CVE-2024-49000 to CVE-2024-49999
37 CVEs with public proof-of-concept exploits.
- CVE-2024-490191 PoCActive Directory Certificate Services Elevation of Privilege Vulnerability
- CVE-2024-490392 PoCsKEVWindows Task Scheduler Elevation of Privilege Vulnerability
- CVE-2024-490491 PoCVisual Studio Code Remote Extension Elevation of Privilege Vulnerability
- CVE-2024-491123 PoCsWindows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- CVE-2024-491134 PoCsWindows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
- CVE-2024-491387 PoCsKEVWindows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2024-491941 PoCDatabricks JDBC Driver 2.x before 2.6.40 could potentially allow remote code execution (RCE) by triggering a JNDI injection via a JDBC URL…
- CVE-2024-492031 PoCQuerydsl 5.1.0 and OpenFeign Querydsl 6.8 allows SQL/HQL injection in orderBy in JPAQuery. NOTE: this is disputed by a Querydsl community…
- CVE-2024-493282 PoCsWordPress WP REST API FNS Plugin plugin <= 1.0.0 - Account Takeover vulnerability
- CVE-2024-493572 PoCsZimaOS (Installed Applications and System Information) has Unauthorized Sensitive Data Leak
- CVE-2024-493581 PoCZimaOS vulnerable to Username Enumeration via API Responses
- CVE-2024-493591 PoCZimaOS vulnerable to Directory Listing via Parameter Manipulation
- CVE-2024-493601 PoCPath traversal in Sandboxie
- CVE-2024-493622 PoCsRemote Code Execution on click of <a> Link in markdown preview
- CVE-2024-493641 PoCtiny-secp256k1 vulnerable to private key extraction when signing a malicious JSON-stringifyable message in bundled environment
- CVE-2024-493651 PoCtiny-secp256k1 allows for verify() bypass when running in bundled environment
- CVE-2024-493661 PoCNginx UI's json field can construct a directory traversal payload, causing arbitrary files to be written
- CVE-2024-493682 PoCsUnchecked logrotate settings lead to arbitrary command execution
- CVE-2024-493691 PoCIcinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connections
- CVE-2024-493701 PoCChange-Password via Portal-Profile sets PimcoreBackendUser password without hashing
- CVE-2024-493791 PoCRemote Code Execution (RCE) via Cross-Site Scripting (XSS) in Umbrel
- CVE-2024-493801 PoCPlenti arbitrary file write vulnerability
- CVE-2024-495762 PoCsA use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a checkbox CBF_Widget object. A specially crafted…
- CVE-2024-496071 PoCWordPress WP Dropbox Dropins plugin <= 1.0 - Arbitrary File Upload vulnerability
- CVE-2024-496531 PoCWordPress Portfolleo plugin <= 1.2 - Arbitrary File Upload vulnerability
- CVE-2024-496681 PoCWordPress Verbalize WP plugin <= 1.0 - Arbitrary File Upload vulnerability
- CVE-2024-496811 PoCWordPress WP Sessions Time Monitoring Full Automatic plugin <= 1.0.9 - SQL Injection vulnerability
- CVE-2024-496991 PoCWordPress ARPrice plugin <= 4.1.3 - PHP Object Injection vulnerability
- CVE-2024-497542 PoCsLibreNMS has a stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/api-access.inc.php
- CVE-2024-497571 PoCZitadel User Registration Bypass Vulnerability
- CVE-2024-497581 PoCLibreNMS has a stored XSS in ExamplePlugin with Device's Notes
- CVE-2024-497592 PoCsLibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/edituser.inc.php
- CVE-2024-497642 PoCsLibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/capture.inc.php
- CVE-2024-497761 PoCA negative-size-param in tsMuxer version nightly-2024-04-05-01-53-02 allows attackers to cause Denial of Service (DoS) via a crafted TS…
- CVE-2024-497771 PoCA heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service (DoS), Information…
- CVE-2024-497781 PoCA heap-based buffer overflow in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Service (DoS) and Code…
- CVE-2024-498821 PoCext4: fix double brelse() the buffer of the extents path