CVE-2024-3000 to CVE-2024-3999
386 CVEs with public proof-of-concept exploits.
- CVE-2024-30001 PoCcode-projects Online Book System index.php sql injection
- CVE-2024-30011 PoCcode-projects Online Book System Product.php sql injection
- CVE-2024-30021 PoCcode-projects Online Book System description.php sql injection
- CVE-2024-30031 PoCcode-projects Online Book System cart.php sql injection
- CVE-2024-30041 PoCcode-projects Online Book System Product.php cross site scripting
- CVE-2024-30061 PoCTenda FH1205 fromRouteStatic fromSetRouteStatic stack-based overflow
- CVE-2024-30071 PoCTenda FH1205 NatStaticSetting fromNatStaticSetting stack-based overflow
- CVE-2024-30081 PoCTenda FH1205 execCommand formexeCommand stack-based overflow
- CVE-2024-30091 PoCTenda FH1205 WriteFacMac formWriteFacMac command injection
- CVE-2024-30101 PoCTenda FH1205 setcfm formSetCfm stack-based overflow
- CVE-2024-30111 PoCTenda FH1205 QuickIndex formQuickIndex stack-based overflow
- CVE-2024-30121 PoCTenda FH1205 GetParentControlInfo stack-based overflow
- CVE-2024-30131 PoCTeledyne FLIR AX8 User Registration test_login.php improper authorization
- CVE-2024-30141 PoCSourceCodester Simple Subscription Website Actions.php sql injection
- CVE-2024-30151 PoCSourceCodester Simple Subscription Website manage_plan.php sql injection
- CVE-2024-30242 PoCsappneta tcpreplay get.c get_layer4_v6 heap-based overflow
- CVE-2024-30261 PoCWordPress Button Plugin MaxButtons < 9.7.8 - Editor+ Stored XSS
- CVE-2024-30322 PoCsThemify Builder < 7.5.8 - Open Redirect
- CVE-2024-30351 PoCAuthorization Bypass Through User-Controlled Key in GitLab
- CVE-2024-30391 PoCShanghai Brad Technology BladeX API export-user sql injection
- CVE-2024-30401 PoCNetentsec NS-ASG Application Security Gateway list_crl_conf sql injection
- CVE-2024-30411 PoCNetentsec NS-ASG Application Security Gateway listloginfo.php sql injection
- CVE-2024-30421 PoCSourceCodester Simple Subscription Website manage_user.php sql injection
- CVE-2024-30481 PoCBannerlid <= 1.1.0 - Reflected XSS
- CVE-2024-30501 PoCSite Reviews < 7.0.0 - IP Spoofing
- CVE-2024-30581 PoCENL Newsletter <= 1.0.1 - Stored XSS via CSRF
- CVE-2024-30591 PoCENL Newsletter <= 1.0.1 - Campaign Deletion via CSRF
- CVE-2024-30601 PoCENL Newsletter <= 1.0.1 - Admin+ SQL Injection
- CVE-2024-30621 PoCSave as PDF by Pdfcrowd < 3.2.2 - Admin+ Stored XSS
- CVE-2024-30751 PoCMM-email2image <= 0.2.5 - Contributor+ Stored XSS
- CVE-2024-30761 PoCMM-email2image <= 0.2.5 - Stored XSS via CSRF
- CVE-2024-30801 PoCASUS Router - Improper Authentication
- CVE-2024-30841 PoCPHPGurukul Emergency Ambulance Hiring Portal Hire an Ambulance Page cross site scripting
- CVE-2024-30851 PoCPHPGurukul Emergency Ambulance Hiring Portal Admin Login Page login.php sql injection
- CVE-2024-30861 PoCPHPGurukul Emergency Ambulance Hiring Portal Ambulance Tracking Page ambulance-tracking.php cross site scripting
- CVE-2024-30871 PoCPHPGurukul Emergency Ambulance Hiring Portal Ambulance Tracking Page ambulance-tracking.php sql injection
- CVE-2024-30881 PoCPHPGurukul Emergency Ambulance Hiring Portal Forgot Password Page forgot-password.php sql injection
- CVE-2024-30891 PoCPHPGurukul Emergency Ambulance Hiring Portal Manage Ambulance Page manage-ambulance.php cross-site request forgery
- CVE-2024-30901 PoCPHPGurukul Emergency Ambulance Hiring Portal Add Ambulance Page add-ambulance.php cross site scripting
- CVE-2024-30911 PoCPHPGurukul Emergency Ambulance Hiring Portal Search Request Page search.php cross site scripting
- CVE-2024-30921 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2024-309447 PoCsXz: malicious code in distributed source
- CVE-2024-30961 PoCPHP function password_verify can erroneously return true when argument contains NUL
- CVE-2024-30971 PoCWordPress Gallery Plugin – NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure
- CVE-2024-31051 PoCWoody code snippets – Insert Header Footer Code, AdSense Ads <= 2.5.0 -Authenticated (Contributor+) Remote Code Execution
- CVE-2024-31111 PoCH5P < 1.15.8 - Contributor+ Stored XSS
- CVE-2024-31121 PoCQuotes and Tips < 1.45 - Admin+ Arbitrary File Upload
- CVE-2024-31131 PoCFormFlow < 2.12.2 - Admin+ Stored XSS
- CVE-2024-31141 PoCUncontrolled Resource Consumption in GitLab
- CVE-2024-31151 PoCExposure of Sensitive Information to an Unauthorized Actor in GitLab
- CVE-2024-31163 PoCsRemote Code Execution Vulnerability through the validate binary path API in pgAdmin 4
- CVE-2024-31171 PoCYouDianCMS ChannelAction.class.php unrestricted upload
- CVE-2024-31181 PoCDreamer CMS Attachment permission
- CVE-2024-31211 PoCRemote Code Execution in create_conda_env function in parisneo/lollms
- CVE-2024-31241 PoCfridgecow smartalarm Backup File androidmanifest.xml backup
- CVE-2024-31251 PoCZebra ZTC GK420d Alert Setup Page settings cross site scripting
- CVE-2024-31272 PoCsImproper Access Control in GitLab
- CVE-2024-31281 PoCReplify-Messenger Backup File androidmanifest.xml backup
- CVE-2024-31291 PoCSourceCodester Image Accordion Gallery App add-image.php unrestricted upload
- CVE-2024-31311 PoCSourceCodester Computer Laboratory Management System sql injection
- CVE-2024-31361 PoCMasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template
- CVE-2024-31381 PoCfrancoisjacquet RosarioSIS Add Portal Note cross site scripting
- CVE-2024-31391 PoCSourceCodester Computer Laboratory Management System save_users improper authorization
- CVE-2024-31401 PoCSourceCodester Computer Laboratory Management System cross site scripting
- CVE-2024-31411 PoCClavister E10/E80 Misc Settings Page MiscSettings cross site scripting
- CVE-2024-31421 PoCClavister E10/E80 Setting cross-site request forgery
- CVE-2024-31431 PoCDedeCMS member_rank.php cross-site request forgery
- CVE-2024-31441 PoCDedeCMS makehtml_spec.php cross-site request forgery
- CVE-2024-31451 PoCDedeCMS makehtml_js_action.php cross-site request forgery
- CVE-2024-31461 PoCDedeCMS makehtml_rss_action.php cross-site request forgery
- CVE-2024-31471 PoCDedeCMS makehtml_map.php cross-site request forgery
- CVE-2024-31481 PoCDedeCMS makehtml_archives_action.php sql injection
- CVE-2024-31511 PoCBdtask Multi-Store Inventory Management System Stock Movement Page cross-site request forgery
- CVE-2024-31571 PoCOut of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU…
- CVE-2024-31601 PoCIntelbras HDCVI 1016 HTTP GET Request cap.js information disclosure
- CVE-2024-31631 PoCEasy Property Listings < 3.5.4 - Arbitrary Contact Deletion via CSRF
- CVE-2024-31691 PoCUse after free in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2024-31721 PoCInsufficient data validation in DevTools in Google Chrome prior to 121.0.6167.85 allowed a remote attacker who convinced a user to engage…
- CVE-2024-31771 PoCBypassing mountable secrets policy imposed by the ServiceAccount admission plugin
- CVE-2024-31832 PoCsFreeipa: user can obtain a hash of the passwords of all domain users and perform offline brute force
- CVE-2024-31881 PoCShortcodes Ultimate < 7.1.0 - Contributor+ Stored XSS
- CVE-2024-31911 PoCMailCleaner Email os command injection
- CVE-2024-31921 PoCMailCleaner Admin Interface cross site scripting
- CVE-2024-31931 PoCMailCleaner Admin Endpoints os command injection
- CVE-2024-31941 PoCMailCleaner Log File Endpoint cross site scripting
- CVE-2024-31951 PoCMailCleaner Admin Endpoints path traversal
- CVE-2024-31961 PoCMailCleaner SOAP Service dumpConfiguration os command injection
- CVE-2024-32021 PoCcodelyfe Stupid Simple CMS Login Page excessive authentication
- CVE-2024-32031 PoCc-blosc2 ndlz8x8.c ndlz8_decompress heap-based overflow
- CVE-2024-32042 PoCsc-blosc2 ndlz4x4.c ndlz4_decompress heap-based overflow
- CVE-2024-32071 PoCermig1979 Simd SimdMemoryStream.h ReadUnsigned heap-based overflow
- CVE-2024-32092 PoCsUPX bele.h get_ne64 heap-based overflow
- CVE-2024-32171 PoCWP Directory Kit <= 1.3.0 - Authenticated (Subscriber+) SQL Injection
- CVE-2024-32181 PoCShibang Communications IP Network Intercom Broadcasting System busyscreenshotpush.php path traversal
- CVE-2024-32211 PoCSourceCodester PHP Task Management System attendance-info.php sql injection
- CVE-2024-32221 PoCSourceCodester PHP Task Management System admin-password-change.php sql injection
- CVE-2024-32231 PoCSourceCodester PHP Task Management System admin-manage-user.php sql injection
- CVE-2024-32241 PoCSourceCodester PHP Task Management System task-details.php sql injection
- CVE-2024-32251 PoCSourceCodester PHP Task Management System edit-task.php sql injection
- CVE-2024-32261 PoCCampcodes Online Patient Record Management System login.php sql injection
- CVE-2024-32271 PoCPanwei eoffice OA Backend save_image.php path traversal
- CVE-2024-32312 PoCsPopup4Phone <= 1.3.2 - Unauthenticated Stored XSS
- CVE-2024-32342 PoCsPath Traversal in gaizhenbiao/chuanhuchatgpt
- CVE-2024-32361 PoCEasy Notify Lite < 1.1.33 - Contributor+ Stored XSS
- CVE-2024-32391 PoCPostX < 4.0.2 - Contributor+ Stored XSS
- CVE-2024-32411 PoCUltimate Blocks < 3.1.7 - Contributor+ Stored XSS
- CVE-2024-32471 PoCStack overflow in Xpdf 4.05 due to object loop in PDF object stream
- CVE-2024-32481 PoCStack overflow in Xpdf 4.05 due to object loop in attachments
- CVE-2024-32511 PoCSourceCodester Computer Laboratory Management System sql injection
- CVE-2024-32521 PoCSourceCodester Internship Portal Management System check_admin.php sql injection
- CVE-2024-32531 PoCSourceCodester Internship Portal Management System add_admin.php sql injection
- CVE-2024-32541 PoCSourceCodester Internship Portal Management System edit_admin.php sql injection
- CVE-2024-32551 PoCSourceCodester Internship Portal Management System edit_admin_query.php sql injection
- CVE-2024-32561 PoCSourceCodester Internship Portal Management System edit_activity.php sql injection
- CVE-2024-32571 PoCSourceCodester Internship Portal Management System edit_activity_query.php sql injection
- CVE-2024-32581 PoCSourceCodester Internship Portal Management System add_activity.php sql injection
- CVE-2024-32591 PoCSourceCodester Internship Portal Management System delete_activity.php sql injection
- CVE-2024-32611 PoCStrong Testimonials < 3.1.12 - Contributor+ Stored XSS
- CVE-2024-32651 PoCWP Advanced Search <= 1.1.6 - Admin+ SQL Injection
- CVE-2024-32701 PoCThingsBoard AdvancedFeature access control
- CVE-2024-32722 PoCsKEVD-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentials
- CVE-2024-327311 PoCsKEVD-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
- CVE-2024-32742 PoCsD-Link DNS-320L/DNS-320LW/DNS-327L HTTP GET Request info.cgi information disclosure
- CVE-2024-32761 PoCFooBox (Free and Premium) < 2.7.28 - Admin+ Stored XSS
- CVE-2024-32811 PoCA vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in the firmware…
- CVE-2024-32821 PoCWP Table Builder <= 1.5.0 - Admin+ Stored XSS
- CVE-2024-32881 PoCLogo Slider < 4.0.0 - Contributor+ Stored XSS
- CVE-2024-32931 PoCrtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 - Authenticated (Contributor+) SQL Injection via rtmedia_gallery Shortcode
- CVE-2024-33001 PoCPre-authentication Unsafe .NET object deserialization vulnerability affecting DELMIA Apriso Release 2019 through Release 2024
- CVE-2024-33031 PoCImproper Neutralization of Input Used for LLM Prompting in GitLab
- CVE-2024-33111 PoCDreamer CMS ThemesController.java ZipUtils.unZipFiles path traversal
- CVE-2024-33151 PoCSourceCodester Computer Laboratory Management System user.php sql injection
- CVE-2024-33161 PoCSourceCodester Computer Laboratory Management System view_category.php sql injection
- CVE-2024-33211 PoCSourceCodester eLearning System Maintenance Module cross site scripting
- CVE-2024-33461 PoCByzoro Smart S80 webmailattach.php os command injection
- CVE-2024-33471 PoCSourceCodester Airline Ticket Reservation System activate_jet_details_form_handler.php sql injection
- CVE-2024-33481 PoCSourceCodester Aplaya Beach Resort Online Reservation System index.php sql injection
- CVE-2024-33491 PoCSourceCodester Aplaya Beach Resort Online Reservation System login.php sql injection
- CVE-2024-33501 PoCSourceCodester Aplaya Beach Resort Online Reservation System index.php sql injection
- CVE-2024-33511 PoCSourceCodester Aplaya Beach Resort Online Reservation System index.php sql injection
- CVE-2024-33521 PoCSourceCodester Aplaya Beach Resort Online Reservation System index.php sql injection
- CVE-2024-33531 PoCSourceCodester Aplaya Beach Resort Online Reservation System index.php sql injection
- CVE-2024-33541 PoCSourceCodester Aplaya Beach Resort Online Reservation System index.php sql injection
- CVE-2024-33551 PoCSourceCodester Aplaya Beach Resort Online Reservation System sql injection
- CVE-2024-33561 PoCSourceCodester Aplaya Beach Resort Online Reservation System sql injection
- CVE-2024-33571 PoCSourceCodester Aplaya Beach Resort Online Reservation System index.php cross site scripting
- CVE-2024-33581 PoCSourceCodester Aplaya Beach Resort Online Reservation System index.php cross site scripting
- CVE-2024-33591 PoCSourceCodester Online Library System login.php sql injection
- CVE-2024-33601 PoCSourceCodester Online Library System index.php sql injection
- CVE-2024-33611 PoCSourceCodester Online Library System deweydecimal.php sql injection
- CVE-2024-33621 PoCSourceCodester Online Library System controller.php sql injection
- CVE-2024-33631 PoCSourceCodester Online Library System index.php sql injection
- CVE-2024-33641 PoCSourceCodester Online Library System index.php cross site scripting
- CVE-2024-33651 PoCSourceCodester Online Library System controller.php cross site scripting
- CVE-2024-33661 PoCXuxueli xxl-job Template JdkSerializeTool.java deserialize injection
- CVE-2024-33681 PoCAll in One SEO < 4.6.1.1 - Contributor+ Stored XSS
- CVE-2024-33691 PoCcode-projects Car Rental add-vehicle.php unrestricted upload
- CVE-2024-33761 PoCSourceCodester Computer Laboratory Management System config.php redirect
- CVE-2024-33771 PoCSourceCodester Computer Laboratory Management System cross site scripting
- CVE-2024-33782 PoCsiboss Secure Web Gateway Login Portal login cross site scripting
- CVE-2024-340045 PoCsKEVPAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
- CVE-2024-34051 PoCWP Prayer <= 2.0.9 - Settings Update via CSRF
- CVE-2024-34061 PoCWP Prayer <= 2.0.9 - Email Settings Update via CSRF
- CVE-2024-34071 PoCWP Prayer <= 2.0.9 - Arbitrary Prayer Deletion via CSRF
- CVE-2024-34082 PoCsAuthentication Bypass and RCE in man-group/dtale
- CVE-2024-34101 PoCDN Footer Contacts < 1.6.3 - Admin+ Stored XSS
- CVE-2024-34131 PoCSourceCodester Human Resource Information System login_process.php sql injection
- CVE-2024-34141 PoCSourceCodester Human Resource Information System addcorporate_process.php cross site scripting
- CVE-2024-34151 PoCSourceCodester Human Resource Information System addbranches_process.php cross site scripting
- CVE-2024-34161 PoCSourceCodester Online Courseware editt.php sql injection
- CVE-2024-34171 PoCSourceCodester Online Courseware saveeditt.php sql injection
- CVE-2024-34181 PoCSourceCodester Online Courseware deactivateteach.php sql injection
- CVE-2024-34191 PoCSourceCodester Online Courseware edit.php sql injection
- CVE-2024-34201 PoCSourceCodester Online Courseware saveedit.php sql injection
- CVE-2024-34211 PoCSourceCodester Online Courseware deactivatestud.php sql injection
- CVE-2024-34221 PoCSourceCodester Online Courseware activatestud.php sql injection
- CVE-2024-34231 PoCSourceCodester Online Courseware activateteach.php sql injection
- CVE-2024-34241 PoCSourceCodester Online Courseware listscore.php sql injection
- CVE-2024-34251 PoCSourceCodester Online Courseware activateall.php sql injection
- CVE-2024-34261 PoCSourceCodester Online Courseware editt.php cross site scripting
- CVE-2024-34271 PoCSourceCodester Online Courseware addq.php cross site scripting
- CVE-2024-34281 PoCSourceCodester Online Courseware edit.php cross site scripting
- CVE-2024-34301 PoCQKSMS Backup File androidmanifest.xml backup
- CVE-2024-34311 PoCEyouCMS Backend deserialization
- CVE-2024-34321 PoCPuneethReddyHC Event Management register.php sql injection
- CVE-2024-34341 PoCCP Plus Wi-Fi Camera User Management improper authorization
- CVE-2024-34351 PoCPath Traversal in parisneo/lollms-webui
- CVE-2024-34361 PoCSourceCodester Prison Management System Avatar edit-photo.php unrestricted upload
- CVE-2024-34371 PoCSourceCodester Prison Management System Avatar add-admin.php unrestricted upload
- CVE-2024-34381 PoCSourceCodester Prison Management System login.php sql injection
- CVE-2024-34391 PoCSourceCodester Prison Management System login.php sql injection
- CVE-2024-34401 PoCSourceCodester Prison Management System edit_profile.php sql injection
- CVE-2024-34411 PoCSourceCodester Prison Management System edit-profile.php sql injection
- CVE-2024-34421 PoCSourceCodester Prison Management System delete_leave.php sql injection
- CVE-2024-34431 PoCSourceCodester Prison Management System apply_leave.php cross site scripting
- CVE-2024-34441 PoCWangshen SecGate 3600 ?g=net_pro_keyword_import_save unrestricted upload
- CVE-2024-34451 PoCSourceCodester Laundry Management System laporan_filter sql injection
- CVE-2024-34481 PoCImproper Access Control Leads to Server-Side Request Forgery in Mautic
- CVE-2024-34551 PoCNetentsec NS-ASG Application Security Gateway add_postlogin.php sql injection
- CVE-2024-34561 PoCNetentsec NS-ASG Application Security Gateway config_Anticrack.php sql injection
- CVE-2024-34571 PoCNetentsec NS-ASG Application Security Gateway config_ISCGroupNoCache.php sql injection
- CVE-2024-34581 PoCNetentsec NS-ASG Application Security Gateway add_ikev2.php sql injection
- CVE-2024-34631 PoCSourceCodester Laundry Management System edit cross site scripting
- CVE-2024-34641 PoCSourceCodester Laundry Management System Pelanggan.php laporan_filter sql injection
- CVE-2024-34651 PoCSourceCodester Laundry Management System Transaki.php laporan_filter sql injection
- CVE-2024-34691 PoCGP Premium <= 2.4.0 - Reflected Cross-Site Scripting
- CVE-2024-34711 PoCButton Generator < 3.0 - Button Deletion via CSRF
- CVE-2024-34721 PoCModal Window < 5.3.10 - Modal Deletion via CSRF
- CVE-2024-34741 PoCWow Skype Buttons < 4.0.4 - Button Deletion via CSRF
- CVE-2024-34751 PoCSticky Buttons < 3.2.4 - Button Deletion via CSRF
- CVE-2024-34761 PoCSide Menu Lite < 4.2.1 - Menu Deletion via CSRF
- CVE-2024-34771 PoCPopup Box < 2.2.7 - Popup Deletion via CSRF
- CVE-2024-34781 PoCHerd Effects < 5.2.7 - Effect Deletion via CSRF
- CVE-2024-34811 PoCCounter Box < 1.2.4 - Counter Deletion via CSRF
- CVE-2024-34959 PoCsCountry State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection
- CVE-2024-35161 PoCHeap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption…
- CVE-2024-35211 PoCByzoro Smart S80 Management Platform userattestation.php unrestricted upload
- CVE-2024-35221 PoCCampcodes Online Event Management System process.php sql injection
- CVE-2024-35231 PoCCampcodes Online Event Management System index.php sql injection
- CVE-2024-35241 PoCCampcodes Online Event Management System process.php cross site scripting
- CVE-2024-35251 PoCCampcodes Online Event Management System index.php cross site scripting
- CVE-2024-35261 PoCCampcodes Online Event Management System index.php cross site scripting
- CVE-2024-35281 PoCCampcodes Complete Online Student Management System units_view.php cross site scripting
- CVE-2024-35291 PoCCampcodes Complete Online Student Management System students_view.php cross site scripting
- CVE-2024-35301 PoCCampcodes Complete Online Student Management System Marks_view.php cross site scripting
- CVE-2024-35311 PoCCampcodes Complete Online Student Management System courses_view.php cross site scripting
- CVE-2024-35321 PoCCampcodes Complete Online Student Management System attendance_view.php cross site scripting
- CVE-2024-35331 PoCCampcodes Complete Online Student Management System academic_year_view.php cross site scripting
- CVE-2024-35341 PoCCampcodes Church Management System login.php sql injection
- CVE-2024-35351 PoCCampcodes Church Management System index.php sql injection
- CVE-2024-35361 PoCCampcodes Church Management System delete_log.php sql injection
- CVE-2024-35371 PoCCampcodes Church Management System admin_user.php sql injection
- CVE-2024-35381 PoCCampcodes Church Management System addTithes.php sql injection
- CVE-2024-35391 PoCCampcodes Church Management System addgiving.php sql injection
- CVE-2024-35401 PoCCampcodes Church Management System add_sundaysch.php sql injection
- CVE-2024-35411 PoCCampcodes Church Management System admin_user.php cross site scripting
- CVE-2024-35421 PoCCampcodes Church Management System add_visitor.php cross site scripting
- CVE-2024-35481 PoCShortcodes Ultimate < 7.1.2 - Contributor+ Stored XSS
- CVE-2024-35523 PoCsWeb Directory Free < 1.7.0 - Unauthenticated SQL Injection
- CVE-2024-35531 PoCTutor LMS <= 2.6.2 - Missing Authorization to Unauthenticated Limited Options Update
- CVE-2024-35671 PoCQemu-kvm: net: assertion failure in update_sctp_checksum()
- CVE-2024-35682 PoCsArbitrary Code Execution via Deserialization in huggingface/transformers
- CVE-2024-35801 PoCPopup4Phone <= 1.3.2 - Editor+ Stored XSS
- CVE-2024-35821 PoCUngallery <= 2.2.4 - Stored XSS via CSRF
- CVE-2024-35901 PoCLetterPress <= 1.2.2 - Subscriber Deletion via CSRF
- CVE-2024-35911 PoCWordPress Geo Controller < 8.6.5 - PHP Object Injection
- CVE-2024-35941 PoCIDonate <= 1.9.0 - Admin+ Stored XSS
- CVE-2024-36052 PoCsWP Hotel Booking <= 2.1.0 - Unauthenticated SQL Injection
- CVE-2024-36121 PoCSourceCodester Warehouse Management System barang.php cross site scripting
- CVE-2024-36131 PoCSourceCodester Warehouse Management System supplier.php cross site scripting
- CVE-2024-36141 PoCSourceCodester Warehouse Management System customer.php cross site scripting
- CVE-2024-36161 PoCSourceCodester Warehouse Management System pengguna.php cross site scripting
- CVE-2024-36171 PoCSourceCodester Kortex Lite Advocate Office Management System deactivate_case.php sql injection
- CVE-2024-36181 PoCSourceCodester Kortex Lite Advocate Office Management System activate_case.php sql injection
- CVE-2024-36191 PoCSourceCodester Kortex Lite Advocate Office Management System addcase_stage.php sql injection
- CVE-2024-36201 PoCSourceCodester Kortex Lite Advocate Office Management System adds.php sql injection
- CVE-2024-36211 PoCSourceCodester Kortex Lite Advocate Office Management System register_case.php sql injection
- CVE-2024-36281 PoCEasyEvent <= 1.0.0 - Admin+ Stored XSS
- CVE-2024-36291 PoCHL Twitter <= 2014.1.18 - Settings Update via CSRF
- CVE-2024-36301 PoCHL Twitter <= 2014.1.18 - Admin+ Stored XSS via Widget
- CVE-2024-36311 PoCHL Twitter <= 2014.1.18 - Unlink Twitter Account via CSRF
- CVE-2024-36321 PoCSmart Image Gallery < 1.0.19 - Update/Delete Google API Key via CSRF
- CVE-2024-36331 PoCWebP & SVG Support <= 1.4.0 - Author+ Stored XSS via SVG
- CVE-2024-36341 PoCmonth name translation benaceur < 2.3.8 - Admin+ Stored XSS
- CVE-2024-36351 PoCThe Post Grid < 7.5.0 - Editor+ Stored XSS via Grid Creation
- CVE-2024-36361 PoCPinpoint Booking System < 2.9.9.4.8 - Admin+ Stored XSS
- CVE-2024-36371 PoCResponsive Contact Form Builder & Lead Generation Plugin <= 1.8.9 - Admin+ Stored XSS
- CVE-2024-36401 PoCRockwell Automation FactoryTalk® Remote Access™ has Unquoted Executables
- CVE-2024-36411 PoCNewsletter Popup <= 1.2 - Unauthenticated Stored XSS
- CVE-2024-36421 PoCNewsletter Popup <= 1.2 - Subscriber Deletion via CSRF
- CVE-2024-36431 PoCNewsletter Popup <= 1.2 - List Deletion via CSRF
- CVE-2024-36441 PoCNewsletter Popup <= 1.2 - Admin+ Stored XSS
- CVE-2024-36562 PoCsKeycloak: unguarded admin rest api endpoints allows low privilege users to use administrative functionalities
- CVE-2024-36603 PoCsArbitrary code injection vulnerability in Keras framework < 2.13
- CVE-2024-36612 PoCsDHCP routing options can manipulate interface-based VPN traffic
- CVE-2024-36691 PoCWeb Directory Free < 1.7.2 - Reflected XSS
- CVE-2024-36734 PoCsWeb Directory Free < 1.7.3 - Unauthenticated LFI
- CVE-2024-36851 PoCDedeCMS stepselect_main.php sql injection
- CVE-2024-36861 PoCDedeCMS update_guide.php path traversal
- CVE-2024-36871 PoCbihell Dice Comment cross site scripting
- CVE-2024-36881 PoCXiamen Four-Faith RMP Router Management Platform sql injection
- CVE-2024-36891 PoCZhejiang Land Zongheng Network Technology O2OA information disclosure
- CVE-2024-36902 PoCsPHPGurukul Small CRM Change Password sql injection
- CVE-2024-36911 PoCPHPGurukul Small CRM Registration Page sql injection
- CVE-2024-36921 PoCGutenverse < 1.9.1 - Contributor+ Stored XSS
- CVE-2024-36951 PoCSourceCodester Computer Laboratory Management System Users.php cross site scripting
- CVE-2024-36961 PoCCampcodes House Rental Management System view_payment.php sql injection
- CVE-2024-36971 PoCCampcodes House Rental Management System manage_tenant.php sql injection
- CVE-2024-36981 PoCCampcodes House Rental Management System manage_payment.php sql injection
- CVE-2024-37031 PoCCarousel Slider < 2.2.10 - Editor+ Stored XSS
- CVE-2024-37101 PoCImage Photo Gallery Final Tiles Grid < 3.6.0 - Contributor+ Stored XSS
- CVE-2024-37191 PoCCampcodes House Rental Management System ajax.php sql injection
- CVE-2024-37201 PoCTianwell Fire Intelligent Command Platform API Interface page sql injection
- CVE-2024-37211 PoCTBK DVR-4104/DVR-4216 os command injection
- CVE-2024-37351 PoCSmart Office Main.aspx weak password
- CVE-2024-37361 PoCcym1102 nginxWebUI upload unrestricted upload
- CVE-2024-37371 PoCcym1102 nginxWebUI addOver findCountByQuery path traversal
- CVE-2024-37381 PoCcym1102 nginxWebUI saveCmd handlePath certificate validation
- CVE-2024-37391 PoCcym1102 nginxWebUI upload os command injection
- CVE-2024-37401 PoCcym1102 nginxWebUI reload exec deserialization
- CVE-2024-37421 PoCElectrolink FM/DAB/TV Transmitter Cleartext Storage of Sensitive Information
- CVE-2024-37451 PoCMSI Afterburner v4.6.6.16381 Beta 3 - ACL Bypass
- CVE-2024-37481 PoCSP Project & Document Manager <= 4.71 - Data Update via IDOR
- CVE-2024-37491 PoCSP Project & Document Manager <= 4.71 - Subscriber+ File Download via IDOR
- CVE-2024-37511 PoCSeriously Simple Podcasting < 3.3.0 - Admin+ Stored XSS
- CVE-2024-37521 PoCCrelly Slider <= 1.4.5 - Admin+ Stored XSS
- CVE-2024-37532 PoCsHostel < 1.1.5.3 - Reflected XSS
- CVE-2024-37541 PoCAlemha Watermarker <= 1.3.1 - Author+ Stored XSS
- CVE-2024-37551 PoCMF Gig Calendar <= 1.2.1 - Editor+ Stored XSS
- CVE-2024-37561 PoCMF Gig Calendar <= 1.2.1 - Arbitrary Event Deletion via CSRF
- CVE-2024-37621 PoCEmlog Pro Whisper Page twitter.php cross site scripting
- CVE-2024-37631 PoCEmlog Pro Post Tag tag.php cross site scripting
- CVE-2024-37641 PoCTuya SDK MQTT Packet denial of service
- CVE-2024-37651 PoCXiongmai AHB7804R-MH-V2 Sofia Service access control
- CVE-2024-37661 PoCslowlyo OwlAdmin Image File Upload upload_image cross site scripting
- CVE-2024-37671 PoCPHPGurukul News Portal edit-post.php sql injection
- CVE-2024-37682 PoCsPHPGurukul/itsourcecode News Portal search.php sql injection
- CVE-2024-37691 PoCPHPGurukul Student Record System login.php sql injection
- CVE-2024-37701 PoCPHPGurukul Student Record System sql injection
- CVE-2024-37711 PoCPHPGurukul Student Record System edit-subject.php sql injection
- CVE-2024-37731 PoCLiveJournal Shortcode <= 1.1.1 - Contributor+ Stored XSS via Shortcode
- CVE-2024-37971 PoCSourceCodester QR Code Bookmark System sql injection
- CVE-2024-38031 PoCVesystem Cloud Desktop fileupload.php unrestricted upload
- CVE-2024-38041 PoCVesystem Cloud Desktop fileupload2.php unrestricted upload
- CVE-2024-38061 PoCPorto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts
- CVE-2024-38222 PoCsBase64 Encoder/Decoder <= 0.9.2 - Reflected XSS
- CVE-2024-38231 PoCBase64 Encoder/Decoder <= 0.9.2 - Stored XSS via CSRF
- CVE-2024-38241 PoCBase64 Encoder/Decoder <= 0.9.2 - Settings Reset via CSRF
- CVE-2024-38291 PoCArbitrary File Read and Write during Snapshot Recovery in qdrant/qdrant
- CVE-2024-38401 PoCInsufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation…
- CVE-2024-38441 PoCInappropriate implementation in Extensions in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a…
- CVE-2024-38461 PoCInappropriate implementation in Prompts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage…
- CVE-2024-38481 PoCPath Traversal Bypass in mlflow/mlflow
- CVE-2024-38501 PoCUniview NVR301-04S2-P4 Cross-site Scripting
- CVE-2024-38671 PoCTainacan Interface <= 2.7.2 - Reflected Cross-Site Scripting
- CVE-2024-38731 PoCSMI SMI-EX-5414W Web Interface cross-site request forgery
- CVE-2024-38741 PoCTenda W20E SetRemoteWebManage formSetRemoteWebManage stack-based overflow
- CVE-2024-38751 PoCTenda F1202 Natlimit fromNatlimit stack-based overflow
- CVE-2024-38761 PoCTenda F1202 VirtualSer fromVirtualSer stack-based overflow
- CVE-2024-38771 PoCTenda F1202 fromqossetting stack-based overflow
- CVE-2024-38781 PoCTenda F1202 webExcptypemanFilter fromwebExcptypemanFilter stack-based overflow
- CVE-2024-38791 PoCTenda W30E setcfm formSetCfm stack-based overflow
- CVE-2024-38801 PoCTenda W30E WriteFacMac formWriteFacMac os command injection
- CVE-2024-38811 PoCTenda W30E frmL7ProtForm frmL7PlotForm stack-based overflow
- CVE-2024-38821 PoCTenda W30E fromRouteStatic stack-based overflow
- CVE-2024-38991 PoCEnvira Gallery < 1.8.15 - Author+ Stored XSS
- CVE-2024-39011 PoCGenesis Blocks <= 3.1.3 - Contributor+ Stored XSS
- CVE-2024-39031 PoCAdd Custom CSS and JS <= 1.20 - Stored XSS via CSRF
- CVE-2024-39051 PoCTenda AC500 execCommand R7WebsSecurityHandler stack-based overflow
- CVE-2024-39061 PoCTenda AC500 QuickIndex formQuickIndex stack-based overflow
- CVE-2024-39071 PoCTenda AC500 setcfm formSetCfm stack-based overflow
- CVE-2024-39081 PoCTenda AC500 WriteFacMac formWriteFacMac command injection
- CVE-2024-39091 PoCTenda AC500 execCommand formexeCommand stack-based overflow
- CVE-2024-39101 PoCTenda AC500 DhcpListClient fromDhcpListClient stack-based overflow
- CVE-2024-39121 PoCASUS Router - Upload arbitrary firmware
- CVE-2024-39171 PoCPet Manager <= 1.4 - Reflected XSS
- CVE-2024-39181 PoCPet Manager <= 1.4 - Contributor+ Stored XSS
- CVE-2024-39191 PoCOpenPGP Form Encryption for WordPress < 1.5.1 - Contributor+ Stored XSS
- CVE-2024-39201 PoCFlattr <= 1.2.2 - Admin+ Stored XSS
- CVE-2024-39211 PoCGianism <= 5.1.0 - Admin+ Stored XSS
- CVE-2024-39222 PoCsDokan Pro <= 3.10.3 - Unauthenticated SQL Injection
- CVE-2024-39281 PoCDromara open-capacity-platform auth-server heapdump information disclosure
- CVE-2024-39371 PoCPlaylist for Youtube <= 1.32 - Editor+ Stored XSS
- CVE-2024-39391 PoCDitty < 3.1.36 - Author+ Stored XSS
- CVE-2024-39401 PoCreCAPTCHA Jetpack <= 0.2.2 - Settings Update via CSRF
- CVE-2024-39411 PoCreCAPTCHA Jetpack <= 0.2.2 - Stored XSS via CSRF
- CVE-2024-39481 PoCSourceCodester Home Clean Service System Photo student.add.php unrestricted upload
- CVE-2024-39581 PoCImproper Control of Generation of Code ('Code Injection') in GitLab
- CVE-2024-39591 PoCImproper Authorization in GitLab
- CVE-2024-39631 PoCRafflePress Lite < 1.12.14 - Editor+ Stored XSS
- CVE-2024-39641 PoCProduct Enquiry for WooCommerce < 3.1.8 - Admin+ Stored XSS
- CVE-2024-39651 PoCPray For Me <= 1.0.4 - Settings Update via CSRF
- CVE-2024-39661 PoCPray For Me <= 1.0.4 - Unauthenticated Stored XSS
- CVE-2024-39711 PoCSimilarity <= 3.0 - Plugin Reset via CSRF
- CVE-2024-39721 PoCSimilarity <= 3.0 - Stored XSS via CSRF
- CVE-2024-39731 PoCHouse Manager <= 1.0.8.4 - Reflected XSS
- CVE-2024-39761 PoCMissing Authorization in GitLab
- CVE-2024-39771 PoCWordPress Jitsi Shortcode <= 0.1 - Admin+ Stored XSS
- CVE-2024-39781 PoCWordPress Jitsi Shortcode <= 0.1 - Contributor+ Stored XSS via Shortcode
- CVE-2024-39791 PoCCOVESA vsomeip race condition
- CVE-2024-39831 PoCWooCommerce Customers Manager < 30.1 - Bulk Action via CSRF
- CVE-2024-39861 PoCSportsPress < 2.7.22 - Admin+ Stored XSS
- CVE-2024-39921 PoCAmen <= 3.3.1 - Admin+ Stored XSS
- CVE-2024-39931 PoCAZAN Plugin <= 0.6 - Stored XSS via CSRF
- CVE-2024-39961 PoCPost Grid, Post Carousel, & List Category Posts < 2.4.28 - Editor+ Stored XSS
- CVE-2024-39991 PoCEazyDocs < 2.5.0 - Admin+ Stored XSS