CVE-2024-33000 to CVE-2024-33999
93 CVEs with public proof-of-concept exploits.
- CVE-2024-331011 PoCA stored cross-site scripting (XSS) vulnerability in the component /action/anti.php of ThinkSAAS v3.7.0 allows attackers to execute…
- CVE-2024-331021 PoCA stored cross-site scripting (XSS) vulnerability in the component /pubs/counter.php of ThinkSAAS v3.7.0 allows attackers to execute…
- CVE-2024-331101 PoCD-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component.
- CVE-2024-331112 PoCsD-Link DIR-845L router <=v1.01KRb03 is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php.
- CVE-2024-331121 PoCD-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.
- CVE-2024-331134 PoCsD-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.
- CVE-2024-331811 PoCTenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceMac parameter at…
- CVE-2024-332091 PoCFlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry"…
- CVE-2024-332101 PoCA cross-site scripting (XSS) vulnerability has been identified in Flatpress 1.3. This vulnerability allows an attacker to inject malicious…
- CVE-2024-332111 PoCTenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword parameter in…
- CVE-2024-332121 PoCTenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter in…
- CVE-2024-332131 PoCTenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in…
- CVE-2024-332141 PoCTenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter in…
- CVE-2024-332151 PoCTenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in…
- CVE-2024-332171 PoCTenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter in…
- CVE-2024-332311 PoCCross Site Scripting vulnerability in Ferozo Email version 1.1 allows a local attacker to execute arbitrary code via a crafted payload to…
- CVE-2024-332551 PoCJerryscript commit cefd391 was discovered to contain an Assertion Failure via ECMA_STRING_IS_REF_EQUALS_TO_ONE (string_p) in…
- CVE-2024-332581 PoCJerryscript commit ff9ff8f was discovered to contain a segmentation violation via the component vm_loop at jerry-core/vm/vm.c.
- CVE-2024-332591 PoCJerryscript commit cefd391 was discovered to contain a segmentation violation via the component scanner_seek at…
- CVE-2024-332601 PoCJerryscript commit cefd391 was discovered to contain a segmentation violation via the component parser_parse_class at…
- CVE-2024-332631 PoCQuickJS commit 3b45d15 was discovered to contain an Assertion Failure via JS_FreeRuntime(JSRuntime *) at quickjs.c.
- CVE-2024-332882 PoCsPrison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the Admin login page.
- CVE-2024-332971 PoCCross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name…
- CVE-2024-332981 PoCMicroweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new…
- CVE-2024-332991 PoCCross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last…
- CVE-2024-333021 PoCSourceCodester Product Show Room 1.0 and before is vulnerable to Cross Site Scripting (XSS) via "Middle Name" under Add Users.
- CVE-2024-333031 PoCSourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" under Add Users.
- CVE-2024-333041 PoCSourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "Last Name" under Add Users.
- CVE-2024-333051 PoCSourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Middle Name" parameter in Create User.
- CVE-2024-333061 PoCSourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" parameter in Create User.
- CVE-2024-333071 PoCSourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Last Name" parameter in Create User.
- CVE-2024-333261 PoCA cross-site scripting (XSS) vulnerability in the component XsltResultControllerHtml.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to…
- CVE-2024-333321 PoCAn issue discovered in SpringBlade 3.7.1 allows attackers to obtain sensitive information via crafted GET request to…
- CVE-2024-333381 PoCCross Site Scripting vulnerability in jizhicms v.2.5.4 allows a remote attacker to obtain sensitive information via a crafted article…
- CVE-2024-333451 PoCD-Link DIR-823G A1V1.0.2B05 was found to contain a Null-pointer dereference in the main function of upload_firmware.cgi, which allows…
- CVE-2024-333501 PoCDirectory Traversal vulnerability in TaoCMS v.3.0.2 allows a remote attacker to execute arbitrary code and obtain sensitive information…
- CVE-2024-333651 PoCBuffer Overflow vulnerability in Tenda AC10 v4 US_AC10V4.0si_V16.03.10.20_cn allows a remote attacker to execute arbitrary code via the…
- CVE-2024-333711 PoCCross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to execute arbitrary code via the typeid parameter in the…
- CVE-2024-333831 PoCArbitrary File Read vulnerability in novel-plus 4.3.0 and before allows a remote attacker to obtain sensitive information via a crafted…
- CVE-2024-333981 PoCThere is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allows an attacker to…
- CVE-2024-334011 PoCCross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to run arbitrary code via the mnum parameter.
- CVE-2024-334282 PoCsBuffer-Overflow vulnerability at conv.c:68 of stsaz phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via the a crafted…
- CVE-2024-334292 PoCsBuffer-Overflow vulnerability at pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via a crafted…
- CVE-2024-334302 PoCsAn issue in phiola/src/afilter/pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via the a crafted…
- CVE-2024-334312 PoCsAn issue in phiola/src/afilter/conv.c:115 of phiola v2.0-rc22 allows a remote attacker to cause a denial of service via a crafted .wav file.
- CVE-2024-334362 PoCsAn issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information due to missing support for CSS variables
- CVE-2024-334372 PoCsAn issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information due to missing support for CSS Style…
- CVE-2024-334381 PoCFile Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file.
- CVE-2024-334432 PoCsAn issue in onethink v.1.1 allows a remote attacker to execute arbitrary code via a crafted script to the AddonsController.class.php…
- CVE-2024-334442 PoCsSQL injection vulnerability in onethink v.1.1 allows a remote attacker to escalate privileges via a crafted script to the…
- CVE-2024-334452 PoCsAn issue in hisiphp v2.0.111 allows a remote attacker to execute arbitrary code via a crafted script to the SystemPlugins::mkInfo…
- CVE-2024-334521 PoCAn issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD…
- CVE-2024-334851 PoCSQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote attacker to obtain…
- CVE-2024-335221 PoCPrivilege escalation in Calico CNI install binary
- CVE-2024-335261 PoCA Stored Cross-site Scripting (XSS) vulnerability in the "Import of user role and title of user role" feature in ILIAS 7 before 7.30 and…
- CVE-2024-335271 PoCA Stored Cross-site Scripting (XSS) vulnerability in the "Import of Users and login name of user" feature in ILIAS 7 before 7.30 and ILIAS…
- CVE-2024-335281 PoCA Stored Cross-site Scripting (XSS) vulnerability in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authenticated attackers…
- CVE-2024-335291 PoCILIAS 7 before 7.30 and ILIAS 8 before 8.11 as well as ILIAS 9.0 allow remote authenticated attackers with administrative privileges to…
- CVE-2024-335592 PoCsWordPress XStore theme <= 9.3.5 - Unauthenticated SQL Injection vulnerability
- CVE-2024-335751 PoCWordPress User Meta plugin <= 3.0 - Sensitive Data Exposure vulnerability
- CVE-2024-336051 PoCImproper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for the details of…
- CVE-2024-336101 PoC"sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides logged-in users'…
- CVE-2024-336632 PoCspython-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.
- CVE-2024-336642 PoCspython-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web…
- CVE-2024-336691 PoCAn issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is…
- CVE-2024-336991 PoCThe LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers to change the…
- CVE-2024-337001 PoCThe LevelOne WBR-6012 router firmware R0.40e6 suffers from an input validation vulnerability within its FTP functionality, enabling…
- CVE-2024-337221 PoCSOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].
- CVE-2024-337241 PoCSOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.
- CVE-2024-337631 PoClunasvg v2.3.9 was discovered to contain a stack-buffer-underflow at lunasvg/source/layoutcontext.cpp.
- CVE-2024-337641 PoClunasvg v2.3.9 was discovered to contain a stack-overflow at lunasvg/source/element.h.
- CVE-2024-337661 PoClunasvg v2.3.9 was discovered to contain an FPE (Floating Point Exception) at blend_transformed_tiled_argb.isra.0.
- CVE-2024-337671 PoClunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source.
- CVE-2024-337681 PoClunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source_over.
- CVE-2024-337711 PoCA buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via goform/formWPS, allows remote authenticated users to…
- CVE-2024-337721 PoCA buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formTcpipSetup allows remote authenticated users to…
- CVE-2024-337731 PoCA buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanGuestSetup allows remote authenticated users to…
- CVE-2024-337741 PoCA buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanSetup_Wizard allows remote authenticated users to…
- CVE-2024-337751 PoCAn issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.
- CVE-2024-337891 PoCLinksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint.
- CVE-2024-337921 PoCnetis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the tracert page.
- CVE-2024-337931 PoCnetis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the ping test page.
- CVE-2024-338201 PoCTotolink AC1200 Wireless Dual Band Gigabit Router A3002R_V4 Firmware V4.0.0-B20230531.1404 is vulnerable to Buffer Overflow via the…
- CVE-2024-338291 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=updateWebCache.
- CVE-2024-338321 PoCOneNav v0.9.35-20240318 was discovered to contain a Server-Side Request Forgery (SSRF) via the component…
- CVE-2024-338351 PoCTenda AC18 V15.03.05.05 has a stack overflow vulnerability in the remoteIp parameter from formSetSafeWanWebMan function.
- CVE-2024-338831 PoCThe ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.
- CVE-2024-338912 PoCsDelinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in…
- CVE-2024-338961 PoCCosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper…
- CVE-2024-338991 PoCRARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen output, or cause a denial of service, via…
- CVE-2024-339011 PoCIssue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database…
- CVE-2024-339111 PoCWordPress The School Management Pro plugin <= 10.3.4 - SQL Injection vulnerability
- CVE-2024-339391 PoCWordPress LMS by Masteriyo plugin <= 1.7.3 - Broken Authentication vulnerability