CVE-2024-42000 to CVE-2024-42999
131 CVEs with public proof-of-concept exploits.
- CVE-2024-420051 PoCAn issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a…
- CVE-2024-420072 PoCsSPX (aka php-spx) through 0.4.15 allows SPX_UI_URI Directory Traversal to read arbitrary files.
- CVE-2024-420083 PoCsA Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote…
- CVE-2024-420098 PoCsKEVA Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails…
- CVE-2024-420101 PoCmod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in…
- CVE-2024-420111 PoCThe Spotify app 8.9.58 for iOS has a buffer overflow in its use of strcat.
- CVE-2024-420492 PoCsTightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.
- CVE-2024-423233 PoCsApache HertzBeat: RCE by snakeYaml deser load malicious xml
- CVE-2024-4232712 PoCsSQL injection in user.get API
- CVE-2024-423461 PoCStored Cross Site Scripting (Stored XSS) in Galaxy
- CVE-2024-423481 PoCFOG leaks sensitive information (AD domain, username and password)
- CVE-2024-423491 PoCFOG has a Log Information Disclosure
- CVE-2024-423581 PoCLoop with Unreachable Exit Condition ('Infinite Loop') in pdfio
- CVE-2024-423611 PoCGHSL-2023-256: HertzBeat Authenticated (guest role) SQL injection in /api/monitor/{monitorId}/metric/{metricFull}
- CVE-2024-423621 PoCGHSL-2023-255: HertzBeat Authenticated (user role) RCE via unsafe deserialization in /api/monitors/import
- CVE-2024-423652 PoCsAsterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplan
- CVE-2024-424481 PoCFrom the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform…
- CVE-2024-424611 PoCIn the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.
- CVE-2024-424712 PoCsArbitrary File Write via artifact extraction in actions/artifact
- CVE-2024-424781 PoCllama.cpp allows Arbitrary Address Read in rpc_server::get_tensor
- CVE-2024-424791 PoCllama.cpp allows write-what-where in rpc_server::set_tensor
- CVE-2024-424801 PoCKamaji's RBAC Roles for `etcd` are not disjunct
- CVE-2024-425231 PoCpubliccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData
- CVE-2024-425431 PoCTOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.
- CVE-2024-425451 PoCTOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the ssid parameter in setWizardCfg function.
- CVE-2024-425461 PoCTOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the password parameter in the loginauth function.
- CVE-2024-425471 PoCTOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.
- CVE-2024-425521 PoCHotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at…
- CVE-2024-425531 PoCA Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allows attackers to…
- CVE-2024-425541 PoCHotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at…
- CVE-2024-425551 PoCA Cross-Site Request Forgery (CSRF) in the component admin_room_removed.php of Hotel Management System commit 91caab8 allows attackers to…
- CVE-2024-425561 PoCHotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at…
- CVE-2024-425571 PoCA Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 allows attackers to…
- CVE-2024-425581 PoCHotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at…
- CVE-2024-425601 PoCA cross-site scripting (XSS) vulnerability in the component update_page_details.php of Blood Bank And Donation Management System commit…
- CVE-2024-425611 PoCPharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at…
- CVE-2024-425621 PoCPharmacy Management System commit a2efc8 was discovered to contain a SQL injection vulnerability via the invoice_number parameter at…
- CVE-2024-425631 PoCAn arbitrary file upload vulnerability in ERP commit 44bd04 allows attackers to execute arbitrary code via uploading a crafted HTML file.
- CVE-2024-425641 PoCERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at…
- CVE-2024-425651 PoCERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at…
- CVE-2024-425661 PoCSchool Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the password parameter at login.php
- CVE-2024-425671 PoCSchool Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the sid parameter at…
- CVE-2024-425681 PoCSchool Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the transport parameter at vehicle.php.
- CVE-2024-425691 PoCSchool Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at paidclass.php.
- CVE-2024-425701 PoCSchool Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at admininsert.php.
- CVE-2024-425711 PoCSchool Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at…
- CVE-2024-425721 PoCSchool Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at unitmarks.php.
- CVE-2024-425731 PoCSchool Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at dtmarks.php.
- CVE-2024-425741 PoCSchool Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at attendance.php.
- CVE-2024-425751 PoCSchool Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at substaff.php.
- CVE-2024-425761 PoCA Cross-Site Request Forgery (CSRF) in the component edit_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate…
- CVE-2024-425771 PoCA Cross-Site Request Forgery (CSRF) in the component add_product.php of Warehouse Inventory System v2.0 allows attackers to escalate…
- CVE-2024-425781 PoCA Cross-Site Request Forgery (CSRF) in the component edit_product.php of Warehouse Inventory System v2.0 allows attackers to escalate…
- CVE-2024-425791 PoCA Cross-Site Request Forgery (CSRF) in the component add_group.php of Warehouse Inventory System v2.0 allows attackers to escalate…
- CVE-2024-425801 PoCA Cross-Site Request Forgery (CSRF) in the component edit_group.php of Warehouse Inventory System v2.0 allows attackers to escalate…
- CVE-2024-425811 PoCA Cross-Site Request Forgery (CSRF) in the component delete_group.php of Warehouse Inventory System v2.0 allows attackers to escalate…
- CVE-2024-425821 PoCA Cross-Site Request Forgery (CSRF) in the component delete_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate…
- CVE-2024-425831 PoCA Cross-Site Request Forgery (CSRF) in the component delete_user.php of Warehouse Inventory System v2.0 allows attackers to escalate…
- CVE-2024-425841 PoCA Cross-Site Request Forgery (CSRF) in the component delete_product.php of Warehouse Inventory System v2.0 allows attackers to escalate…
- CVE-2024-425851 PoCA Cross-Site Request Forgery (CSRF) in the component delete_media.php of Warehouse Inventory System v2.0 allows attackers to escalate…
- CVE-2024-425861 PoCA Cross-Site Request Forgery (CSRF) in the component categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate…
- CVE-2024-426121 PoCPligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?whitelist_add
- CVE-2024-426191 PoCPligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via…
- CVE-2024-426231 PoCFrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/delete/1
- CVE-2024-426241 PoCFrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/delete/10.
- CVE-2024-426261 PoCFrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/add.
- CVE-2024-426271 PoCFrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/delete/3.
- CVE-2024-426281 PoCFrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/edit/3.
- CVE-2024-426301 PoCFrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_file.
- CVE-2024-426311 PoCFrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/edit/1.
- CVE-2024-426321 PoCFrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/add.
- CVE-2024-426406 PoCsangular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this…
- CVE-2024-426421 PoCMicron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially…
- CVE-2024-426572 PoCsAn issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of…
- CVE-2024-426582 PoCsAn issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's…
- CVE-2024-426971 PoCCross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to execute arbitrary…
- CVE-2024-427361 PoCIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist.…
- CVE-2024-427371 PoCIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in delBlacklist.…
- CVE-2024-427381 PoCIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setDmzCfg.…
- CVE-2024-427391 PoCIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in…
- CVE-2024-427401 PoCIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setLedCfg.…
- CVE-2024-427411 PoCIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in…
- CVE-2024-427421 PoCIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in…
- CVE-2024-427431 PoCIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setSyslogCfg .…
- CVE-2024-427441 PoCIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in…
- CVE-2024-427451 PoCIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUPnPCfg.…
- CVE-2024-427471 PoCIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWanIeCfg.…
- CVE-2024-427481 PoCIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWiFiWpsCfg.…
- CVE-2024-427581 PoCA Cross-site Scripting (XSS) vulnerability exists in version v2024-01-05 of the indexmenu plugin when is used and enabled in Dokuwiki…
- CVE-2024-428121 PoCIn D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi.…
- CVE-2024-428131 PoCIn TRENDnet TEW-752DRU FW1.03B01, there is a buffer overflow vulnerability due to the lack of length verification for the service field in…
- CVE-2024-428151 PoCIn the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the USER_AGENT field…
- CVE-2024-428311 PoCA reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to execute arbitrary…
- CVE-2024-428341 PoCA stored cross-site scripting (XSS) vulnerability in the Create Customer API in Incognito Service Activation Center (SAC) UI v14.11 allows…
- CVE-2024-428452 PoCsAn eval Injection vulnerability in the component invesalius/reader/dicom.py of InVesalius 3.1.99991 through 3.1.99998 allows attackers to…
- CVE-2024-428491 PoCAn issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.
- CVE-2024-428501 PoCAn issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.
- CVE-2024-428521 PoCCross Site Scripting vulnerability in AcuToWeb server v.10.5.0.7577C8b allows a remote attacker to execute arbitrary code via the…
- CVE-2024-428611 PoCAn issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted Pdelay_Req…
- CVE-2024-428851 PoCSQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id parameter of the…
- CVE-2024-428981 PoCA cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted…
- CVE-2024-429001 PoCRuoyi v4.7.9 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the sql parameter of the createTable()…
- CVE-2024-429011 PoCA CSV injection vulnerability in Lime Survey v6.5.12 allows attackers to execute arbitrary code via uploading a crafted CSV file.
- CVE-2024-429021 PoCAn issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a…
- CVE-2024-429141 PoCA host header injection vulnerability exists in the forgot password functionality of ArrowCMS version 1.0.0. By sending a specially…
- CVE-2024-429191 PoCeScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.
- CVE-2024-429361 PoCThe mqlink.elf is service component in Ruijie RG-EW300N with firmware ReyeeOS 1.300.1422 is vulnerable to Remote Code Execution via a…
- CVE-2024-429401 PoCTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromP2pListFilter function. This…
- CVE-2024-429411 PoCTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the wanmode parameter in the fromAdvSetWan function. This…
- CVE-2024-429431 PoCTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function.…
- CVE-2024-429441 PoCTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromNatlimit function. This…
- CVE-2024-429461 PoCTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. This…
- CVE-2024-429481 PoCTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This…
- CVE-2024-429501 PoCTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the Go parameter in the fromSafeClientFilter function. This…
- CVE-2024-429511 PoCTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the mit_pptpusrpw parameter in the fromWizardHandle function.…
- CVE-2024-429521 PoCTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromqossetting function. This…
- CVE-2024-429551 PoCTenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromSafeClientFilter function. This…
- CVE-2024-429661 PoCIncorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration file, which contains…
- CVE-2024-429671 PoCIncorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains…
- CVE-2024-429691 PoCTenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeUrlFilter function. This…
- CVE-2024-429761 PoCTenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeClientFilter function. This…
- CVE-2024-429771 PoCTenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the qos parameter in the fromqossetting function. This…
- CVE-2024-429781 PoCAn issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary commands via a…
- CVE-2024-429801 PoCTenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the frmL7ImForm function. This…
- CVE-2024-429811 PoCTenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This…
- CVE-2024-429821 PoCTenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. This…
- CVE-2024-429851 PoCTenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromNatlimit function. This…
- CVE-2024-429861 PoCTenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This…
- CVE-2024-429872 PoCsTenda FH1206 v02.03.01.35 was discovered to contain a stack-based buffer overflow vulnerability in the fromPptpUserAdd function. The…
- CVE-2024-429941 PoCVTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the…
- CVE-2024-429951 PoCVTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migration"…