CVE-2024-44000 to CVE-2024-44999
60 CVEs with public proof-of-concept exploits.
- CVE-2024-440008 PoCsWordPress LiteSpeed Cache plugin < 6.5.0.1 - Unauthenticated Account Takeover via Cookie Leak vulnerability
- CVE-2024-440681 PoCAn issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and…
- CVE-2024-440832 PoCsida64.dll in Hex-Rays IDA Pro through 8.4 crashes when there is a section that has many jumps linked, and the final jump corresponds to…
- CVE-2024-440851 PoCONLYOFFICE Docs before 8.1.0 allows XSS via a GeneratorFunction Object attack against a macro. This is related to use of an…
- CVE-2024-441331 PoCThis issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15. On MDM managed devices, an app may be…
- CVE-2024-441931 PoCA logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Windows. A local attacker may be able to…
- CVE-2024-442351 PoCThe issue was addressed with improved checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to view restricted…
- CVE-2024-442521 PoCA logic issue was addressed with improved file handling. This issue is fixed in iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1,…
- CVE-2024-442582 PoCsThis issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS…
- CVE-2024-443081 PoCKEVThe issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1,…
- CVE-2024-443131 PoCTastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows…
- CVE-2024-443401 PoCD-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_express_devices and…
- CVE-2024-443411 PoCD-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist…
- CVE-2024-443421 PoCD-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the wl(0).(0)_ssid parameter.…
- CVE-2024-443492 PoCsA SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL…
- CVE-2024-443811 PoCD-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.
- CVE-2024-443821 PoCD-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function.
- CVE-2024-444021 PoCD-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.
- CVE-2024-444081 PoCD-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration file downloads,…
- CVE-2024-444101 PoCD-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.
- CVE-2024-444111 PoCD-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.
- CVE-2024-444502 PoCsMultiple functions are vulnerable to Authorization Bypass in AIMS eCrew. The issue was fixed in version JUN23 #190.
- CVE-2024-444661 PoCCOMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to…
- CVE-2024-445412 PoCsevilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin."
- CVE-2024-445422 PoCsSQL Injection vulnerability in todesk v.1.1 allows a remote attacker to execute arbitrary code via the /todesk.com/news.html parameter.
- CVE-2024-445631 PoCTenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo.
- CVE-2024-445651 PoCTenda AX1806 v1.0.0.1 contains a stack overflow via the serverName parameter in the function form_fast_setting_internet_set.
- CVE-2024-445871 PoCitsourcecode Alton Management System 1.0 is vulnerable to SQL Injection in /noncombo_save.php via the "menu" parameter.
- CVE-2024-445891 PoCStack overflow vulnerability in the Login function in the HNAP service in D-Link DCS-960L with firmware 1.09 allows attackers to execute…
- CVE-2024-446101 PoCPCAN-Ethernet Gateway FD before 1.3.0 and PCAN-Ethernet Gateway before 2.11.0 are vulnerable to Command injection via shell metacharacters…
- CVE-2024-446231 PoCAn issue in TuomoKu SPx-GC v.1.3.0 and before allows a remote attacker to execute arbitrary code via the child_process.js function.
- CVE-2024-446252 PoCsGogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.
- CVE-2024-446741 PoCD-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an…
- CVE-2024-447201 PoCSeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component admin_safe.php.
- CVE-2024-447211 PoCSeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.
- CVE-2024-447241 PoCAutoCMS v5.4 was discovered to contain a PHP code injection vulnerability via the txtsite_url parameter at /admin/site_add.php. This…
- CVE-2024-447251 PoCAutoCMS v5.4 was discovered to contain a SQL injection vulnerability via the sidebar parameter at /admin/robot.php.
- CVE-2024-447271 PoCSourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/login.php.
- CVE-2024-447281 PoCSourcecodehero Event Management System 1.0 allows Stored Cross-Site Scripting via parameters Full Name, Address, Email, and contact# in…
- CVE-2024-447624 PoCsA discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts.
- CVE-2024-447651 PoCAn Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH CloudPanel v2.0.0 to v2.4.2 allows…
- CVE-2024-447931 PoCA cross-site scripting (XSS) vulnerability in the component /managers/multiple_freeleech.php of Gazelle commit 63b3370 allows attackers to…
- CVE-2024-447941 PoCA cross-site scripting (XSS) vulnerability in the component /master/auth/OnedriveRedirect.php of PicUploader commit fcf82ea allows…
- CVE-2024-447951 PoCA cross-site scripting (XSS) vulnerability in the component /login/disabled.php of Gazelle commit 63b3370 allows attackers to execute…
- CVE-2024-447981 PoCphpgurukul Bus Pass Management System 1.0 is vulnerable to Cross-site scripting (XSS) in /admin/pass-bwdates-reports-details.php via…
- CVE-2024-448121 PoCSQL Injection vulnerability in Online Complaint Site v.1.0 allows a remote attacker to escalate privileges via the username and password…
- CVE-2024-448151 PoCVulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash…
- CVE-2024-448251 PoCDirectory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write…
- CVE-2024-448492 PoCsQualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.
- CVE-2024-448591 PoCTenda FH1201 v1.2.0.14 has a stack buffer overflow vulnerability in `formWrlExtraGet`.
- CVE-2024-448672 PoCsphpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php.
- CVE-2024-448712 PoCsAn arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via…
- CVE-2024-448721 PoCA reflected cross-site scripting (XSS) vulnerability in moziloCMS v3.0 allows attackers to execute arbitrary code in the context of a…
- CVE-2024-449022 PoCsA deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
- CVE-2024-449131 PoCAn issue in the component EXR!ReadEXR+0x40ef1 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file.…
- CVE-2024-449141 PoCAn issue in the component EXR!ReadEXR+0x3df50 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file.…
- CVE-2024-449151 PoCAn issue in the component EXR!ReadEXR+0x4eef0 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file.…
- CVE-2024-449161 PoCVulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the…
- CVE-2024-449461 PoCkcm: Serialise kcm_sendmsg() for the same socket.
- CVE-2024-449471 PoCfuse: Initialize beyond-EOF page contents before setting uptodate