CVE-2024-32000 to CVE-2024-32999
103 CVEs with public proof-of-concept exploits.
- CVE-2024-3200280 PoCsGit's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution
- CVE-2024-320042 PoCsGit vulnerable to Remote Code Execution while cloning special-crafted local repositories
- CVE-2024-3201915 PoCsndsudo: local privilege escalation via untrusted search path
- CVE-2024-320201 PoCCloning local Git repository by untrusted user allows the untrusted user to modify objects in the cloned repository at will
- CVE-2024-320211 PoCLocal Git clone may hardlink arbitrary user-readable files into the new repository's "objects/" directory
- CVE-2024-320221 PoCKohya_ss is vulnerable to a command injection in basic_caption_gui.py (GHSL-2024-019)
- CVE-2024-320231 PoCKohya_ss vulnerable to path injection in `common_gui.py` `find_and_replace` function (`GHSL-2024-024`)
- CVE-2024-320241 PoCKohya_ss vulenrable to path injection in `common_gui.py` `add_pre_postfix` function (`GHSL-2024-023`)
- CVE-2024-320251 PoCKohya_ss is vulnerable to a command injection in `group_images_gui.py` (`GHSL-2024-021`)
- CVE-2024-320261 PoCKohya_ss is vulnerable to a command injection in `git_caption_gui.py` (`GHSL-2024-020`)
- CVE-2024-320271 PoCKohya_ss is vulnerable to a command injection in `finetune_gui.py` (`GHSL-2024-022`)
- CVE-2024-321041 PoCWordPress NextMove Lite plugin <= 2.18.1 - Cross Site Request Forgery (CSRF) vulnerability
- CVE-2024-321111 PoCWordPress core < 6.5.5 - Auth. Arbitrary .html File Read (Windows Only) vulnerability
- CVE-2024-321138 PoCsKEVApache OFBiz: Path traversal leading to RCE
- CVE-2024-321144 PoCsApache ActiveMQ: Jolokia and REST API were not secured with default configuration
- CVE-2024-321281 PoCWordPress Realtyna Organic IDX plugin + WPL Real Estate plugin <= 4.14.4 - Unauthenticated SQL Injection vulnerability
- CVE-2024-321361 PoCWordPress BWL Advanced FAQ Manager plugin <= 2.0.3 - Auth. SQL Injection vulnerability
- CVE-2024-321631 PoCCMSeasy 7.7.7.9 is vulnerable to code execution.
- CVE-2024-321661 PoCWebid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now…
- CVE-2024-321671 PoCSourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend settings have the…
- CVE-2024-322061 PoCA stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows attackers to execute…
- CVE-2024-322281 PoCFFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.
- CVE-2024-322291 PoCFFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:5 in copy_column.
- CVE-2024-322301 PoCFFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in…
- CVE-2024-322311 PoCStash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort parameter.
- CVE-2024-322382 PoCsH3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accessed via the…
- CVE-2024-322541 PoCPhpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via…
- CVE-2024-322562 PoCsPhpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via…
- CVE-2024-322581 PoCThe network server of fceux 2.7.0 has a path traversal vulnerability, allowing attackers to overwrite any files on the server without…
- CVE-2024-322811 PoCTenda AC7V1.0 v15.03.06.44 firmware contains a command injection vulnerablility in formexeCommand function via the cmdinput parameter.
- CVE-2024-322831 PoCTenda FH1203 V2.0.1.6 firmware has a command injection vulnerablility in formexeCommand function via the cmdinput parameter.
- CVE-2024-322851 PoCTenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the password parameter in the formaddUserName function.
- CVE-2024-322861 PoCTenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromVirtualSer function.
- CVE-2024-322871 PoCTenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the qos parameter in the fromqossetting function.
- CVE-2024-322881 PoCTenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromwebExcptypemanFilter…
- CVE-2024-322901 PoCTenda W30E v1.0 v1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in the fromAddressNat function.
- CVE-2024-322911 PoCTenda W30E v1.0 firmware v1.0.1.25(633) has a stack overflow vulnerability via the page parameter in the fromNatlimit function.
- CVE-2024-322921 PoCTenda W30E v1.0 V1.0.1.25(633) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput…
- CVE-2024-322931 PoCTenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in the fromDhcpListClient function.
- CVE-2024-322991 PoCTenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle function.
- CVE-2024-323011 PoCTenda AC7V1.0 v15.03.06.44 firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle function.
- CVE-2024-323061 PoCTenda AC10U v1.0 Firmware v15.03.06.49 has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.
- CVE-2024-323071 PoCTenda FH1205 V2.0.0.7(775) firmware has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.
- CVE-2024-323101 PoCTenda F1203 V2.0.1.6 firmware has a stack overflow vulnerability located in the PPW parameter of the fromWizardHandle function.
- CVE-2024-323111 PoCTenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSetting function.
- CVE-2024-323121 PoCTenda F1203 V2.0.1.6 firmware has a stack overflow vulnerability located in the adslPwd parameter of the formWanParameterSetting function.
- CVE-2024-323131 PoCTenda FH1205 V2.0.0.7(775) firmware has a stack overflow vulnerability located via the adslPwd parameter of the formWanParameterSetting…
- CVE-2024-323141 PoCTenda AC500 V2.0.1.9(1307) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.
- CVE-2024-323161 PoCTenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability in the fromDhcpListClient function.
- CVE-2024-323171 PoCTenda AC10 v4.0 V16.03.10.13 and V16.03.10.20 firmware has a stack overflow vulnerability via the adslPwd parameter in the…
- CVE-2024-323181 PoCTenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the vlan parameter in the formSetVlanInfo function.
- CVE-2024-323201 PoCTenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the timeZone parameter in the formSetTimeZone function.
- CVE-2024-323441 PoCA cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or…
- CVE-2024-323591 PoCAn RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through designed commands to…
- CVE-2024-323691 PoCSQL Injection vulnerability in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive…
- CVE-2024-323701 PoCAn issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a…
- CVE-2024-323711 PoCAn issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their privileges and gain…
- CVE-2024-323911 PoCCross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.
- CVE-2024-323921 PoCCross Site Scripting vulnerability in CmSimple v.5.15 allows a remote attacker to execute arbitrary code via the functions.php component.
- CVE-2024-323992 PoCsDirectory Traversal vulnerability in RaidenMAILD Mail Server v.4.9.4 and before allows a remote attacker to obtain sensitive information…
- CVE-2024-324051 PoCCross Site Scripting vulnerability in inducer relate before v.2024.1 allows a remote attacker to escalate privileges via a crafted payload…
- CVE-2024-324061 PoCServer-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code…
- CVE-2024-324441 PoCWordPress RealHomes theme <= 4.3.6 - Privilege Escalation vulnerability
- CVE-2024-324591 PoCFreeRDP Out-Of-Bounds Read in ncrush_decompress
- CVE-2024-324611 PoCLibreNMS vulnerable to time-based SQL injection that leads to database extraction
- CVE-2024-324621 PoCFlatpak vulnerable to a sandbox escape via RequestBackground portal due to bad argument parsing
- CVE-2024-324671 PoCMeteraphsere vulnerable to unauthorized viewing by workspace members
- CVE-2024-324771 PoCRace condition when flushing input stream leads to permission prompt bypass
- CVE-2024-324791 PoCLibreNMS's Improper Sanitization on Service template name leads to Stored XSS
- CVE-2024-324802 PoCsLibreNMS's Time-Based Blind SQL injection leads to database extraction
- CVE-2024-324811 PoCvyper's range(start, start + N) reverts for negative numbers
- CVE-2024-326406 PoCsMasaCMS SQL Injection vulnerability
- CVE-2024-326461 PoCvyper performs double eval of the slice args when buffer from adhoc locations
- CVE-2024-326471 PoCvyper performs double eval of raw_args in create_from_blueprint
- CVE-2024-326481 PoCvyper default functions don't respect nonreentrancy keys
- CVE-2024-326491 PoCvyper performs double eval of the argument of sqrt
- CVE-2024-326501 PoCRustls vulnerable to an infinite loop in rustls::conn::ConnectionCommon::complete_io() with proper client input
- CVE-2024-326514 PoCsServer Side Template Injection in Jinja2 allows Remote Command Execution
- CVE-2024-326521 PoC@hono/node-server contains Denial of Service risk when receiving Host header that cannot be parsed
- CVE-2024-327001 PoCWordPress Kognetiks Chatbot for WordPress plugin <= 2.0.0 - Arbitrary File Upload vulnerability
- CVE-2024-327091 PoCWordPress WP-Recall plugin <= 16.26.5 - SQL Injection vulnerability
- CVE-2024-327351 PoCCyberPower PowerPanel Enterprise Missing Authentication
- CVE-2024-327361 PoCCyberPower PowerPanel Enterprise SQL Injection
- CVE-2024-327371 PoCCyberPower PowerPanel Enterprise SQL Injection
- CVE-2024-327381 PoCCyberPower PowerPanel Enterprise SQL Injection
- CVE-2024-327391 PoCCyberPower PowerPanel Enterprise SQL Injection
- CVE-2024-328251 PoCWordPress Simply Static plugin <= 3.1.3 - Sensitive Data Exposure via Log File vulnerability
- CVE-2024-328301 PoCWordPress buddyforms plugin <= 2.8.8- Arbitrary File Read and SSRF vulnerability
- CVE-2024-328661 PoCConform contains Prototype Pollution Vulnerability in `parseWith...` function
- CVE-2024-328692 PoCsHono vulnerable to Restricted Directory Traversal in serveStatic with deno
- CVE-2024-328701 PoCiTop hub connector Information disclosure
- CVE-2024-328802 PoCspyLoad allows upload to arbitrary folder lead to RCE
- CVE-2024-328841 PoCgix-transport indirect code execution via malicious username
- CVE-2024-329621 PoCXML signature verification bypass due improper verification of signature / signature spoofing
- CVE-2024-329631 PoCParameter Tampering vulnerability in Navidrome
- CVE-2024-329643 PoCslobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability
- CVE-2024-329652 PoCsssrf vulnerability in lobe-chat
- CVE-2024-329741 PoCEnvoy affected by a crash in EnvoyQuicServerStream::OnInitialHeadersComplete()
- CVE-2024-329751 PoCEnvoy crashes in QuicheDataReader::PeekVarInt62Length()
- CVE-2024-329761 PoCEnvoy can enter an endless loop while decompressing Brotli data with extra input
- CVE-2024-329771 PoCOctoPrint Authentication Bypass via X-Forwarded-For Header when autologinLocal is enabled
- CVE-2024-329821 PoCLitestar and Starlite affected by Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CVE-2024-329831 PoCMisskey allows the impersonation and takeover of remote accounts with unnormalized signed activities