CVE-2024-48000 to CVE-2024-48999
115 CVEs with public proof-of-concept exploits.
- CVE-2024-480501 PoCIn agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this…
- CVE-2024-480521 PoCIn gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that…
- CVE-2024-480571 PoClocalai <=2.20.1 is vulnerable to Cross Site Scripting (XSS). When calling the delete model API and passing inappropriate parameters, it…
- CVE-2024-480612 PoCslangflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on…
- CVE-2024-481121 PoCA deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary…
- CVE-2024-481191 PoCVtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML.
- CVE-2024-481202 PoCsX2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject malicious JavaScript…
- CVE-2024-481911 PoCdingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component…
- CVE-2024-481971 PoCCross Site Scripting vulnerability in Audiocodes MP-202b v.4.4.3 allows a remote attacker to escalate privileges via the login page of the…
- CVE-2024-482021 PoCicecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile.
- CVE-2024-482083 PoCspure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file.
- CVE-2024-482181 PoCFunadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.
- CVE-2024-482221 PoCFunadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.
- CVE-2024-482231 PoCFunadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.
- CVE-2024-482281 PoCAn issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters…
- CVE-2024-482301 PoCfunadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php.
- CVE-2024-482311 PoCFunadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php.
- CVE-2024-482321 PoCAn issue was found in mipjz 5.0.5. In the mipPost method of \app\setting\controller\ApiAdminTool.php, the value of the postAddress…
- CVE-2024-482331 PoCmipjz 5.0.5 is vulnerable to Cross Site Scripting (XSS) in \app\setting\controller\ApiAdminSetting.php via the ICP parameter.
- CVE-2024-482381 PoCWTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the parentid parameter.
- CVE-2024-482451 PoCVehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in various…
- CVE-2024-482461 PoCVehicle Management System 1.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the "Name" parameter of…
- CVE-2024-482483 PoCsKEVNAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may…
- CVE-2024-482591 PoCCloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign.
- CVE-2024-482701 PoCAn issue in the component /logins of oasys v1.1 allows attackers to access sensitive information via a burst attack.
- CVE-2024-482711 PoCD-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly allowing attackers…
- CVE-2024-482721 PoCD-Link DSL6740C v6.TR069.20211230 was discovered to use an insecure default Wifi password, possibly allowing attackers to connect to the…
- CVE-2024-482781 PoCPhpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via…
- CVE-2024-482881 PoCTP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification on both the…
- CVE-2024-482911 PoCdingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=editAdmin&id=17
- CVE-2024-483073 PoCsJeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.
- CVE-2024-483121 PoCWebLaudos v20.8 (118) was discovered to contain a cross-site scripting (XSS) vulnerability via the login page.
- CVE-2024-483221 PoCUsersController.php in Run.codes 1.5.2 and older has a reset password race condition vulnerability.
- CVE-2024-483251 PoCPortabilis i-Educar 2.8.0 is vulnerable to SQL Injection in the "getDocuments" function of the "InstituicaoDocumentacaoController" class.…
- CVE-2024-483591 PoCQualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parameter.
- CVE-2024-483602 PoCsQualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.php.
- CVE-2024-483921 PoCOrangeScrum v2.0.11 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into user email due to…
- CVE-2024-484151 PoCitsourcecode Loan Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the lastname, firstname,…
- CVE-2024-484161 PoCEdimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/fromSetLanDhcpsClientbinding.
- CVE-2024-484171 PoCEdimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Cross Site Scripting (XSS) in : /bin/goahead via…
- CVE-2024-484181 PoCIn Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in…
- CVE-2024-484191 PoCEdimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues…
- CVE-2024-484201 PoCEdimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/getWifiBasic.
- CVE-2024-484231 PoCAn issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp…
- CVE-2024-484241 PoCA heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library,…
- CVE-2024-484251 PoCA segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library…
- CVE-2024-484261 PoCA segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing with…
- CVE-2024-484271 PoCA SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute…
- CVE-2024-484451 PoCAn issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and ts parameters.
- CVE-2024-484552 PoCsAn issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63…
- CVE-2024-484561 PoCAn issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63…
- CVE-2024-484571 PoCAn issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63…
- CVE-2024-484631 PoCBruno before 1.29.1 uses Electron shell.openExternal without validation (of http or https) for opening windows within the Markdown docs…
- CVE-2024-485101 PoCDirectory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code via the…
- CVE-2024-485141 PoCphp-heic-to-jpg <= 1.0.5 is vulnerable to code injection (fixed in 1.0.6). An attacker who can upload heic images is able to execute code…
- CVE-2024-485701 PoCClient Management System 1.0 was discovered to contain a SQL injection vulnerability via the Between Dates Reports parameter at…
- CVE-2024-485731 PoCA NoSQL injection vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to reset user and administrator account…
- CVE-2024-485791 PoCSQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code…
- CVE-2024-485801 PoCSQL Injection vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the…
- CVE-2024-485811 PoCFile Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the…
- CVE-2024-485901 PoCInflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an attacker to…
- CVE-2024-485911 PoCInflectra SpiraTeam 7.2.00 is vulnerable to Cross Site Scripting (XSS). A specially crafted SVG file can be uploaded that will render and…
- CVE-2024-485942 PoCsFile Upload vulnerability in Prison Management System v.1.0 allows a remote attacker to execute arbitrary code via the file upload…
- CVE-2024-486051 PoCAn issue in Helakuru Desktop Application v1.1 allows a local attacker to execute arbitrary code via the lack of proper validation of the…
- CVE-2024-486151 PoCNull Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at…
- CVE-2024-486222 PoCsA cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via…
- CVE-2024-486232 PoCsIn queue\index.php of DomainMOD below v4.12.0, the list_id and domain_id parameters in the GET request can be exploited to cause a…
- CVE-2024-486242 PoCsIn segments\edit.php of DomainMOD below v4.12.0, the segid parameter in the GET request can be exploited to cause a reflected Cross Site…
- CVE-2024-486461 PoCAn Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files without proper…
- CVE-2024-486471 PoCA file disclosure vulnerability exists in Sage 1000 v7.0.0. This vulnerability allows remote attackers to retrieve arbitrary files from…
- CVE-2024-486481 PoCA Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0. This vulnerability allows attackers to inject…
- CVE-2024-486511 PoCIn ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of…
- CVE-2024-486521 PoCCross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the content group name…
- CVE-2024-486552 PoCsAn issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.
- CVE-2024-486591 PoCAn issue in DCME-320-L <=9.3.2.114 allows a remote attacker to execute arbitrary code via the log_u_umount.php component.
- CVE-2024-486941 PoCFile Upload vulnerability in Xi'an Daxi Information technology OfficeWeb365 v.8.6.1.0 and v7.18.23.0 allows a remote attacker to execute…
- CVE-2024-487051 PoCWavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection…
- CVE-2024-487061 PoCCollabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a)…
- CVE-2024-487071 PoCCollabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit within…
- CVE-2024-487081 PoCCollabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action = add/edit and in…
- CVE-2024-487091 PoCCodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the membershipType parameter in edit_type.php
- CVE-2024-487581 PoCdingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the addPro parameter of the component…
- CVE-2024-487602 PoCsAn issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a…
- CVE-2024-487662 PoCsNetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors…
- CVE-2024-488251 PoCTenda AC7 v.15.03.06.44 ate_ifconfig_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.
- CVE-2024-488261 PoCTenda AC7 v.15.03.06.44 ate_iwpriv_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.
- CVE-2024-488271 PoCAn issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the Change Password…
- CVE-2024-488392 PoCsRemote Code Execution, RCE
- CVE-2024-488401 PoCUnauthorized Access
- CVE-2024-488412 PoCsRemote Code Execution (RCE) Vulnerabilities
- CVE-2024-488441 PoCDenial of Service, DoS
- CVE-2024-488451 PoCWeak Password Rules/Strength
- CVE-2024-488461 PoCCross Side Request Forgery, CSRF
- CVE-2024-488491 PoCAuthentication and Authorization Issues
- CVE-2024-488521 PoCInformation disclosures
- CVE-2024-488772 PoCsA memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility version 0.95. A…
- CVE-2024-488872 PoCsA unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin…
- CVE-2024-488951 PoCImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Rakuten Turbo 5G firmware…
- CVE-2024-489051 PoCSematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint.
- CVE-2024-489061 PoCSematell ReplyOne 7.4.3.0 allows XSS via a ReplyDesk e-mail attachment name.
- CVE-2024-489071 PoCSematell ReplyOne 7.4.3.0 allows SSRF via the application server API.
- CVE-2024-489102 PoCsDOMPurify vulnerable to tampering by prototype polution
- CVE-2024-489132 PoCsHono vulnerable to bypass of CSRF Middleware by a request without Content-Type header.
- CVE-2024-489143 PoCsVendure asset server plugin has local file read vulnerability with AssetServerPlugin & LocalAssetStorageStrategy
- CVE-2024-489172 PoCsXXE in PHPSpreadsheet's XLSX reader
- CVE-2024-489211 PoCKyverno's PolicyException objects can be created in any namespace by default
- CVE-2024-489301 PoCsecp256k1-node vulnerable to private key extraction over ECDH
- CVE-2024-489311 PoCZimaOS Arbitrary File Read via Parameter Manipulation
- CVE-2024-489321 PoCZimaOS Unauthenticated API Discloses Usernames
- CVE-2024-489481 PoCThe Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains…
- CVE-2024-489551 PoCBroken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus,…
- CVE-2024-489571 PoCexecute_filter_audio in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive…
- CVE-2024-489581 PoCexecute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive…
- CVE-2024-489871 PoCSnipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is…
- CVE-2024-4899022 PoCsQualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart…