CVE-2024-35000 to CVE-2024-35999
67 CVEs with public proof-of-concept exploits.
- CVE-2024-350091 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component…
- CVE-2024-350101 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component…
- CVE-2024-350111 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component…
- CVE-2024-350121 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component…
- CVE-2024-350391 PoCidccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/tplSys_deal.php?mudi=area.
- CVE-2024-350481 PoCAn issue in SurveyKing v1.3.1 allows attackers to execute a session replay attack after a user changes their password.
- CVE-2024-350491 PoCSurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-25590.
- CVE-2024-350501 PoCAn issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was deleted by an Admin.
- CVE-2024-351061 PoCNEXTU FLETA AX1500 WIFI6 v1.0.3 was discovered to contain a buffer overflow at /boafrm/formIpQoS. This vulnerability allows attackers to…
- CVE-2024-351081 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component…
- CVE-2024-351091 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /homePro_deal.php?mudi=add&nohrefStr=close.
- CVE-2024-351101 PoCA reflected XSS vulnerability has been found in YzmCMS 7.1. The vulnerability exists in yzmphp/core/class/application.class.php: when…
- CVE-2024-351331 PoCIBM Security Verify Access HTTP open redirect
- CVE-2024-351751 PoCsshpiper's Enabling of Proxy Protocol without proper feature flagging allows faking source address
- CVE-2024-351761 PoCREXML contains a denial of service vulnerability
- CVE-2024-351771 PoCImproper Access Control in wazuh-agent
- CVE-2024-351811 PoCGHSL-2024-013 Meshery SQL Injection vulnerability
- CVE-2024-351821 PoCGHSL-2024-014 Meshery SQL Injection vulnerability
- CVE-2024-351892 PoCsSensitive Data Disclosure Vulnerability in Connection Configuration Endpoints in Fides
- CVE-2024-351901 PoCAsterisk' res_pjsip_endpoint_identifier_ip: wrongly matches ALL unauthorized SIP requests
- CVE-2024-352052 PoCsThe WPS Office (aka cn.wps.moffice_eng) application before 17.0.0 for Android fails to properly sanitize file names before processing them…
- CVE-2024-352191 PoCOpenAPI Generator Online - Arbitrary File Read/Delete
- CVE-2024-352301 PoCWelcome and About GeoServer pages communicate version and revision information
- CVE-2024-352311 PoCrack-contrib vulnerable to Denial of Service due to the unconstrained value of the incoming "profiler_runs" parameter
- CVE-2024-352352 PoCsCupsd Listen arbitrary chmod 0140777
- CVE-2024-352361 PoCAudiobookshelf Cross-Site-Scripting vulnerability via crafted ebooks
- CVE-2024-352421 PoCComposer vulnerable to command injection via malicious git/hg branch names
- CVE-2024-352507 PoCsKEVWindows Kernel-Mode Driver Elevation of Privilege Vulnerability
- CVE-2024-352861 PoCA vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL…
- CVE-2024-353151 PoCA vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI)…
- CVE-2024-353331 PoCA stack-buffer-overflow vulnerability exists in the read_charset_decl function of html2xhtml 1.3. This vulnerability occurs due to…
- CVE-2024-353391 PoCTenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac.
- CVE-2024-353401 PoCTenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the cmdinput parameter at…
- CVE-2024-353621 PoCEcshop 3.6 is vulnerable to Cross Site Scripting (XSS) via ecshop/article_cat.php.
- CVE-2024-353731 PoCMocodo Mocodo Online 4.2.6 and below is vulnerable to Remote Code Execution via /web/rewrite.php.
- CVE-2024-353741 PoCMocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers…
- CVE-2024-353841 PoCAn issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_array_length function in the mjs.c file.
- CVE-2024-353851 PoCAn issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_mk_ffi_sig function in the mjs.c file.
- CVE-2024-353861 PoCAn issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_do_gc function in the mjs.c file.
- CVE-2024-354101 PoCwac commit 385e1 was discovered to contain a heap overflow via the interpret function at /wac-asan/wa.c. This vulnerability allows…
- CVE-2024-354231 PoCvmir e8117 was discovered to contain a heap buffer overflow via the wasm_parse_section_functions function at /src/vmir_wasm_parser.c.
- CVE-2024-354291 PoCZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via eventRecord.
- CVE-2024-354341 PoCIrontec Sngrep v1.8.1 was discovered to contain a heap buffer overflow via the function rtp_check_packet at /sngrep/src/rtp.c. This…
- CVE-2024-354691 PoCA SQL injection vulnerability in /hrm/user/ in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary…
- CVE-2024-354751 PoCA Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The…
- CVE-2024-354982 PoCsA cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
- CVE-2024-355111 PoCphpgurukul Men Salon Management System v2.0 is vulnerable to SQL Injection via the "username" parameter of /msms/admin/index.php.
- CVE-2024-355381 PoCTypecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by…
- CVE-2024-355392 PoCsTypecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows…
- CVE-2024-355402 PoCsA stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2024-355501 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=rev.
- CVE-2024-355511 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=add.
- CVE-2024-355521 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component…
- CVE-2024-355531 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component…
- CVE-2024-355541 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component…
- CVE-2024-355551 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component…
- CVE-2024-355561 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsSys_deal.php?mudi=infoSet.
- CVE-2024-355571 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component…
- CVE-2024-355581 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=rev&nohrefStr=close.
- CVE-2024-355591 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component…
- CVE-2024-355601 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component…
- CVE-2024-355611 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=add&nohrefStr=close.
- CVE-2024-355842 PoCsSQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in…
- CVE-2024-355911 PoCAn arbitrary file upload vulnerability in O2OA v8.3.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.
- CVE-2024-356271 PoCtileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /data/v3/?key.
- CVE-2024-356931 PoCWordPress 12 Step Meeting List plugin <= 3.14.33 - Cross Site Scripting (XSS) vulnerability
- CVE-2024-356941 PoCWordPress WPMobile.App plugin <= 11.41 - Cross Site Scripting (XSS) vulnerability