CVE-2024-36000 to CVE-2024-36999
72 CVEs with public proof-of-concept exploits.
- CVE-2024-360391 PoCPyMySQL through 1.1.0 allows SQL injection if used with untrusted JSON input because keys are not escaped by escape_dict.
- CVE-2024-360421 PoCSilverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an…
- CVE-2024-360521 PoCRARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than…
- CVE-2024-360791 PoCAn issue was discovered in Vaultize 21.07.27. When uploading files, there is no check that the filename parameter is correct. As a result,…
- CVE-2024-361044 PoCsApache OFBiz: Path traversal leading to a RCE
- CVE-2024-361151 PoCStored Cross site scripting in Reposilite artifacts
- CVE-2024-361161 PoCPath traversal in Reposilite javadoc file expansion
- CVE-2024-361171 PoCPath traversal while serving Reposilite javadoc expanded files
- CVE-2024-361231 PoCCitizen has a Stored Cross-Site Scripting Vulnerability by editing MediaWiki:Tagline
- CVE-2024-361271 PoCapko Exposure of HTTP basic auth credentials in log output
- CVE-2024-361292 PoCsOpenTelemetry Collector has a Denial of Service via Zip/Decompression Bomb sent over HTTP or gRPC
- CVE-2024-363991 PoCKanboard affected by Project Takeover via IDOR in ProjectPermissionController
- CVE-2024-364001 PoCnano-id is unable to generate the correct character set
- CVE-2024-3640131 PoCsKEVRemote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
- CVE-2024-364044 PoCsGeoTools Remote Code Execution (RCE) vulnerability in evaluating XPath expressions
- CVE-2024-364121 PoCSuiteCRM unauthenticated SQL Injection
- CVE-2024-364161 PoCSuiteCRM v4 API Excessive log data DOS
- CVE-2024-364202 PoCsGHSL-2023-232: Flowise Path Injection at /api/v1/openai-assistants-file
- CVE-2024-364242 PoCsK7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of a NULL pointer…
- CVE-2024-364651 PoCSQL injection in Zabbix API
- CVE-2024-364671 PoCAuthentication privilege escalation via user groups due to missing authorization checks
- CVE-2024-364691 PoCUser enumeration via timing attack in Zabbix web interface
- CVE-2024-364961 PoCHardcoded Credentials
- CVE-2024-365261 PoCZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key.
- CVE-2024-365272 PoCspuppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal. Attackers can exploit the URL parameter using the file…
- CVE-2024-365381 PoCInsecure permissions in chaos-mesh v2.6.3 allows attackers to access sensitive data and escalate privileges by obtaining the service…
- CVE-2024-365391 PoCInsecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service…
- CVE-2024-365471 PoCidccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mudi=add
- CVE-2024-365491 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=rev&nohrefStr=close
- CVE-2024-365501 PoCidccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=add&nohrefStr=close
- CVE-2024-365721 PoCPrototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the functions…
- CVE-2024-365871 PoCInsecure permissions in DNSCrypt-proxy v2.0.0alpha9 to v2.1.5 allows non-privileged attackers to escalate privileges to root via…
- CVE-2024-365971 PoCAegon Life v1.0 was discovered to contain a SQL injection vulnerability via the client_id parameter at clientStatus.php.
- CVE-2024-365991 PoCA cross-site scripting (XSS) vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted…
- CVE-2024-366001 PoCBuffer Overflow Vulnerability in libcdio v2.1.0 allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.
- CVE-2024-366501 PoCTOTOLINK AC1200 Wireless Dual Band Gigabit Router firmware A3100R V4.1.2cu.5247_B20211129, in the cgi function `setNoticeCfg` of the file…
- CVE-2024-366561 PoCIn MintHCM 4.0.3, a registered user can execute arbitrary JavaScript code and achieve a reflected Cross-site Scripting (XSS) attack.
- CVE-2024-366671 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component…
- CVE-2024-366681 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=del
- CVE-2024-366691 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=add.
- CVE-2024-366701 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mudi=del
- CVE-2024-366731 PoCSourcecodester Pharmacy/Medical Store Point of Sale System 1.0 is vulnerable SQL Injection via login.php. This vulnerability stems from…
- CVE-2024-366741 PoCLyLme_spage v1.9.5 is vulnerable to Cross Site Scripting (XSS) via admin/link.php.
- CVE-2024-366752 PoCsLyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function.
- CVE-2024-366781 PoCIn the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script…
- CVE-2024-366831 PoCSQL injection vulnerability in the module "Products Alert" (productsalert) before 1.7.4 from Smart Modules for PrestaShop allows attackers…
- CVE-2024-366943 PoCsOpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.
- CVE-2024-367741 PoCAn arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.
- CVE-2024-367791 PoCSourcecodester Stock Management System v1.0 is vulnerable to SQL Injection via editCategories.php.
- CVE-2024-367871 PoCAn issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass authentication and access the administrative…
- CVE-2024-367881 PoCNetgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 does not properly set the HTTPOnly flag for cookies. This allows attackers to possibly…
- CVE-2024-367891 PoCAn issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to defined security…
- CVE-2024-367901 PoCNetgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.
- CVE-2024-367921 PoCAn issue in the implementation of the WPS in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to gain access to the router's…
- CVE-2024-367951 PoCInsecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories embedded within the…
- CVE-2024-368001 PoCA SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in…
- CVE-2024-368011 PoCA SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid parameter in…
- CVE-2024-368211 PoCInsecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest to root.
- CVE-2024-368231 PoCThe encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible leakage of…
- CVE-2024-368374 PoCsSQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProductList function in…
- CVE-2024-368402 PoCsSQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code and obtain…
- CVE-2024-368421 PoCAn issue in Oncord+ Android Infotainment Systems OS Android 12, Model Hardware TS17,Hardware part Number F57L_V3.2_20220301, and Build…
- CVE-2024-368432 PoCslibmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function.
- CVE-2024-368441 PoClibmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows attackers to cause a…
- CVE-2024-368451 PoCAn invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (DoS) via a crafted…
- CVE-2024-368572 PoCsJan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.
- CVE-2024-368582 PoCsAn arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code…
- CVE-2024-368772 PoCsMicro-Star International Z-series motherboards (Z590, Z490, and Z790) and B-series motherboards (B760, B560, B660, and B460) with firmware…
- CVE-2024-368861 PoCtipc: fix UAF in error path
- CVE-2024-369711 PoCKEVnet: fix __dst_negative_advice() race
- CVE-2024-369852 PoCsRemote Code Execution (RCE) through an external lookup due to “copybuckets.py“ script in the “splunk_archiver“ application in Splunk…
- CVE-2024-3699114 PoCsPath Traversal on the “/modules/messaging/“ endpoint in Splunk Enterprise on Windows