CVE-2024-45000 to CVE-2024-45999
98 CVEs with public proof-of-concept exploits.
- CVE-2024-450431 PoCOpenTelemetry Collector AWS Firehose Receiver Authentication Bypass Vulnerability
- CVE-2024-450462 PoCsPhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via style information
- CVE-2024-450472 PoCsPotential mXSS vulnerability due to improper HTML escaping in svelte
- CVE-2024-450482 PoCsXML External Entity Reference (XXE) in PHPSpreadsheet
- CVE-2024-450522 PoCsFides Webserver Authentication Timing-Based Username Enumeration Vulnerability
- CVE-2024-450532 PoCsRemote Code Execution Vulnerability via SSTI in Fides Webserver Jinja Email Templating Engine
- CVE-2024-450571 PoCReflected Cross-Site Scripting in i-Educar
- CVE-2024-450582 PoCsPrivilege escalation in i-Educar
- CVE-2024-450591 PoCAuthenticated SQL Injection in i-Educar
- CVE-2024-450602 PoCsUnauthenticated Cross-Site-Scripting (XSS) in sample file in PHPSpreadsheet
- CVE-2024-450621 PoCA stack based buffer overflow vulnerability is present in OpenPrinting ippusbxd 1.34. A specially configured printer that supports…
- CVE-2024-451631 PoCThe Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Unauthenticated…
- CVE-2024-451661 PoCAn issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and…
- CVE-2024-451672 PoCsAn issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and…
- CVE-2024-451681 PoCAn issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is transferred over a raw socket without any…
- CVE-2024-451691 PoCAn issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and…
- CVE-2024-451701 PoCAn issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper or missing access control, low privileged users…
- CVE-2024-451711 PoCAn issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to upload…
- CVE-2024-451721 PoCAn issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to missing protection mechanisms, the C-MOR web…
- CVE-2024-451731 PoCAn issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning sudo privileges,…
- CVE-2024-451741 PoCAn issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to improper validation of user-supplied data,…
- CVE-2024-451751 PoCAn issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Sensitive information is stored in cleartext. It was found out…
- CVE-2024-451771 PoCAn issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to improper input validation, the C-MOR web…
- CVE-2024-451781 PoCAn issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to download…
- CVE-2024-451791 PoCAn issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to insufficient input validation, the C-MOR web…
- CVE-2024-451881 PoCMage AI file content request remote arbitrary file leak
- CVE-2024-451891 PoCMage AI git content request remote arbitrary file leak
- CVE-2024-451901 PoCMage AI pipeline interaction request remote arbitrary file leak
- CVE-2024-451953 PoCsKEVApache OFBiz: Confused controller-view authorization logic (forced browsing)
- CVE-2024-452002 PoCsIn Nintendo Mario Kart 8 Deluxe before 3.0.3, the LAN/LDN local multiplayer implementation allows a remote attacker to exploit a…
- CVE-2024-452081 PoCThe Versa Director SD-WAN orchestration platform which makes use of Cisco NCS application service. Active and Standby Directors…
- CVE-2024-452163 PoCsApache Solr: Authentication bypass possible using a fake URL Path ending
- CVE-2024-452413 PoCsA traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated…
- CVE-2024-452561 PoCAn arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overwrite SQLite…
- CVE-2024-452571 PoCA Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on…
- CVE-2024-452601 PoCAn issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to…
- CVE-2024-452611 PoCAn issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a…
- CVE-2024-452641 PoCA cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add…
- CVE-2024-452651 PoCA SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to execute arbitrary SQL…
- CVE-2024-452902 PoCsPath traversal and Server-Side Request Forgery when opening XLSX files in PHPSpreadsheet
- CVE-2024-452911 PoCPath traversal and Server-Side Request Forgery in HTML writer when embedding images is enabled in PHPSpreadsheet
- CVE-2024-452922 PoCsPhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via JavaScript hyperlinks
- CVE-2024-452933 PoCsXML External Entity Reference (XXE) in PHPSpreadsheet's XLSX reader
- CVE-2024-452991 PoCalf.io's preloaded data as json is not escaped correctly
- CVE-2024-453001 PoCBypassing promo code limitations with race conditions
- CVE-2024-453022 PoCsCRLF Injection in RestSharp's `RestRequest.AddHeader` method
- CVE-2024-453051 PoCgix-path uses local config across repos when it is the highest scope
- CVE-2024-453081 PoCMySQL & free URL mode allows to hide existing notes in hedgedoc
- CVE-2024-453092 PoCsOneDev vulnerable to arbitrary file reading for unauthenticated user
- CVE-2024-453101 PoCrunc can be confused to create empty files/directories on the host
- CVE-2024-453374 PoCsMisuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto
- CVE-2024-453523 PoCsXiaomi smarthome application Webview has code execution vulnerability
- CVE-2024-453831 PoCA mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver…
- CVE-2024-453883 PoCsArbitrary file read in the `/api/v2/simulation` endpoint in hoverfly (`GHSL-2023-274`)
- CVE-2024-454051 PoCgix-path improperly resolves configuration path reported by Git
- CVE-2024-454062 PoCsCraft CMS stored XSS in breadcrumb list and title fields
- CVE-2024-454092 PoCsThe Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector
- CVE-2024-454102 PoCsHTTP client can remove the X-Forwarded headers in Traefik
- CVE-2024-454311 PoCOpenSynergy BlueSDK (aka Blue SDK) through 6.x has Improper Input Validation. The specific flaw exists within the BlueSDK Bluetooth stack.…
- CVE-2024-454321 PoCOpenSynergy BlueSDK (aka Blue SDK) through 6.x mishandles a function call. The specific flaw exists within the BlueSDK Bluetooth stack.…
- CVE-2024-454331 PoCOpenSynergy BlueSDK (aka Blue SDK) through 6.x has Incorrect Control Flow Scoping. The specific flaw exists within the BlueSDK Bluetooth…
- CVE-2024-454341 PoCOpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetooth stack. The…
- CVE-2024-454364 PoCsextractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent directory.
- CVE-2024-454404 PoCscore/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is…
- CVE-2024-454881 PoCOne Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only…
- CVE-2024-455073 PoCsApache OFBiz: Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCE
- CVE-2024-455081 PoCHTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a…
- CVE-2024-455197 PoCsKEVThe postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before…
- CVE-2024-455271 PoCREDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via…
- CVE-2024-455892 PoCsRapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote…
- CVE-2024-455902 PoCsbody-parser vulnerable to denial of service when url encoding is enabled
- CVE-2024-455911 PoCXWiki Platform document history including authors of any page exposed to unauthorized actors
- CVE-2024-455962 PoCsDirectus's session is cached for OpenID and OAuth2 if `redirect` is not used
- CVE-2024-455981 PoCCacti has a Local File Inclusion (LFI) Vulnerability via Poller Standard Error Log Path
- CVE-2024-456141 PoCHeader normalization allows for client to clobber proxy set headers in Puma
- CVE-2024-456221 PoCASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for Authentication…
- CVE-2024-456991 PoCReflected XSS vulnerability in /zabbix.php?action=export.valuemaps
- CVE-2024-457581 PoCH2O.ai H2O through 3.46.0.4 allows attackers to arbitrarily set the JDBC URL, leading to deserialization attacks, file reads, and command…
- CVE-2024-457942 PoCsSQL Injection in CreateUser API in devtron
- CVE-2024-458031 PoCCross site scripting (XSS) Vulnerability on route /wireui/button?label=Content in wireui
- CVE-2024-458101 PoCEnvoy crashes for LocalReply in http async client
- CVE-2024-458121 PoCDOM Clobbering gadget found in vite bundled scripts that leads to XSS in Vite
- CVE-2024-458271 PoCImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Mesh Wi-Fi router RP562B…
- CVE-2024-458441 PoCBIG-IP monitors vulnerability
- CVE-2024-458702 PoCsBandisoft BandiView 7.05 is vulnerable to Incorrect Access Control in sub_0x3d80fc via a crafted POC file.
- CVE-2024-458712 PoCsBandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of service (DOS).
- CVE-2024-458722 PoCsBandisoft BandiView 7.05 is vulnerable to Buffer Overflow via sub_0x410d1d. The vulnerability occurs due to insufficient validation of PSD…
- CVE-2024-458731 PoCA DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persistence via placing a…
- CVE-2024-458741 PoCA DLL hijacking vulnerability in VegaBird Vooki 5.2.9 allows attackers to execute arbitrary code / maintain persistence via placing a…
- CVE-2024-459601 PoCZenario 9.7.61188 allows authenticated admin users to upload PDF files containing malicious code into the target system. If the PDF file…
- CVE-2024-459621 PoCOctober 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the…
- CVE-2024-459641 PoCZenario 9.7.61188 is vulnerable to Cross Site Scripting (XSS) in the Image library via the "Organizer tags" field.
- CVE-2024-459651 PoCContao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through…
- CVE-2024-459831 PoCA Cross-Site Request Forgery (CSRF) vulnerability exists in kishan0725's Hospital Management System version 6.3.5. The vulnerability…
- CVE-2024-459841 PoCA Cross Site Scripting (XSS) vulnerability in add_donor.php of Blood Bank And Donation Management System 1.0 allows an attacker to inject…
- CVE-2024-459851 PoCA Cross Site Scripting (XSS) vulnerability in update_contact.php of Blood Bank and Donation Management System v1.0 allows an attacker to…
- CVE-2024-459861 PoCA stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs when an account is…
- CVE-2024-459871 PoCProjectworld Online Voting System Version 1.0 is vulnerable to Cross Site Request Forgery (CSRF) via voter.php. This vulnerability allows…