CVE-2024-31000 to CVE-2024-31999
90 CVEs with public proof-of-concept exploits.
- CVE-2024-310021 PoCBuffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4…
- CVE-2024-310031 PoCBuffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the…
- CVE-2024-310051 PoCAn issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the…
- CVE-2024-310081 PoCAn issue was discovered in WUZHICMS version 4.1.0, allows an attacker to execute arbitrary code and obtain sensitive information via the…
- CVE-2024-310091 PoCSQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via lgid parameter in Banner.php.
- CVE-2024-310101 PoCSQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Banner.php.
- CVE-2024-310471 PoCAn issue in Academy Software Foundation openexr v.3.2.3 and before allows a local attacker to cause a denial of service (DoS) via the…
- CVE-2024-310611 PoCCross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via…
- CVE-2024-310621 PoCCross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via…
- CVE-2024-310631 PoCCross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via…
- CVE-2024-310641 PoCCross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via…
- CVE-2024-310651 PoCCross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via…
- CVE-2024-311111 PoCWordPress Core < 6.5.5 - Cross Site Scripting (XSS) vulnerability
- CVE-2024-311141 PoCWordPress Shortcode Addons <= 3.2.5 - Arbitrary File Upload vulnerability
- CVE-2024-311521 PoCThe LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web application, where a…
- CVE-2024-312041 PoCmailcow Cross-site Scripting Vulnerability via Exception Handler
- CVE-2024-312112 PoCsRemote Code Execution in `WP_HTML_Token`
- CVE-2024-312121 PoCSQL injection in index_chart_data action
- CVE-2024-312131 PoCInstantCMS Open Redirect vulnerability
- CVE-2024-312143 PoCsTraccar's unrestricted file upload vulnerability in device image upload could lead to remote code execution
- CVE-2024-312172 PoCs@strapi/plugin-upload has a Denial-of-Service via Improper Exception Handling
- CVE-2024-312233 PoCsFides Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URL
- CVE-2024-313091 PoCApache Traffic Server: HTTP/2 CONTINUATION frames can be utilized for DoS attack
- CVE-2024-313151 PoCIn multiple functions of ManagedServices.java, there is a possible way to hide an app with notification access in the Device & app…
- CVE-2024-3131711 PoCsIn multiple functions of ZygoteProcess.java, there is a possible way to achieve code execution as any app via WRITE_SECURE_SETTINGS due to…
- CVE-2024-313201 PoCIn setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation…
- CVE-2024-313511 PoCWordPress Copymatic plugin <= 1.6 - Unauthenticated Arbitrary File Upload vulnerability
- CVE-2024-313901 PoCWordPress Breakdance plugin <= 1.7.2 - Authenticated Remote Code Execution (RCE) vulnerability
- CVE-2024-314431 PoCCacti XSS vulnerability in lib/html_tree.php by reading dirty data stored in database
- CVE-2024-314441 PoCCacti XSS vulnerability in lib/html.php by reading dirty data stored in database
- CVE-2024-314451 PoCSQL Injection vulnerability in automation_get_new_graphs_sql
- CVE-2024-314481 PoCCross-site Scripting vulnerability in link CSV import in Combodo iTop
- CVE-2024-314491 PoCLua library commands may lead to stack overflow and RCE in Redis
- CVE-2024-314531 PoCPsiTransfer vulnerable to violation of the integrity of file distribution
- CVE-2024-314571 PoCgin-vue-admin background arbitrary code coverage vulnerability
- CVE-2024-314581 PoCCacti SQL Injection vulnerability in lib/html_form_templates.php by reading dirty data stored in database
- CVE-2024-314591 PoCCacti RCE vulnerability by file include in lib/plugin.php
- CVE-2024-314601 PoCCacti SQL Injection vulnerability in lib/api_automation.php caused by reading dirty data stored in database
- CVE-2024-314974 PoCsIn PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a…
- CVE-2024-315061 PoCSourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "id" parameter in admin/admin_cs.php.
- CVE-2024-315071 PoCSourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "request" parameter in admin/fetch_gendercs.php.
- CVE-2024-315101 PoCAn issue in Open Quantum Safe liboqs v.10.0 allows a remote attacker to escalate privileges via the crypto_sign_signature parameter in the…
- CVE-2024-315441 PoCA stored cross-site scripting (XSS) vulnerability in Computer Laboratory Management System v1.0 allows attackers to execute arbitrary…
- CVE-2024-315451 PoCComputer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/?page=user/manage_user&id=6.
- CVE-2024-315461 PoCComputer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/damage/view_damage.php.
- CVE-2024-315471 PoCComputer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/item/view_item.php.
- CVE-2024-315861 PoCA Cross Site Scripting (XSS) vulnerability exists in Computer Laboratory Management System version 1.0. This vulnerability allows a remote…
- CVE-2024-316101 PoCFile Upload vulnerability in the function for employees to upload avatars in Code-Projects Simple School Management System v1.0 allows…
- CVE-2024-316121 PoCEmlog pro2.3 is vulnerable to Cross Site Request Forgery (CSRF) via twitter.php which can be used with a XSS vulnerability to access…
- CVE-2024-316131 PoCBOSSCMS v3.10 is vulnerable to Cross Site Request Forgery (CSRF) in name="head_code" or name="foot_code."
- CVE-2024-316212 PoCsAn issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1…
- CVE-2024-316361 PoCAn issue in LIEF v.0.14.1 allows a local attacker to obtain sensitive information via the name parameter of the machd_reader.c component.
- CVE-2024-316481 PoCCross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts or HTML via a…
- CVE-2024-316491 PoCA cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML…
- CVE-2024-316501 PoCA cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML…
- CVE-2024-316511 PoCA cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML…
- CVE-2024-316521 PoCA cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML…
- CVE-2024-316661 PoCAn issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon_post.php component.
- CVE-2024-316781 PoCSourcecodester Loan Management System v1.0 is vulnerable to SQL Injection via the "password" parameter in the "login.php" file.
- CVE-2024-316801 PoCFile Upload vulnerability in Shibang Communications Co., Ltd. IP network intercom broadcasting system v.1.0 allows a local attacker to…
- CVE-2024-317471 PoCAn issue in Yealink VP59 Microsoft Teams Phone firmware 91.15.0.118 (fixed in 122.15.0.142) allows a physically proximate attacker to…
- CVE-2024-317501 PoCSQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the req_id parameter.
- CVE-2024-317551 PoCcJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of function…
- CVE-2024-317591 PoCAn issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function.
- CVE-2024-317601 PoCAn issue in sanluan flipped-aurora gin-vue-admin 2.4.x allows an attacker to escalate privileges via the Session Expiration component.
- CVE-2024-317711 PoCInsecure Permission vulnerability in TotalAV v.6.0.740 allows a local attacker to escalate privileges via a crafted file
- CVE-2024-317772 PoCsFile Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the…
- CVE-2024-317981 PoCIdentical Hardcoded Root Password for All Devices in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to…
- CVE-2024-317991 PoCInformation Disclosure in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to read the WiFi passphrase via…
- CVE-2024-318001 PoCAuthentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command…
- CVE-2024-318041 PoCAn unquoted service path vulnerability in Terratec DMX_6Fire USB v.1.23.0.02 allows a local attacker to escalate privileges via the…
- CVE-2024-318195 PoCsAn issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the…
- CVE-2024-318351 PoCCross Site Scripting vulnerability in flatpress CMS Flatpress v1.3 allows a remote attacker to execute arbitrary code via a crafted…
- CVE-2024-318393 PoCsCross Site Scripting vulnerability in tiagorlampert CHAOS v.5.0.1 allows a remote attacker to escalate privileges via the…
- CVE-2024-318401 PoCAn issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An…
- CVE-2024-318411 PoCAn issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers…
- CVE-2024-318431 PoCAn issue was discovered in Italtel Embrace 1.6.4. The Web application does not properly check the parameters sent as input before they are…
- CVE-2024-318441 PoCAn issue was discovered in Italtel Embrace 1.6.4. The server does not properly handle application errors. In some cases, this leads to a…
- CVE-2024-318451 PoCAn issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to…
- CVE-2024-318461 PoCAn issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access to a resource from…
- CVE-2024-318471 PoCAn issue was discovered in Italtel Embrace 1.6.4. A stored cross-site scripting (XSS) vulnerability allows authenticated and…
- CVE-2024-318482 PoCsA path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server,…
- CVE-2024-318492 PoCsA path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which…
- CVE-2024-318502 PoCsA path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty server, which…
- CVE-2024-318512 PoCsA path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which…
- CVE-2024-319032 PoCsIBM Sterling B2B Integrator Standard Edition code execution
- CVE-2024-319641 PoCA vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970…
- CVE-2024-319827 PoCsXWiki Platform: Remote code execution as guest via DatabaseSearch
- CVE-2024-319893 PoCsArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache
- CVE-2024-319981 PoCCSRF security issue on CSV import in Combodo iTop