CVE-2024-39000 to CVE-2024-39999
76 CVEs with public proof-of-concept exploits.
- CVE-2024-390013 PoCsag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability…
- CVE-2024-390021 PoCrjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function util.clone. This vulnerability allows…
- CVE-2024-390191 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/idcProData_deal.php?mudi=del
- CVE-2024-390201 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via…
- CVE-2024-390211 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsApiData_deal.php?mudi=del
- CVE-2024-390221 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/infoSys_deal.php?mudi=deal
- CVE-2024-390231 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/info_deal.php?mudi=add&nohrefStr=close
- CVE-2024-390272 PoCsSeaCMS v12.9 has an unauthorized SQL injection vulnerability. The vulnerability is caused by the SQL injection through the cid parameter…
- CVE-2024-390311 PoCIn Silverpeas Core <= 6.3.5, in Mes Agendas, a user can create new events and add them to their calendar. Additionally, users can invite…
- CVE-2024-390361 PoCSeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php.
- CVE-2024-390631 PoCLime Survey <= 6.5.12 is vulnerable to Cross Site Request Forgery (CSRF). The YII_CSRF_TOKEN is only checked when passed in the body of…
- CVE-2024-390902 PoCsThe PHPGurukul Online Shopping Portal Project version 2.0 contains a vulnerability that allows Cross-Site Request Forgery (CSRF) to lead…
- CVE-2024-390972 PoCsThere is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path.
- CVE-2024-391192 PoCsidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/info_deal.php?mudi=rev&nohrefStr=close.
- CVE-2024-391233 PoCsIn janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper…
- CVE-2024-391331 PoCHeap Buffer Overflow vulnerability in zziplib v0.13.77 allows attackers to cause a denial of service via the __zzip_parse_root_directory()…
- CVE-2024-391341 PoCA Stack Buffer Overflow vulnerability in zziplibv 0.13.77 allows attackers to cause a denial of service via the…
- CVE-2024-391431 PoCA stored cross-site scripting (XSS) vulnerability exists in ResidenceCMS 2.10.1 that allows a low-privilege user to create malicious…
- CVE-2024-391531 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component…
- CVE-2024-391541 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component…
- CVE-2024-391551 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mudi=add.
- CVE-2024-391561 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=add.
- CVE-2024-391571 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component…
- CVE-2024-391581 PoCidccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/userSys_deal.php?mudi=infoSet.
- CVE-2024-391711 PoCDirectory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via…
- CVE-2024-392021 PoCD-Link DIR-823X firmware - 240126 was discovered to contain a remote command execution (RCE) vulnerability via the dhcpd_startip parameter…
- CVE-2024-392054 PoCsAn issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a crafted HTTP…
- CVE-2024-392101 PoCBest House Rental Management System v1.0 was discovered to contain an arbitrary file read vulnerability via the Page parameter at…
- CVE-2024-392111 PoCKaiten 57.128.8 allows remote attackers to enumerate user accounts via a crafted POST request, because a login response contains a…
- CVE-2024-392251 PoCGL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B…
- CVE-2024-392361 PoCGradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is…
- CVE-2024-392482 PoCsA cross-site scripting (XSS) vulnerability in SimpCMS v0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload…
- CVE-2024-392502 PoCsEfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in the search web…
- CVE-2024-392511 PoCAn issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows attackers to access…
- CVE-2024-393043 PoCsChurchCRM SQL Injection Vulnerability
- CVE-2024-393091 PoCZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability
- CVE-2024-393111 PoCPublify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction
- CVE-2024-393211 PoCTraefik vulnerable to bypassing IP allow-lists via HTTP/3 early data requests in QUIC 0-RTT handshakes
- CVE-2024-393321 PoCWebswing 23.2.2 allows remote attackers to modify client-side JavaScript code to achieve path traversal, likely leading to remote code…
- CVE-2024-395731 PoCApache HTTP Server: mod_rewrite proxy handler substitution
- CVE-2024-396031 PoCA stack-based buffer overflow vulnerability exists in the wireless.cgi set_wifi_basic_mesh() functionality of Wavlink AC3000…
- CVE-2024-396141 PoCAn issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject to a potential…
- CVE-2024-396461 PoCWordPress Custom 404 Pro plugin <= 3.11.1 - Reflected Cross Site Scripting (XSS) vulnerability
- CVE-2024-396781 PoCWordPress Cooked Plugin - Cross-Site Request Forgery to Get Recipe IDs
- CVE-2024-396791 PoCWordPress Cooked Plugin - Cross-Site Request Forgery to Recipe Template Reset
- CVE-2024-396801 PoCWordPress Cooked Plugin - Cross-Site Request Forgery to Default Recipe Template Save
- CVE-2024-396811 PoCWordPress Cooked Plugin - Cross-Site Request Forgery to Apply Template to All Recipes
- CVE-2024-396821 PoCWordPress Cooked Plugin - Authenticated (Contributor+) HTML Injection via Recipe Excerpt
- CVE-2024-396851 PoCfishaudio/Bert-VITS2 Command Injection in webui_preprocess.py resample function
- CVE-2024-396861 PoCfishaudio/Bert-VITS2 Command Injection in webui_preprocess.py bert_gen function
- CVE-2024-396881 PoCfishaudio/Bert-VITS2 Limited File Write in webui_preprocess.py generate_config function
- CVE-2024-396992 PoCsDirectus has a Blind SSRF On File Import
- CVE-2024-397001 PoCRemote Code Execution (RCE) vulnerability in jupyterlab extension template `update-integration-tests` GitHub Action
- CVE-2024-397012 PoCsDirectus Incorrectly handles _in` filter
- CVE-2024-397133 PoCsA Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
- CVE-2024-397192 PoCsAn issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/create. When calling the CreateModel route…
- CVE-2024-397201 PoCAn issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file containing just 4…
- CVE-2024-397211 PoCAn issue was discovered in Ollama before 0.1.34. The CreateModelHandler function uses os.Open to read a file until completion. The…
- CVE-2024-397222 PoCsAn issue was discovered in Ollama before 0.1.46. It exposes which files exist on the server on which it is deployed via path traversal in…
- CVE-2024-398441 PoCIn ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.
- CVE-2024-398531 PoCadolph_dudu ratio-swiper 0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers…
- CVE-2024-398771 PoCApache Airflow: DAG Author Code Execution possibility in airflow-scheduler
- CVE-2024-398872 PoCsApache Superset: Improper SQL authorisation, parse not checking for specific engine functions
- CVE-2024-398952 PoCsDirectus GraphQL Field Duplication Denial of Service (DoS)
- CVE-2024-398961 PoCDirectus allows SSO User Enumeration
- CVE-2024-399031 PoCLocal File Inclusion in Solara
- CVE-2024-399073 PoCsa sqlinjection in 1Panel
- CVE-2024-399081 PoCDenial of service in REXML
- CVE-2024-399111 PoC1Panel SQL injection
- CVE-2024-399142 PoCsFOG has a command injection in /fog/management/export.php?filename=
- CVE-2024-399191 PoCCapture screenshot of localhost web services (unauthenticated pages) in @jmondi/url-to-png
- CVE-2024-399292 PoCsExim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename…
- CVE-2024-399304 PoCsThe built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution.…
- CVE-2024-399434 PoCsrejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users…
- CVE-2024-399621 PoCD-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (RCE) vulnerability…
- CVE-2024-399631 PoCAX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01.46 were…