CVE-2024-41000 to CVE-2024-41999
107 CVEs with public proof-of-concept exploits.
- CVE-2024-411072 PoCsApache CloudStack: SAML Signature Exclusion
- CVE-2024-411081 PoCFOG Sensitive Information Disclosure
- CVE-2024-411091 PoCPimcore vulnerable to disclosure of system and database information behind /admin firewall
- CVE-2024-411101 PoCMoby authz zero length regression
- CVE-2024-411111 PoCBishopFox Sliver Authenticated Remote Code Execution
- CVE-2024-411121 PoCRemote code execution in streamlit geospatial in pages/1_đź“·_Timelapse.py Any Earth Engine ImageCollection option palette
- CVE-2024-411131 PoCRemote code execution in streamlit geospatial in pages/1_đź“·_Timelapse.py Any Earth Engine ImageCollection option vis_params
- CVE-2024-411141 PoCRemote code execution in streamlit geospatial in pages/1_đź“·_Timelapse.py MODIS Gap filled Land Surface Temperature Daily option
- CVE-2024-411151 PoCRemote code execution in streamlit geospatial in pages/1_đź“·_Timelapse.py MODIS Ocean Color SMI option palette
- CVE-2024-411161 PoCRemote code execution in streamlit geospatial in pages/1_đź“·_Timelapse.py MODIS Ocean Color SMI option vis_params
- CVE-2024-411171 PoCRemote code execution in streamlit geospatial in pages/10_🌍_Earth_Engine_Datasets.py
- CVE-2024-411181 PoCstreamlit-geospatial blind SSRF in pages/7_📦_Web_Map_Service.py
- CVE-2024-411191 PoCstreamlit-geospatial remote code execution in pages/8_🏜️_Raster_Data_Visualization.py
- CVE-2024-411201 PoCstreamlit-geospatial blind SSRF in pages/9_🔲_Vector_Data_Visualization.py
- CVE-2024-411271 PoCMonkeytype is vulnerable to Poisoned Pipeline Execution through Code Injection in its `ci-failure-comment.yml` GitHub Workflow, enabling…
- CVE-2024-412061 PoCA stack-based buffer over-read in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Information Disclosure via a…
- CVE-2024-412092 PoCsA heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service (DoS) and Code…
- CVE-2024-412171 PoCA heap-based buffer overflow in tsMuxer version nightly-2024-05-10-02-00-45 allows attackers to cause Denial of Service (DoS) via a…
- CVE-2024-412261 PoCA CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted…
- CVE-2024-412761 PoCA vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism. The application…
- CVE-2024-412901 PoCFlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to store authentication data via the cookie's component.
- CVE-2024-413111 PoCIn Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can…
- CVE-2024-413191 PoCTOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd…
- CVE-2024-413321 PoCIncorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 allows authenticated…
- CVE-2024-413331 PoCA reflected cross-site scripting (XSS) vulnerability in Phpgurukul Tourism Management System v2.0 allows attackers to execute arbitrary…
- CVE-2024-413441 PoCA Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator password and escalate…
- CVE-2024-413451 PoCopenflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/trip.php
- CVE-2024-413461 PoCopenflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/submit.php
- CVE-2024-413471 PoCopenflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/settings.php
- CVE-2024-413481 PoCopenflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/alsearch.php
- CVE-2024-413491 PoCunmark 1.9.2 is vulnerable to Cross Site Scripting (XSS) via application/views/marks/add_by_url.php.
- CVE-2024-413531 PoCphpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php
- CVE-2024-413541 PoCphpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php
- CVE-2024-413551 PoCphpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php.
- CVE-2024-413561 PoCphpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\firewall-zones\zones-edit-network.php.
- CVE-2024-413572 PoCsphpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.
- CVE-2024-413582 PoCsphpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.
- CVE-2024-413611 PoCRPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\manageFilesFolders.php
- CVE-2024-413641 PoCRPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\trackEdit.php
- CVE-2024-413661 PoCRPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\userScripts.php
- CVE-2024-413671 PoCRPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via…
- CVE-2024-413681 PoCRPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWlanIpMail.php
- CVE-2024-413691 PoCRPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWifi.php
- CVE-2024-413701 PoCOrganizr v1.90 was discovered to contain a SQL injection vulnerability via chat/setlike.php.
- CVE-2024-413711 PoCOrganizr v1.90 is vulnerable to Cross Site Scripting (XSS) via api.php.
- CVE-2024-413721 PoCOrganizr v1.90 was discovered to contain a SQL injection vulnerability via chat/settyping.php.
- CVE-2024-413731 PoCICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php.
- CVE-2024-413741 PoCICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php
- CVE-2024-413751 PoCICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php
- CVE-2024-413761 PoCdzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.
- CVE-2024-413801 PoCmicroweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_tagging_tagged.php.
- CVE-2024-413811 PoCmicroweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\admin.php.
- CVE-2024-414371 PoCA heap buffer overflow in the function cp_unfilter() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service…
- CVE-2024-414381 PoCA heap buffer overflow in the function cp_stored() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service…
- CVE-2024-414391 PoCA heap buffer overflow in the function cp_block() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service…
- CVE-2024-414401 PoCA heap buffer overflow in the function png_quantize() of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) via a crafted…
- CVE-2024-414431 PoCA stack overflow in the function cp_dynamic() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS)…
- CVE-2024-414471 PoCA stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2024-414532 PoCsA cross-site scripting (XSS) vulnerability in Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitrary web scripts or…
- CVE-2024-414542 PoCsAn arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-RC7 allows…
- CVE-2024-414601 PoCTenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at…
- CVE-2024-414611 PoCTenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at…
- CVE-2024-414621 PoCTenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at…
- CVE-2024-414631 PoCTenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at…
- CVE-2024-414641 PoCTenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in…
- CVE-2024-414651 PoCTenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter at…
- CVE-2024-414661 PoCTenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at…
- CVE-2024-414731 PoCTenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac
- CVE-2024-414751 PoCGnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.
- CVE-2024-414921 PoCA stack overflow in Tenda AX1806 v1.0.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
- CVE-2024-415021 PoCJetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) via the form field "Observaces" (observances) in the…
- CVE-2024-415031 PoCJetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the field "Ttulo" (title) inside the filter Save…
- CVE-2024-415041 PoCJetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS). In the "Oportunidades" (opportunities) section of…
- CVE-2024-415051 PoCJetimob Plataforma Imobiliaria 20240627-0 is vulnerable to Cross Site Scripting (XSS) in the "Pessoas" (persons) section via the field…
- CVE-2024-415708 PoCsAn Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send arbitrary network…
- CVE-2024-415971 PoCCross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to execute arbitrary code via a crafted HTML…
- CVE-2024-416221 PoCD-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address…
- CVE-2024-416231 PoCAn issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code via a crafted…
- CVE-2024-416282 PoCsDirectory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before…
- CVE-2024-416301 PoCStack-based buffer overflow vulnerability in Tenda AC18 V15.03.3.10_EN allows a remote attacker to execute arbitrary code via the ssid…
- CVE-2024-416311 PoCBuffer Overflow vulnerability in host-host NEUQ_board v.1.0 allows a remote attacker to cause a denial of service via the password.h…
- CVE-2024-416401 PoCCross Site Scripting (XSS) vulnerability in AML Surety Eco up to 3.5 allows an attacker to run arbitrary code via crafted GET request…
- CVE-2024-416511 PoCAn issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE:…
- CVE-2024-416591 PoCGHSL-2024-034: memos CORS Misconfiguration in server.go
- CVE-2024-416621 PoCVNote vulnerable to Markdown XSS, which leads to RCE
- CVE-2024-416651 PoCAmpache Stored Cross-site Scripting Vulnerability
- CVE-2024-416661 PoCThe Argo CD web terminal session does not handle the revocation of user permissions properly.
- CVE-2024-416671 PoCOpenAM FreeMarker template injection
- CVE-2024-416711 PoCtwisted.web has disordered HTTP pipeline response
- CVE-2024-416722 PoCsDuckDB: sniff_csv provides filesystem access even when enable_external_access is disabled
- CVE-2024-416772 PoCsCross-site Scripting (XSS) vulnerability due to improper HTML escaping in qwik
- CVE-2024-417137 PoCsKEVA vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an…
- CVE-2024-418081 PoCOpenObserve stored XSS vulnerability may lead to complete account takeover
- CVE-2024-418102 PoCsHTML injection in HTTP redirect body
- CVE-2024-418121 PoCtxtdot SSRF vulnerability in /get
- CVE-2024-418131 PoCtxtdot SSRF vulnerability in /proxy
- CVE-2024-418152 PoCsStarship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commands
- CVE-2024-418161 PoCWordPress Cooked Plugin Persistent Cross-Site Scripting via Shortcode
- CVE-2024-418173 PoCsArbitrary Code Execution in `AppImage` version `ImageMagick`
- CVE-2024-418181 PoCReDOS at currency parsing fast-xml-parser
- CVE-2024-418191 PoCNote Mark has a stored XSS in the note link href attribute
- CVE-2024-419451 PoCThe fuels-ts typescript SDK has no awareness of to-be-spent transactions
- CVE-2024-419471 PoCXWiki Platform XSS through conflict resolution
- CVE-2024-419541 PoCFOG Weak file permissions
- CVE-2024-419552 PoCsMobile Security Framework (MobSF) has an Open Redirect in Login Redirect
- CVE-2024-419581 PoCTwo-Factor Authentication (2FA) Bypass in mailcow: dockerized
- CVE-2024-419921 PoCWi-Fi Alliance wfa_dut (in Wi-Fi Test Suite) through 9.0.0 allows OS command injection via 802.11x frames because the system() library…