CVE-2024-37000 to CVE-2024-37999
89 CVEs with public proof-of-concept exploits.
- CVE-2024-370141 PoCLangflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and…
- CVE-2024-370327 PoCsOllama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus…
- CVE-2024-370512 PoCsGitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7,…
- CVE-2024-370544 PoCsDeserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously…
- CVE-2024-370814 PoCsThe vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local…
- CVE-2024-370842 PoCsCVE-2024-37084: Remote code execution in Spring Cloud Data Flow
- CVE-2024-370853 PoCsKEVVMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain…
- CVE-2024-371471 PoCGLPI allows Authenticated File Upload to Restricted Tickets
- CVE-2024-371521 PoCUnauthenticated Access to sensitive settings in Argo CD
- CVE-2024-371531 PoCEvmos's contract balance not updating correctly after interchain transaction
- CVE-2024-371601 PoCFormwork has a Cross-site scripting (XSS) vulnerability in Description metadata
- CVE-2024-371611 PoCMeterSphere front-end editor stores XSS vulnerability
- CVE-2024-372591 PoCWordPress WP Extended plugin <= 2.4.7 - Cross Site Scripting (XSS) vulnerability
- CVE-2024-372611 PoCWordPress WP-Lister Lite for Amazon plugin <= 2.6.16 - Reflected Cross Site Scripting (XSS) vulnerability
- CVE-2024-372731 PoCAn arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code…
- CVE-2024-372981 PoCPotential memory exhaustion attack due to sparse slice deserialization
- CVE-2024-373011 PoCdocument-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
- CVE-2024-373081 PoCWordPress Cooked Plugin - Authenticated (Contributor+) Persistent Cross-Site Scripting Vulnerability
- CVE-2024-373092 PoCsClient initialized Session-Renegotiation DoS
- CVE-2024-373834 PoCsKEVRoundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
- CVE-2024-373934 PoCsMultiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An…
- CVE-2024-373941 PoCA stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute…
- CVE-2024-373951 PoCA stored cross-site scripting (XSS) vulnerability in the Public Survey function of REDCap 13.1.9 allows authenticated users to execute…
- CVE-2024-373961 PoCA stored cross-site scripting (XSS) vulnerability in the Calendar function of REDCap 13.1.9 allows authenticated users to execute…
- CVE-2024-373971 PoCAn External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update…
- CVE-2024-374041 PoCImproper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before…
- CVE-2024-374071 PoCLibarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled. This occurs in…
- CVE-2024-375681 PoClepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call,…
- CVE-2024-375691 PoCAn issue was discovered on Mitel 6869i through 4.5.0.41 and 5.x through 5.0.0.1018 devices. A command injection vulnerability exists in…
- CVE-2024-375701 PoCOn Mitel 6869i 4.5.0.41 devices, the Manual Firmware Update (upgrade.html) page does not perform sanitization on the username and path…
- CVE-2024-376061 PoCA Stack overflow vulnerability in D-Link DCS-932L REVB_FIRMWARE_2.18.01 allows attackers to cause a Denial of Service (DoS) via a crafted…
- CVE-2024-376221 PoCXinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the num parameter at /flow/flow.php.
- CVE-2024-376231 PoCXinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the…
- CVE-2024-376292 PoCsSummerNote 0.8.18 is vulnerable to Cross Site Scripting (XSS) via the Code View Function.
- CVE-2024-376311 PoCTOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the File parameter in function UploadCustomModule.
- CVE-2024-376331 PoCTOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiGuestCfg
- CVE-2024-376341 PoCTOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiEasyCfg.
- CVE-2024-376371 PoCTOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWizardCfg.
- CVE-2024-376391 PoCTOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via eport in the function setIpPortFilterRules.
- CVE-2024-376401 PoCTOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWiFiEasyGuestCfg.
- CVE-2024-376411 PoCTRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow via the submit-url parameter at /formNewSchedule
- CVE-2024-376421 PoCTRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4_ping, ipv6_ping parameter at…
- CVE-2024-376431 PoCTRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter at…
- CVE-2024-376451 PoCTRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter at /formSysLog .
- CVE-2024-376562 PoCsAn open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the insufficient URL…
- CVE-2024-376571 PoCAn open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via thebbs/login.php…
- CVE-2024-376581 PoCAn open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the…
- CVE-2024-376611 PoCTP-LINK TL-7DR5130 v1.0.23 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack…
- CVE-2024-376621 PoCTP-LINK TL-7DR5130 v1.0.23 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or…
- CVE-2024-376631 PoCRedmi router RB03 v1.0.57 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the…
- CVE-2024-376641 PoCRedmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or…
- CVE-2024-376711 PoCCross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code…
- CVE-2024-376721 PoCCross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code…
- CVE-2024-376731 PoCCross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code…
- CVE-2024-376751 PoCCross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code…
- CVE-2024-376992 PoCsAn issue in DataLife Engine v.17.1 and before is vulnerable to SQL Injection in dboption.
- CVE-2024-377262 PoCsInsecure Permissions vulnerability in Micro-Star International Co., Ltd MSI Center v.2.0.36.0 allows a local attacker to escalate…
- CVE-2024-377282 PoCsArbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote…
- CVE-2024-377341 PoCAn issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.
- CVE-2024-377422 PoCsInsecure Access Control in Safe Exam Browser (SEB) = 3.5.0 on Windows. The vulnerability allows an attacker to share clipboard data…
- CVE-2024-377591 PoCDataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerability via the Data…
- CVE-2024-377621 PoCMachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.
- CVE-2024-377631 PoCMachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can…
- CVE-2024-377641 PoCMachForm up to version 19 is affected by an authenticated stored cross-site scripting.
- CVE-2024-377651 PoCMachform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.
- CVE-2024-377701 PoC14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This vulnerability…
- CVE-2024-377911 PoCDuxCMS3 v3.1.3 was discovered to contain a SQL injection vulnerability via the keyword parameter at /article/Content/index?class_id.
- CVE-2024-377991 PoCCodeProjects Restaurant Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the reserv_id parameter at…
- CVE-2024-378001 PoCCodeProjects Restaurant Reservation System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the…
- CVE-2024-378021 PoCCodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Patient Info…
- CVE-2024-378031 PoCMultiple stored cross-site scripting (XSS) vulnerabilities in CodeProjects Health Care hospital Management System v1.0 allows attackers to…
- CVE-2024-378291 PoCAn issue in Outline <= v0.76.1 allows attackers to execute a session hijacking attack via user interaction with a crafted magic sign-in…
- CVE-2024-378432 PoCsCraft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.
- CVE-2024-378481 PoCSQL Injection vulnerability in Online-Bookstore-Project-In-PHP v1.0 allows a local attacker to execute arbitrary code via the…
- CVE-2024-378681 PoCFile Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the…
- CVE-2024-378691 PoCFile Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the…
- CVE-2024-378701 PoCSQL injection vulnerability in processscore.php in Learning Management System Project In PHP With Source Code 1.0 allows attackers to…
- CVE-2024-378711 PoCSQL injection vulnerability in login.php in Itsourcecode Online Discussion Forum Project in PHP with Source Code 1.0 allows remote…
- CVE-2024-378721 PoCSQL injection vulnerability in process.php in Itsourcecode Billing System in PHP 1.0 allows remote attackers to execute arbitrary SQL…
- CVE-2024-378731 PoCSQL injection vulnerability in view_payslip.php in Itsourcecode Payroll Management System Project In PHP With Source Code 1.0 allows…
- CVE-2024-378801 PoCThe Kyber reference implementation before 9b8d306, when compiled by LLVM Clang through 18.x with some common optimization options, has a…
- CVE-2024-378811 PoCSiteGuard WP Plugin provides a functionality to customize the path to the login page wp-login.php and implements a measure to avoid…
- CVE-2024-378881 PoCThe Open Link CKEditor plugin has a cross-site scripting (XSS) vulnerability in open link functionality
- CVE-2024-378891 PoCMyFinances Allows Unauthorized Access to Other Customer Data
- CVE-2024-378901 PoCDenial of service when handling a request with many HTTP headers in ws
- CVE-2024-378911 PoCProxy-Authorization request header isn't stripped during cross-origin redirects in urllib3
- CVE-2024-378952 PoCsAPI Key Leak in lobe-chat
- CVE-2024-379041 PoCDenial of service from maliciously configured Git repository in Minder
- CVE-2024-379062 PoCsAdmidio has Blind SQL Injection in ecard_send.php