CVE-2024-43000 to CVE-2024-43999
40 CVEs with public proof-of-concept exploits.
- CVE-2024-430181 PoCPiwigo 13.8.0 and below is vulnerable to SQL Injection in the parameters max_level and min_register. These parameters are used in…
- CVE-2024-430331 PoCJPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to…
- CVE-2024-430351 PoCFonoster 0.5.5 before 0.6.1 allows ../ directory traversal to read arbitrary files via the /sounds/:file or /tts/:file VoiceServer…
- CVE-2024-430445 PoCsJenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system…
- CVE-2024-431441 PoCWordPress Cost Calculator Builder plugin <= 3.2.15 - SQL Injection vulnerability
- CVE-2024-431602 PoCsWordPress BerqWP plugin <= 1.7.6 - Unauthenticated Arbitrary File Upload vulnerability
- CVE-2024-432831 PoCWordPress Contest Gallery plugin <= 23.1.2 - Unauthenticated Comment UserID And IP address Disclosure vulnerability
- CVE-2024-433602 PoCsZoneMinder Time-based SQL Injection
- CVE-2024-433621 PoCStored Cross-site Scripting (XSS) when creating external links in Cacti
- CVE-2024-433632 PoCsRemote code execution via Log Poisoning in Cacti
- CVE-2024-433641 PoCStored Cross-site Scripting (XSS) when creating external links in Cacti
- CVE-2024-433651 PoCStored Cross-site Scripting (XSS) when creating external links in Cacti
- CVE-2024-433732 PoCswebcrack has an Arbitrary File Write Vulnerability on Windows when Parsing and Saving a Malicious Bundle
- CVE-2024-433811 PoCreNgine vulnerable to Stored Cross-Site Scripting (XSS) via DNS Record Poisoning
- CVE-2024-433961 PoCKhoj Vulnerable to Stored Cross-site Scripting In Automate (Preview feature)
- CVE-2024-433991 PoCMobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files
- CVE-2024-434001 PoCXWiki Platform allows XSS through XClass name in string properties
- CVE-2024-434061 PoCLF Edge eKuiper has a SQL Injection in sqlKvStore
- CVE-2024-434102 PoCsRussh has an OOM Denial of Service due to allocation of untrusted amount
- CVE-2024-434161 PoCGLPI vulnerable to enumeration of users' email addresses by unauthenticated user
- CVE-2024-434259 PoCsMoodle: remote code execution via calculated question types
- CVE-2024-434412 PoCsApache HugeGraph-Server: Fixed JWT Token(Secret)
- CVE-2024-434512 PoCsKEVNTLM Hash Disclosure Spoofing Vulnerability
- CVE-2024-434682 PoCsKEVMicrosoft Configuration Manager Remote Code Execution Vulnerability
- CVE-2024-435831 PoCWinlogon Elevation of Privilege Vulnerability
- CVE-2024-436301 PoCWindows Kernel Elevation of Privilege Vulnerability
- CVE-2024-436391 PoCWindows KDC Proxy Remote Code Execution Vulnerability
- CVE-2024-436872 PoCsXSS vulnerability in bannerconfig endpoint in TimeProvider 4100
- CVE-2024-437792 PoCsAn information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially…
- CVE-2024-437851 PoCgitoxide-core does not neutralize special characters for terminals
- CVE-2024-437871 PoCHono CSRF middleware can be bypassed using crafted Content-Type header
- CVE-2024-437883 PoCsDOM Clobbering Gadget found in Webpack's AutoPublicPathRuntimeModule that leads to Cross-site Scripting (XSS)
- CVE-2024-437971 PoCPath Traversal in audiobookshelf
- CVE-2024-438041 PoCOS Command Injection via Port Scan Functionality in Roxy-WI
- CVE-2024-439174 PoCsWordPress TI WooCommerce Wishlist plugin <= 2.8.2 - SQL Injection vulnerability
- CVE-2024-439181 PoCWordPress WBW Product Table PRO plugin <= 1.9.4 - Unauthenticated Arbitrary SQL Query Execution vulnerability
- CVE-2024-439192 PoCsWordPress Yet Another Related Posts Plugin (YARPP) plugin <= 5.30.10 - Broken Access Control vulnerability
- CVE-2024-439652 PoCsWordPress SendGrid for WordPress plugin <= 1.4 - SQL Injection vulnerability
- CVE-2024-439711 PoCWordPress Sunshine Photo Cart plugin <= 3.2.5 - Cross Site Scripting (XSS) vulnerability
- CVE-2024-439982 PoCsWordPress Blogpoet theme <= 1.0.3 - Broken Access Control vulnerability