CVE-2024-46000 to CVE-2024-46999
89 CVEs with public proof-of-concept exploits.
- CVE-2024-460411 PoCIoT Haat Smart Plug IH-IN-16A-S v5.16.1 is vulnerable to Authentication Bypass by Capture-replay.
- CVE-2024-460441 PoCCH22 V1.0.0.6(468) has a stack overflow vulnerability located in the fromqossetting function.
- CVE-2024-460451 PoCTenda CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the frmL7PlotForm function.
- CVE-2024-460461 PoCTenda FH451 v1.0.0.9 has a stack overflow vulnerability located in the RouteStatic function.
- CVE-2024-460471 PoCTenda FH451 v1.0.0.9 has a stack overflow vulnerability in the fromDhcpListClient function.
- CVE-2024-460481 PoCTenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i
- CVE-2024-460491 PoCTenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function.
- CVE-2024-460791 PoCScriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter.
- CVE-2024-460811 PoCScriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in the…
- CVE-2024-460821 PoCScriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parameters.
- CVE-2024-460831 PoCScriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads using the…
- CVE-2024-460971 PoCTestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section. When a new TestPlan is created, an ID with an…
- CVE-2024-462091 PoCA stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attackers to execute…
- CVE-2024-462121 PoCAn issue in the component /index.php?page=backup/export of REDAXO CMS v5.17.1 allows attackers to execute a directory traversal.
- CVE-2024-462131 PoCREDAXO CMS v2.11.0 was discovered to contain a remote code execution (RCE) vulnerability.
- CVE-2024-462261 PoCA stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary JavaScript in the…
- CVE-2024-462361 PoCCodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the address parameter in add_members.php and…
- CVE-2024-462381 PoCMultiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in…
- CVE-2024-462391 PoCMultiple cross-site scripting vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in…
- CVE-2024-462401 PoCCollabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under action=system and the company/contact parameters…
- CVE-2024-462411 PoCPHPGurukul Dairy Farm Shop Management System v1.1 is vulnerable to Cross-Site Scripting (XSS) via the pname parameter in add_product.php…
- CVE-2024-462563 PoCsA Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt…
- CVE-2024-462571 PoCA Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve…
- CVE-2024-462581 PoCcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_load_png_mem() function at cute_png.h.
- CVE-2024-462591 PoCcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_unfilter() function at cute_png.h.
- CVE-2024-462611 PoCcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_make32() function at cute_png.h.
- CVE-2024-462631 PoCcute_png v1.05 was discovered to contain a stack overflow via the cp_dynamic() function at cute_png.h.
- CVE-2024-462641 PoCcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at cute_png.h.
- CVE-2024-462671 PoCcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_block() function at cute_png.h.
- CVE-2024-462741 PoCcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_stored() function at cute_png.h.
- CVE-2024-462761 PoCcute_png v1.05 was discovered to contain a heap buffer overflow via the cp_chunk() function at cute_png.h.
- CVE-2024-462783 PoCsTeedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.
- CVE-2024-463101 PoCIncorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via…
- CVE-2024-463621 PoCFrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_directory
- CVE-2024-463771 PoCBest House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function of the file…
- CVE-2024-464091 PoCA stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts or HTML via…
- CVE-2024-464132 PoCsRebuild v3.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the type parameter in the…
- CVE-2024-464191 PoCTOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg function via the ssid5g parameter.
- CVE-2024-464241 PoCTOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomModule function, which allows attackers…
- CVE-2024-464291 PoCA hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management…
- CVE-2024-464301 PoCTenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. Unauthorized password change via the web management portal allows…
- CVE-2024-464311 PoCTenda W18E V16.01.0.8(1625) is vulnerable to Buffer Overflow. An attacker with access to the web management portal can exploit this…
- CVE-2024-464321 PoCTenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. An attacker can send a specially crafted HTTP POST request to the…
- CVE-2024-464331 PoCA default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management…
- CVE-2024-464341 PoCTenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized remote attacker to…
- CVE-2024-464351 PoCA stack overflow vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an authenticated remote attacker to cause a…
- CVE-2024-464361 PoCHardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the device over the…
- CVE-2024-464371 PoCA sensitive information disclosure vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an unauthenticated remote…
- CVE-2024-464461 PoCMecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks.…
- CVE-2024-464512 PoCsTOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the desc parameter.
- CVE-2024-464701 PoCCross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaScript via the…
- CVE-2024-464711 PoCThe Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories,…
- CVE-2024-464721 PoCCodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page.
- CVE-2024-464781 PoCHTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681.
- CVE-2024-464831 PoCXlight FTP Server <3.9.4.3 has an integer overflow vulnerability in the packet parsing logic of the SFTP server, which can lead to a heap…
- CVE-2024-464851 PoCdingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate
- CVE-2024-464862 PoCsTP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv function.
- CVE-2024-465063 PoCsNetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings…
- CVE-2024-465072 PoCsA SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows…
- CVE-2024-465281 PoCAn Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSphere Enterprise…
- CVE-2024-465311 PoCphpgurukul Vehicle Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchinputdata parameter…
- CVE-2024-465321 PoCSQL Injection vulnerability in OpenHIS v.1.0 allows an attacker to execute arbitrary code via the refund function in the…
- CVE-2024-465382 PoCsA cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted…
- CVE-2024-465461 PoCNEXTU FLETA AX1500 WIFI6 Router v1.0.3 was discovered to contain a stack overflow via the url parameter at /boafrm/formFilter. This…
- CVE-2024-466001 PoCdingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.php?act=delCate&id=31
- CVE-2024-466051 PoCA cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to execute arbitrary…
- CVE-2024-466061 PoCA cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to execute arbitrary…
- CVE-2024-466071 PoCIncorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and…
- CVE-2024-466091 PoCAn access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to…
- CVE-2024-466101 PoCAn access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and…
- CVE-2024-466262 PoCsOS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.
- CVE-2024-466272 PoCsIncorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.
- CVE-2024-466281 PoCTenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName…
- CVE-2024-466321 PoCAssimp v5.4.3 is vulnerable to Buffer Overflow via the MD5Importer::LoadMD5MeshFile function.
- CVE-2024-466351 PoCAn issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access sensitive…
- CVE-2024-466541 PoCA stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute…
- CVE-2024-466581 PoCSyrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command injection vulnerability.
- CVE-2024-466711 PoCAn Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and…
- CVE-2024-468781 PoCA Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and earlier. This…
- CVE-2024-468791 PoCA Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system.php in Tiki version…
- CVE-2024-469381 PoCAn issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release…
- CVE-2024-469461 PoClangchain_experimental (aka LangChain Experimental) 0.1.17 through 0.3.0 for LangChain allows attackers to execute arbitrary code through…
- CVE-2024-469781 PoCMissing checks for notification filter preferences editions in XWiki Platform
- CVE-2024-469791 PoCData leak of notification filters of users in XWiki Platform
- CVE-2024-469816 PoCsRedis' Lua library commands may lead to remote code execution
- CVE-2024-469823 PoCsCache Poisoning in next.js
- CVE-2024-469864 PoCsArbitrary file write leading to RCE in Camaleon CMS
- CVE-2024-4698712 PoCsArbitrary path traversal in Camaleon CMS
- CVE-2024-469971 PoCDataEase's H2 datasource has a remote command execution risk