CVE-2024-34000 to CVE-2024-34999
111 CVEs with public proof-of-concept exploits.
- CVE-2024-340612 PoCsReflected cross site scripting in changedetection.io
- CVE-2024-340652 PoCs@strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypass
- CVE-2024-340691 PoCWerkzeug's improper usage of a pathname and improper CSRF protection results in the remote command execution
- CVE-2024-340703 PoCsFroxlor Vulnerable to Blind XSS Leading to Froxlor Application Compromise
- CVE-2024-340821 PoCGrav Arbitrary File Read to Account Takeover
- CVE-2024-3410225 PoCsKEVXXE can expose crypt key and other secrets granting full admin access
- CVE-2024-341441 PoCA sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier…
- CVE-2024-341951 PoCTOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow. In the boa server program's CGI…
- CVE-2024-341961 PoCTotolink AC1200 Wireless Dual Band Gigabit Router A3002RU_V3 Firmware V3.0.0-B20230809.1615 is vulnerable to Buffer Overflow. The "boa"…
- CVE-2024-341981 PoCTOTOLINK AC1200 Wireless Router A3002RU V2.1.1-B20230720.1011 is vulnerable to Buffer Overflow. The formWlEncrypt CGI handler in the boa…
- CVE-2024-342001 PoCTOTOLINK CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpQosRules function.
- CVE-2024-342011 PoCTOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the getSaveConfig function.
- CVE-2024-342021 PoCTOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setMacFilterRules function.
- CVE-2024-342031 PoCTOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setLanguageCfg function.
- CVE-2024-342041 PoCTOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setUpgradeFW function…
- CVE-2024-342061 PoCTOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setWebWlanIdx…
- CVE-2024-342071 PoCTOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setStaticDhcpConfig function.
- CVE-2024-342091 PoCTOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpPortFilterRules function.
- CVE-2024-342101 PoCTOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the CloudACMunualUpdate…
- CVE-2024-342121 PoCTOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the CloudACMunualUpdate function.
- CVE-2024-342131 PoCTOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the SetPortForwardRules function.
- CVE-2024-342151 PoCTOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setUrlFilterRules function.
- CVE-2024-342171 PoCTOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the addWlProfileClientMode…
- CVE-2024-342181 PoCTOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the NTPSyncWithHost…
- CVE-2024-342191 PoCTOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allows attackers to…
- CVE-2024-342201 PoCSourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the 'leave' parameter.
- CVE-2024-342211 PoCSourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.
- CVE-2024-342221 PoCSourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.
- CVE-2024-342231 PoCInsecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow attackers to…
- CVE-2024-342241 PoCCross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0…
- CVE-2024-342251 PoCCross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0…
- CVE-2024-342261 PoCSQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&id=1 in SourceCodester Visitor Management System 1.0 allow attackers…
- CVE-2024-342301 PoCA cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web…
- CVE-2024-342311 PoCA cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web…
- CVE-2024-342351 PoCOpen5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.…
- CVE-2024-342411 PoCA cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript payload using the…
- CVE-2024-342461 PoCwasm3 v0.5.0 was discovered to contain an out-of-bound memory read which leads to segmentation fault via the function "main" in…
- CVE-2024-342491 PoCwasm3 v0.5.0 was discovered to contain a heap buffer overflow which leads to segmentation fault via the function "DeallocateSlot" in…
- CVE-2024-342501 PoCA heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause…
- CVE-2024-342511 PoCAn out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to…
- CVE-2024-342521 PoCwasm3 v0.5.0 was discovered to contain a global buffer overflow which leads to segmentation fault via the function…
- CVE-2024-342572 PoCsTOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of…
- CVE-2024-343101 PoCJin Fang Times Content Management System v3.2.3 was discovered to contain a SQL injection vulnerability via the id parameter.
- CVE-2024-343121 PoCVirtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component…
- CVE-2024-343131 PoCAn issue in VPL Jail System up to v4.0.2 allows attackers to execute a directory traversal via a crafted request to a public endpoint.
- CVE-2024-343271 PoCSielox AnyWare v2.1.2 was discovered to contain a SQL injection vulnerability via the email address field of the password reset form.
- CVE-2024-343291 PoCInsecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch allows…
- CVE-2024-343401 PoCAuthentication Bypass when using using older password hashes
- CVE-2024-343421 PoCreact-pdf's PDF.js vulnerable to arbitrary JavaScript execution upon opening a malicious PDF
- CVE-2024-343431 PoCCross-site Scripting (XSS) in navigateTo if used after SSR in nuxt
- CVE-2024-343441 PoCRemote code execution via the browser when running the test locally in nuxt
- CVE-2024-343471 PoC@hoppscotch/cli affected by Sandbox Escape in @hoppscotch/js-sandbox leads to RCE
- CVE-2024-343517 PoCsNext.js Server-Side Request Forgery in Server Actions
- CVE-2024-343522 PoCsArbitrary file write vulnerability in 1Panel
- CVE-2024-343591 PoCllama-cpp-python vulnerable to Remote Code Execution by Server-Side Template Injection in Model Metadata
- CVE-2024-343613 PoCsPi-hole Blind Server-Side Request Forgery (SSRF) vulnerability can lead to Remote Code Execution (RCE)
- CVE-2024-343621 PoCEnvoy affected by a crash (use-after-free) in EnvoyQuicServerStream
- CVE-2024-343631 PoCEnvoy can crash due to uncaught nlohmann JSON exception
- CVE-2024-343701 PoCWordPress EAN for WooCommerce plugin <= 4.8.9 - Arbitrary Option Update to Privilege Escalation vulnerability
- CVE-2024-343912 PoCslibxmljs attrs type confusion RCE
- CVE-2024-343922 PoCslibxmljs namespaces type confusion RCE
- CVE-2024-343971 PoCAn issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals…
- CVE-2024-344011 PoCSavsoft Quiz 6.0 allows stored XSS via the index.php/quiz/insert_quiz/ quiz_name parameter.
- CVE-2024-344081 PoCTencent libpag through 4.3.51 has an integer overflow in DecodeStream::checkEndOfFile() in codec/utils/DecodeStream.cpp via a crafted PAG…
- CVE-2024-344441 PoCWordPress Slider Revolution plugin < 6.7.0 - Unauthenticated Broken Access Control vulnerability
- CVE-2024-344481 PoCGhost before 5.82.0 allows CSV Injection during a member CSV export.
- CVE-2024-344521 PoCCMSimple_XH 1.7.6 allows XSS by uploading a crafted SVG document.
- CVE-2024-344631 PoCBPL Personal Weighing Scale PWS-01BT IND/09/18/599 devices send sensitive information in unencrypted BLE packets. (The packet data also…
- CVE-2024-344671 PoCThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl.
- CVE-2024-344691 PoCRukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save.
- CVE-2024-344706 PoCsAn issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability exists in the…
- CVE-2024-344721 PoCAn issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An authenticated blind SQL injection vulnerability exists in the…
- CVE-2024-344741 PoCClario through 2024-04-11 for Desktop has weak permissions for %PROGRAMDATA%\Clario and tries to load DLLs from there as SYSTEM.
- CVE-2024-344831 PoCOFPGroupDescStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via OFPBucket.len=0.
- CVE-2024-344841 PoCOFPBucket in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via action.len=0.
- CVE-2024-344861 PoCOFPPacketQueue in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via OFPQueueProp.len=0.
- CVE-2024-344871 PoCOFPFlowStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via inst.length=0.
- CVE-2024-344881 PoCOFPMultipartReply in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via b.length=0.
- CVE-2024-344891 PoCOFPHello in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via length=0.
- CVE-2024-345681 PoCWordPress LetterPress Newsletter plugin <= 1.2.1 - Cross Site Scripting (XSS) vulnerability
- CVE-2024-345821 PoCSunhillo SureLine through 8.10.0 on RICI 5000 devices allows cgi/usrPasswd.cgi userid_change XSS within the Forgot Password feature.
- CVE-2024-346932 PoCsApache Superset: Server arbitrary file read
- CVE-2024-347141 PoCHoppscotch Extension responds to calls made by origins not in the domain list
- CVE-2024-347152 PoCsPartial Password Exposure Vulnerability in Fides Webserver Logs
- CVE-2024-347165 PoCsPrestaShop vulnerable to XSS via customer contact form in FO, through file upload
- CVE-2024-347391 PoCIn shouldRestrictOverlayActivities of UsbProfileGroupSettingsManager.java, there is a possible escape from SUW due to a logic error in the…
- CVE-2024-347411 PoCIn setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be visible on the…
- CVE-2024-348311 PoCcross-site scripting (XSS) vulnerability in Gibbon Core v26.0.00 allows an attacker to execute arbitrary code via the imageLink parameter…
- CVE-2024-348321 PoCDirectory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded…
- CVE-2024-348332 PoCsSourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An…
- CVE-2024-348521 PoCF-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point in the…
- CVE-2024-348541 PoCF-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.`
- CVE-2024-348991 PoCWWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS).
- CVE-2024-349051 PoCFlyFish v3.0.0 was discovered to contain a buffer overflow via the password parameter on the login page. This vulnerability allows…
- CVE-2024-349061 PoCAn arbitrary file upload vulnerability in dootask v0.30.13 allows attackers to execute arbitrary code via uploading a crafted PDF file.
- CVE-2024-349421 PoCTenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter at…
- CVE-2024-349431 PoCTenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at…
- CVE-2024-349451 PoCTenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPW parameter at…
- CVE-2024-349461 PoCTenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at…
- CVE-2024-349501 PoCD-Link DIR-822+ v1.0.5 was discovered to contain a stack-based buffer overflow vulnerability in the SetNetworkTomographySettings module.
- CVE-2024-349521 PoCtaurusxin ncmdump v1.3.2 was discovered to contain a segmentation violation via the NeteaseCrypt::FixMetadata() function at…
- CVE-2024-349531 PoCAn issue in taurusxin ncmdump v1.3.2 allows attackers to cause a Denial of Service (DoS) via memory exhaustion by supplying a crafted .ncm…
- CVE-2024-349541 PoCCode-projects Budget Management 1.0 is vulnerable to Cross Site Scripting (XSS) via the budget parameter.
- CVE-2024-349551 PoCCode-projects Budget Management 1.0 is vulnerable to SQL Injection via the delete parameter.
- CVE-2024-349572 PoCsidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/sysImages_deal.php?mudi=infoSet.
- CVE-2024-349583 PoCsidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/banner_deal.php?mudi=add
- CVE-2024-349591 PoCDedeCMS V5.7.113 is vulnerable to Cross Site Scripting (XSS) via sys_data_replace.php.
- CVE-2024-349741 PoCTenda AC18 v15.03.05.19 is vulnerable to Buffer Overflow in the formSetPPTPServer function via the endIp parameter.
- CVE-2024-349821 PoCAn arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to execute arbitrary code…
- CVE-2024-349872 PoCsA SQL Injection vulnerability exists in the `ofrs/admin/index.php` script of PHPGurukul Online Fire Reporting System 1.2. The…
- CVE-2024-349971 PoCjoblib v1.4.2 was discovered to contain a deserialization vulnerability via the component…