CVE-2024-47000 to CVE-2024-47999
59 CVEs with public proof-of-concept exploits.
- CVE-2024-470511 PoCRemote Code Execution & File Deletion in Asset Uploads
- CVE-2024-470623 PoCsMultiple SQL Injections and ORM Leak in navidrome
- CVE-2024-470651 PoCTraceroute_APP responses are not rate-limited.
- CVE-2024-470663 PoCsLobe Chat has insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)
- CVE-2024-470671 PoCAlist Contains a Reflected Cross-Site Scripting Vulnerability
- CVE-2024-470682 PoCsDOM Clobbering Gadget found in rollup bundled scripts that leads to XSS
- CVE-2024-470692 PoCsOveleon Cookiebar reflected Cross-site Scripting vulnerability
- CVE-2024-470731 PoCDataease arbitrary interface access vulnerability
- CVE-2024-470766 PoCslibcupsfilters's cfGetPrinterAttributes5 does not validate IPP attributes returned from an IPP server
- CVE-2024-471672 PoCsSSRF in the path parameter of /queue/join in Gradio
- CVE-2024-471755 PoCslibppd's ppdCreatePPDFromIPP2 function does not sanitize IPP attributes when creating the PPD buffer
- CVE-2024-4717617 PoCscups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
- CVE-2024-471841 PoCAmpache vulnerable to Stored XSS via Democratic Playlist Name
- CVE-2024-471861 PoCFilament has unvalidated ColorColumn and ColorEntry values that can be used for Cross-site Scripting
- CVE-2024-472261 PoCA stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel…
- CVE-2024-473081 PoCWordPress Templately plugin <= 3.1.2 - Broken Access Control vulnerability
- CVE-2024-473741 PoCWordPress LiteSpeed Cache plugin <= 6.5.0.2 - Cross Site Scripting (XSS) vulnerability
- CVE-2024-474071 PoCmySCADA myPRO OS Command Injection
- CVE-2024-475232 PoCsLibreNMS has Stored Cross-site Scripting vulnerability in "Alert Transports" feature
- CVE-2024-475242 PoCsLibreNMS has Stored Cross-site Scripting vulnerability in "Device Group" Name
- CVE-2024-475252 PoCsStored XSS ('Cross-site Scripting') in librenms/includes/html/print-alert-rules.php
- CVE-2024-475262 PoCsLibreNMS has a Self-XSS ('Cross-site Scripting') in librenms/includes/html/modal/alert_template.inc.php
- CVE-2024-475272 PoCsLibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device-dependencies.inc.php
- CVE-2024-475282 PoCsLibreNMS Contains a Stored XSS via File Upload
- CVE-2024-475291 PoCOpenC3 COSMOS uses clear text storage of password/token (`GHSL-2024-129`)
- CVE-2024-475301 PoCScout contains an Open Redirect on Login via `next`
- CVE-2024-475311 PoCScout contains insufficient output escaping of attachment names
- CVE-2024-475337 PoCsCobbler allows anyone to connect to cobbler XML-RPC server with a known password and make changes
- CVE-2024-475352 PoCsDenial of Service attack on windows app using Netty
- CVE-2024-475362 PoCsstarcitizentools/citizen-skin vulnerable to stored, self-XSS in the "real name" field
- CVE-2024-475541 PoCApache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
- CVE-2024-475757 PoCsKEVA missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7,…
- CVE-2024-476051 PoCCross-site Scripting via insert media remote file oembed in silverstripe-asset-admin
- CVE-2024-476191 PoCtranport: TLS host name wildcard matching too lax
- CVE-2024-477691 PoCIDURAR has a Path Traversal (unauthenticated user can read sensitive data)
- CVE-2024-477731 PoCAnonymous cache poisoning via XHR requests in Discourse
- CVE-2024-477991 PoCExposure of sensitive system information to an unauthorized control sphere issue exists in Mesh Wi-Fi router RP562B firmware version…
- CVE-2024-478102 PoCsA use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a 3D page object. A specially crafted Javascript code…
- CVE-2024-478181 PoCLogged-in users with any role can delete arbitrary files in @saltcorn/server
- CVE-2024-478212 PoCspyLoad vulnerable to remote code execution by download to /.pyload/scripts using /flashgot API
- CVE-2024-478221 PoCDirectus inserts access token from query string into logs
- CVE-2024-478232 PoCsLivewire Remote Code Execution (RCE) on File Uploads
- CVE-2024-478271 PoCArgo Workflows Controller: Denial of Service via malicious daemon Workflows
- CVE-2024-478281 PoCCross-Site Request Forgery in ampache
- CVE-2024-478301 PoCPlane allows server side request forgery via /_next/image endpoint
- CVE-2024-478331 PoCSession Cookie without Secure and HTTPOnly flags in taipy
- CVE-2024-478361 PoCAdmidio vulnerable to HTML Injection In The Messages Section
- CVE-2024-478651 PoCMissing authentication for critical function vulnerability exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If this…
- CVE-2024-478732 PoCsPhpSpreadsheet XmlScanner bypass leads to XXE
- CVE-2024-478741 PoCStarlette Denial of service (DoS) via multipart/form-data
- CVE-2024-478752 PoCsDOMPurify nesting-based mXSS
- CVE-2024-478781 PoCReflected cross-site scripting vulnerability (XSS) in GData extension (authorized.vt)
- CVE-2024-478792 PoCsOpenRefine's PreviewExpressionCommand, which is eval, lacks protection against cross-site request forgery (CSRF)
- CVE-2024-478801 PoCOpenRefine has a reflected cross-site scripting vulnerability from POST request in ExportRowsCommand
- CVE-2024-478812 PoCsOpenRefine's SQLite integration allows filesystem access, remote code execution (RCE)
- CVE-2024-478821 PoCOpenRefine's error page lacks escaping, leading to potential Cross-site Scripting on import of malicious project
- CVE-2024-478831 PoCButterfly has path/URL confusion in resource handling leading to multiple weaknesses
- CVE-2024-478851 PoCastro's client-side router has DOM Clobbering Gadget that leads to XSS
- CVE-2024-479451 PoCPredictable Session ID