the entrys parameter in the fromAddressNat function.
- CVE-2024-306391 PoCTenda F1202 v1.2.0.20(408) has a stack overflow vulnerability in the page parameter of fromAddressNat function.
- CVE-2024-308041 PoCAn issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbitrary code via…
- CVE-2024-308071 PoCAn issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_UnknownAtom::~AP4_UnknownAtom at…
- CVE-2024-308081 PoCAn issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_SubStream::~AP4_SubStream at…
- CVE-2024-308091 PoCAn issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in Ap4Sample.h in AP4_Sample::GetOffset() const,…
- CVE-2024-308491 PoCArbitrary file upload vulnerability in Sourcecodester Complete E-Commerce Site v1.0, allows remote attackers to execute arbitrary code via…
- CVE-2024-308512 PoCsDirectory Traversal vulnerability in codesiddhant Jasmin Ransomware v.1.0.1 allows an attacker to obtain sensitive information via the…
- CVE-2024-308621 PoCnetentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/index.php.
- CVE-2024-308711 PoCnetentsec NS-ASG 6.3 is vulnerable to SQL Injection via /WebPages/applyhardware.php.
- CVE-2024-308781 PoCA cross-site scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML and…
- CVE-2024-308791 PoCReflected Cross Site Scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML…
- CVE-2024-308801 PoCReflected Cross Site Scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML…
- CVE-2024-308831 PoCReflected Cross Site Scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML…
- CVE-2024-308841 PoCReflected Cross-Site Scripting (XSS) vulnerability in Discuz! version X3.4 20220811, allows remote attackers to execute arbitrary code and…
- CVE-2024-308851 PoCReflected Cross-Site Scripting (XSS) vulnerability in HadSky v7.6.3, allows remote attackers to execute arbitrary code and obtain…
- CVE-2024-308861 PoCA stored cross-site scripting (XSS) vulnerability in the remotelink function of HadSky v7.6.3 allows attackers to execute arbitrary web…
- CVE-2024-308891 PoCCross Site Scripting vulnerability in audimex audimexEE v.15.1.2 and fixed in 15.1.3.9 allows a remote attacker to execute arbitrary code…
- CVE-2024-308911 PoCA command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to construct cmdinput…
- CVE-2024-308962 PoCsInfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with…
- CVE-2024-309151 PoCAn issue was discovered in OpenDDS commit b1c534032bb62ad4ae32609778de6b8d6c823a66, allows a local attacker to cause a denial of service…
- CVE-2024-309391 PoCAn issue discovered in Yealink VP59 Teams Editions with firmware version 91.15.0.118 allows a physically proximate attacker to gain…
- CVE-2024-309461 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/co_do.php.
- CVE-2024-309531 PoCA stored cross-site scripting (XSS) vulnerability in Htmly v2.9.5 allows attackers to execute arbitrary web scripts or HTML via a crafted…
- CVE-2024-309611 PoCInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble…
- CVE-2024-309651 PoCDedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/member_scores.php.
- CVE-2024-309731 PoCAn issue in V-SOL G/EPON ONU HG323AC-B with firmware version V2.0.08-210715 allows an attacker to execute arbtirary code and obtain…
- CVE-2024-309791 PoCCross Site Scripting vulnerability in Cyber Cafe Management System 1.0 allows a remote attacker to execute arbitrary code via the compname…
- CVE-2024-309801 PoCSQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL…
- CVE-2024-309811 PoCSQL Injection vulnerability in /edit-computer-detail.php in phpgurukul Cyber Cafe Management System Using PHP & MySQL v1.0 allows…
- CVE-2024-309851 PoCSQL Injection vulnerability in "B/W Dates Reports" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to…
- CVE-2024-309861 PoCCross Site Scripting vulnerability in /edit-services-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows…
- CVE-2024-309871 PoCCross Site Scripting vulnerability in /bwdates-reports-ds.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows…
- CVE-2024-309881 PoCCross Site Scripting vulnerability in /search-invoices.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers…
- CVE-2024-309891 PoCCross Site Scripting vulnerability in /edit-client-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows…
- CVE-2024-309901 PoCSQL Injection vulnerability in the "Invoices" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute…
- CVE-2024-309982 PoCsSQL Injection vulnerability in PHPGurukul Men Salon Management System v.2.0, allows remote attackers to execute arbitrary code and obtain…