CVE-2024-38000 to CVE-2024-38999
64 CVEs with public proof-of-concept exploits.
- CVE-2024-380411 PoCWindows Kernel Information Disclosure Vulnerability
- CVE-2024-3806333 PoCsWindows TCP/IP Remote Code Execution Vulnerability
- CVE-2024-380779 PoCsWindows Remote Desktop Licensing Service Remote Code Execution Vulnerability
- CVE-2024-380801 PoCKEVWindows Hyper-V Elevation of Privilege Vulnerability
- CVE-2024-381121 PoCKEVWindows MSHTML Platform Spoofing Vulnerability
- CVE-2024-381271 PoCWindows Hyper-V Elevation of Privilege Vulnerability
- CVE-2024-381431 PoCWindows WLAN AutoConfig Service Elevation of Privilege Vulnerability
- CVE-2024-381441 PoCKernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
- CVE-2024-381932 PoCsKEVWindows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- CVE-2024-382002 PoCsMicrosoft Office Spoofing Vulnerability
- CVE-2024-382131 PoCKEVWindows Mark of the Web Security Feature Bypass Vulnerability
- CVE-2024-382171 PoCKEVWindows Mark of the Web Security Feature Bypass Vulnerability
- CVE-2024-382882 PoCsA command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated…
- CVE-2024-382892 PoCsA boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows…
- CVE-2024-383471 PoCCodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Room Information…
- CVE-2024-383481 PoCCodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Staff Info module…
- CVE-2024-383532 PoCsCodiMD - Missing Image Access Controls and Unauthorized Image Access
- CVE-2024-383541 PoCCross-site Scripting in Hackmd.io Notes lead by HTML Injection
- CVE-2024-383551 PoCUnhandled 'error' event in socket.io
- CVE-2024-383581 PoCSymlink bypasses filesystem sandbox in wasmer
- CVE-2024-383661 PoCCoacoaPods trunk RCE in email verification system rfc-822
- CVE-2024-383741 PoCImproper Restriction of XML External Entity Reference in org.cyclonedx:cyclonedx-core-java
- CVE-2024-383951 PoCIn iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is…
- CVE-2024-383961 PoCAn issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with…
- CVE-2024-383991 PoCUse After Free in Graphics
- CVE-2024-384571 PoCXenforo before 2.2.16 allows CSRF.
- CVE-2024-384581 PoCXenforo before 2.2.16 allows code injection.
- CVE-2024-384691 PoCzhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /pay.php.
- CVE-2024-384701 PoCzhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /own.php.
- CVE-2024-384723 PoCsApache HTTP Server on WIndows UNC SSRF
- CVE-2024-384734 PoCsApache HTTP Server proxy encoding problem
- CVE-2024-384742 PoCsApache HTTP Server weakness with encoded question marks in backreferences
- CVE-2024-384759 PoCsKEVApache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
- CVE-2024-384762 PoCsApache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect
- CVE-2024-384771 PoCApache HTTP Server: Crash resulting in Denial of Service in mod_proxy via a malicious request
- CVE-2024-385141 PoCNextChat Server-Side Request Forgery (SSRF)
- CVE-2024-385211 PoCPersistent Cross-Site Scripting (XSS) in hushline inbox
- CVE-2024-385221 PoCCSP bypass in Hush Line
- CVE-2024-385241 PoCGWC Home Page communicate version and revision information
- CVE-2024-385262 PoCspdoc embeds link to malicious CDN if math mode is enabled
- CVE-2024-385292 PoCsAdmidio Vulnerable to RCE via Arbitrary File Upload in Message Attachment
- CVE-2024-386531 PoCXXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.
- CVE-2024-387731 PoCWordPress formlift plugin <= 7.5.17 - Unauthenticated Blind SQL Injection vulnerability
- CVE-2024-387931 PoCWordPress Best Restaurant Menu by Pricelisto plugin <= 1.4.1 - SQL Injection vulnerability
- CVE-2024-388164 PoCsCVE-2024-38816: Path traversal vulnerability in functional web frameworks
- CVE-2024-388195 PoCsApplications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal…
- CVE-2024-388201 PoCCVE-2024-38820: Spring Framework DataBinder Case Sensitive Match Exception
- CVE-2024-388212 PoCsAuthorization Bypass of Static Resources in WebFlux Applications
- CVE-2024-388281 PoCCVE-2024-38828: DoS via Spring MVC controller method with byte[] parameter
- CVE-2024-3885616 PoCsKEVApache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
- CVE-2024-388871 PoCAn issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker…
- CVE-2024-388921 PoCAn issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component.
- CVE-2024-388941 PoCWAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi.
- CVE-2024-388951 PoCWAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.
- CVE-2024-388961 PoCWAVLINK WN551K1 found a command injection vulnerability through the start_hour parameter of /cgi-bin/nightled.cgi.
- CVE-2024-388971 PoCWAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.
- CVE-2024-389031 PoCH3C Magic R230 V100R002's udpserver opens port 9034, allowing attackers to execute arbitrary commands.
- CVE-2024-389441 PoCAn issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the…
- CVE-2024-389501 PoCHeap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to…
- CVE-2024-389881 PoCalizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/index.js. This…
- CVE-2024-389931 PoCrjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability allows attackers…
- CVE-2024-389941 PoCamoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to…
- CVE-2024-389963 PoCsag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2 were discovered to contain a prototype pollution via the _.mergeDeep function.…
- CVE-2024-389971 PoCadolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function extendDefaults. This vulnerability allows…