CVE-2024-4000 to CVE-2024-4999
370 CVEs with public proof-of-concept exploits.
- CVE-2024-40021 PoCCarousel, Slider, Gallery by WP Carousel < 2.6.9 - Editor+ Stored XSS
- CVE-2024-40041 PoCAdvanced Cron Manager < 2.5.7 - Admin+ Stored XSS
- CVE-2024-40051 PoCSocial Pixel <= 2.1 - Admin+ Stored XSS
- CVE-2024-40071 PoCHard coded default credential contained in install package
- CVE-2024-40111 PoCImproper Access Control in GitLab
- CVE-2024-40191 PoCByzoro Smart S80 Management Platform importhtml.php deserialization
- CVE-2024-40201 PoCTenda FH1206 addressNat fromAddressNat buffer overflow
- CVE-2024-40211 PoCKeenetic KN-1010/KN-1410/KN-1711/KN-1810/KN-1910 Configuration Setting ndmComponents.js information disclosure
- CVE-2024-40221 PoCKeenetic KN-1010/KN-1410/KN-1711/KN-1810/KN-1910 Version Data version.js information disclosure
- CVE-2024-40251 PoCInefficient Regular Expression Complexity in GitLab
- CVE-2024-404026 PoCsKEVUnauthenticated arbitrary file read and remote code execution in CrushFTP
- CVE-2024-40411 PoCYoast SEO <= 22.5 - Reflected Cross-Site Scripting
- CVE-2024-40571 PoCGutenberg Blocks by Kadence Blocks < 3.2.37 - Contributor+ Stored XSS
- CVE-2024-40611 PoCSurvey Maker < 4.2.9 - Admin+ Stored XSS via Plugin Settings
- CVE-2024-40641 PoCTenda AC8 execCommand R7WebsSecurityHandler stack-based overflow
- CVE-2024-40651 PoCTenda AC8 SetRebootTimer formSetRebootTimer stack-based overflow
- CVE-2024-40661 PoCTenda AC8 AdvSetMacMtuWan fromAdvSetMacMtuWan stack-based overflow
- CVE-2024-40671 PoCRegular Expression Denial of Service in micromatch
- CVE-2024-40681 PoCMemory Exhaustion in braces
- CVE-2024-40691 PoCKashipara Online Furniture Shopping Ecommerce Website search.php sql injection
- CVE-2024-40701 PoCKashipara Online Furniture Shopping Ecommerce Website prodList.php sql injection
- CVE-2024-40711 PoCKashipara Online Furniture Shopping Ecommerce Website prodInfo.php sql injection
- CVE-2024-40721 PoCKashipara Online Furniture Shopping Ecommerce Website search.php cross site scripting
- CVE-2024-40731 PoCKashipara Online Furniture Shopping Ecommerce Website prodList.php cross site scripting
- CVE-2024-40741 PoCKashipara Online Furniture Shopping Ecommerce Website prodInfo.php cross site scripting
- CVE-2024-40751 PoCKashipara Online Furniture Shopping Ecommerce Website login.php cross site scripting
- CVE-2024-40901 PoCMy Sticky Bar < 2.7.2 - Admin+ Stored XSS
- CVE-2024-40911 PoCResponsive Gallery Grid < 2.3.15 - Admin+ Stored XSS
- CVE-2024-40931 PoCSourceCodester Simple Subscription Website view_application.php sql injection
- CVE-2024-40941 PoCSimple Share Buttons Adder < 8.5.1 - Admin+ Stored XSS
- CVE-2024-40961 PoCResponsive Tabs <= 4.0.8 - Contributor+ Stored XSS
- CVE-2024-40991 PoCImproper Encoding or Escaping of Output in GitLab
- CVE-2024-41111 PoCTenda TX9 SetLEDCfg sub_42BD7C stack-based overflow
- CVE-2024-41121 PoCTenda TX9 SetVirtualServerCfg sub_42CB94 stack-based overflow
- CVE-2024-41131 PoCTenda TX9 SetSysTimeCfg sub_42D4DC stack-based overflow
- CVE-2024-41141 PoCTenda TX9 PowerSaveSet sub_42C014 stack-based overflow
- CVE-2024-41151 PoCTenda W15E AddDnsForward formAddDnsForward stack-based overflow
- CVE-2024-41161 PoCTenda W15E DelDhcpRule formDelDhcpRule stack-based overflow
- CVE-2024-41171 PoCTenda W15E DelPortMapping formDelPortMapping stack-based overflow
- CVE-2024-41181 PoCTenda W15E addIpMacBind formIPMacBindAdd stack-based overflow
- CVE-2024-41191 PoCTenda W15E delIpMacBind formIPMacBindDel stack-based overflow
- CVE-2024-41201 PoCTenda W15E modifyIpMacBind formIPMacBindModify stack-based overflow
- CVE-2024-41211 PoCTenda W15E formQOSRuleDel stack-based overflow
- CVE-2024-41221 PoCTenda W15E setDebugCfg formSetDebugCfg stack-based overflow
- CVE-2024-41231 PoCTenda W15E SetPortMapping formSetPortMapping stack-based overflow
- CVE-2024-41241 PoCTenda W15E SetRemoteWebManage formSetRemoteWebManage stack-based overflow
- CVE-2024-41251 PoCTenda W15E setStaticRoute formSetStaticRoute stack-based overflow
- CVE-2024-41261 PoCTenda W15E SetSysTimeCfg formSetSysTime stack-based overflow
- CVE-2024-41271 PoCTenda W15E guestWifiRuleRefresh stack-based overflow
- CVE-2024-41451 PoCSearch & Replace < 3.2.2 - Admin+ SQL injection
- CVE-2024-41491 PoCFloating Chat Widget < 3.2.3 - Admin+ Stored XSS
- CVE-2024-41571 PoCContact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.15 - PHP Object Injection via…
- CVE-2024-41641 PoCTenda G3 ModifyPppAuthWhiteMac formModifyPppAuthWhiteMac stack-based overflow
- CVE-2024-41651 PoCTenda G3 modifyDhcpRule stack-based overflow
- CVE-2024-41661 PoCTenda 4G300 sub_41E858 stack-based overflow
- CVE-2024-41671 PoCTenda 4G300 sub_422AA4 stack-based overflow
- CVE-2024-41681 PoCTenda 4G300 sub_4260F0 stack-based overflow
- CVE-2024-41691 PoCTenda 4G300 sub_4279CC stack-based overflow
- CVE-2024-41701 PoCTenda 4G300 sub_429A30 stack-based overflow
- CVE-2024-41711 PoCTenda W30E WizardHandle fromWizardHandle stack-based overflow
- CVE-2024-41721 PoCidcCMS cross-site request forgery
- CVE-2024-41802 PoCsThe Events Calendar < 6.4.0.1 - Reflected XSS
- CVE-2024-42011 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2024-42071 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2024-42101 PoCUncontrolled Resource Consumption in GitLab
- CVE-2024-42171 PoCShortcodes Ultimate Pro < 7.1.5 - Contributor+ Stored Cross-Site Scripting XSS
- CVE-2024-42312 PoCsIncorrect Access Control Vulnerability in Digisol Router
- CVE-2024-42324 PoCsPassword Storage in Plaintext Vulnerability in Digisol Router
- CVE-2024-42351 PoCNetgear DG834Gv5 Web Management Interface cleartext storage
- CVE-2024-42361 PoCTenda AX1803 SetDDNSCfg formSetSysToolDDNS stack-based overflow
- CVE-2024-42371 PoCTenda AX1806 execCommand R7WebsSecurityHandler stack-based overflow
- CVE-2024-42381 PoCTenda AX1806 SetOnlineDevName formSetDeviceName stack-based overflow
- CVE-2024-42391 PoCTenda AX1806 SetRebootTimer formSetRebootTimer stack-based overflow
- CVE-2024-42421 PoCTenda W9 wifiSSIDget formwrlSSIDget stack-based overflow
- CVE-2024-42431 PoCTenda W9 wifiSSIDset formwrlSSIDset stack-based overflow
- CVE-2024-42441 PoCTenda W9 DhcpSetSer fromDhcpSetSer stack-based overflow
- CVE-2024-42491 PoCTenda i21 wifiSSIDget formwrlSSIDget stack-based overflow
- CVE-2024-42501 PoCTenda i21 wifiSSIDset formwrlSSIDset stack-based overflow
- CVE-2024-42511 PoCTenda i21 DhcpSetSe fromDhcpSetSer stack-based overflow
- CVE-2024-42551 PoCRuijie RG-UAC gre_edit_commit.php os command injection
- CVE-2024-42572 PoCsBlueNet Technology Clinical Browsing System deleteStudy.php sql injection
- CVE-2024-42601 PoCCoBlocks < 3.1.12 - Contributor+ SSRF
- CVE-2024-42691 PoCSVG Block < 1.1.20 - Author+ Stored XSS via SVG File Upload
- CVE-2024-42701 PoCSVGMagic <= 1.1 - Stored XSS via SVG Upload
- CVE-2024-42711 PoCSVGator <= 1.2.6 - Stored XSS via SVG Upload
- CVE-2024-42721 PoCSupport SVG < 1.1.0 - Stored XSS via SVG Upload
- CVE-2024-42781 PoCIncorrect Synchronization in GitLab
- CVE-2024-42831 PoCURL Redirection to Untrusted Site ('Open Redirect') in GitLab
- CVE-2024-42891 PoCSailthru Triggermail <= 1.1 - Reflected XSS
- CVE-2024-42901 PoCSailthru Triggermail <= 1.1 - Admin+ Stored XSS
- CVE-2024-42911 PoCTenda A301 setBlackRule formAddMacfilterRule stack-based overflow
- CVE-2024-42921 PoCContemporary Controls BASrouter BACnet BASRT-B Device-Communication-Control Service denial of service
- CVE-2024-42931 PoCPHPGurukul Doctor Appointment Management System appointment-bwdates-reports-details.php cross site scripting
- CVE-2024-42941 PoCPHPGurukul Doctor Appointment Management System view-appointment-detail.php resource injection
- CVE-2024-42954 PoCsEmail Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via hash
- CVE-2024-43051 PoCPostX < 4.1.0 - Contributor+ Stored XSS
- CVE-2024-43201 PoCRemote Code Execution due to LFI in '/install_extension' in parisneo/lollms-webui
- CVE-2024-43222 PoCsPath Traversal in parisneo/lollms-webui
- CVE-2024-43234 PoCsFluent Bit Memory Corruption Vulnerability
- CVE-2024-43251 PoCServer-Side Request Forgery (SSRF) in gradio-app/gradio
- CVE-2024-43271 PoCApryse WebViewer PDF Document cross site scripting
- CVE-2024-43401 PoCPassing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError.
- CVE-2024-43481 PoCosCommerce all-products cross site scripting
- CVE-2024-43491 PoCSourceCodester Pisay Online E-Learning System controller.php unrestricted upload
- CVE-2024-43511 PoCTutor LMS Pro <= 2.7.0 - Missing Authorization to Privilege Escalation
- CVE-2024-435810 PoCsKEVRegistration Authentication Bypass Vulnerability
- CVE-2024-436729 PoCsA type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This…
- CVE-2024-43721 PoCCarousel Slider < 2.2.11 - Editor+ Stored XSS
- CVE-2024-43771 PoCDOP Shortcodes <= 1.2 - Contributor+ Stored XSS via Shortcode
- CVE-2024-43811 PoCCB (legacy) <= 0.9.4.18 - Admin+ Stored XSS
- CVE-2024-43821 PoCCB (legacy) <= 0.9.4.18 - Code/Timeframe/Booking Deletion via CSRF
- CVE-2024-43841 PoCCSSable Countdown <= 1.5 - Admin+ Stored XSS
- CVE-2024-43881 PoCCAS <= 1.0.0 - Unauthenticated Arbitrary File Access
- CVE-2024-43992 PoCsCAS <= 1.0.0 - Unauthenticated SSRF
- CVE-2024-44061 PoCXiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability
- CVE-2024-44341 PoCLearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injection
- CVE-2024-44396 PoCsWordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due…
- CVE-2024-44432 PoCsBusiness Directory Plugin – Easy Listing Directories for WordPress <= 6.4.2 - Unauthenticated SQL Injection via listingfields Parameter
- CVE-2024-44551 PoCYITH WooCommerce Ajax Search <= 2.4.0 - Unauthenticated Stored Cross-Site Scripting
- CVE-2024-44691 PoCMigration Backup Restore < 3.5.0 - Admin+ SSRF
- CVE-2024-44721 PoCInsertion of Sensitive Information into Log File in GitLab
- CVE-2024-44741 PoCWP Logs Book <= 1.0.1 - Disable Logging via CSRF
- CVE-2024-44751 PoCWP Logs Book <= 1.0.1 - Log Clearing via CSRF
- CVE-2024-44771 PoCWP Logs Book <= 1.0.1 - Unauthenticated Stored XSS
- CVE-2024-44801 PoCWP Prayer II <= 2.4.7 - Email Settings Update via CSRF
- CVE-2024-44831 PoCEmail Encoder < 2.2.2 - Admin+ Stored XSS
- CVE-2024-44911 PoCTenda i21 formGetDiagnoseInfo stack-based overflow
- CVE-2024-44921 PoCTenda i21 setStaOffline formOfflineSet stack-based overflow
- CVE-2024-44931 PoCTenda i21 formSetAutoPing stack-based overflow
- CVE-2024-44941 PoCTenda i21 setUplinkInfo formSetUplinkInfo stack-based overflow
- CVE-2024-44951 PoCTenda i21 formWifiMacFilterGet stack-based overflow
- CVE-2024-44961 PoCTenda i21 formWifiMacFilterSet stack-based overflow
- CVE-2024-44971 PoCTenda i21 formexeCommand stack-based overflow
- CVE-2024-45001 PoCSourceCodester Prison Management System edit-photo.php unrestricted upload
- CVE-2024-45011 PoCRuijie RG-UAC commit.php os command injection
- CVE-2024-45021 PoCRuijie RG-UAC dhcp_client_commit.php os command injection
- CVE-2024-45031 PoCRuijie RG-UAC dhcp_relay_commit.php os command injection
- CVE-2024-45041 PoCRuijie RG-UAC commit.php os command injection
- CVE-2024-45051 PoCRuijie RG-UAC ip_addr_add_commit.php os command injection
- CVE-2024-45061 PoCRuijie RG-UAC ip_addr_edit_commit.php os command injection
- CVE-2024-45071 PoCRuijie RG-UAC static_route_add_ipv6.php os command injection
- CVE-2024-45081 PoCRuijie RG-UAC static_route_edit_ipv6.php os command injection
- CVE-2024-45091 PoCRuijie RG-UAC add_commit.php os command injection
- CVE-2024-45101 PoCRuijie RG-UAC arp_add_commit.php os command injection
- CVE-2024-45111 PoCShanghai Sunfull Automation BACnet Server HMI1002-ARM Message buffer overflow
- CVE-2024-45121 PoCSourceCodester Prison Management System edit-profile.php cross site scripting
- CVE-2024-45131 PoCCampcodes Complete Web-Based School Management System timetable_update_form.php cross site scripting
- CVE-2024-45141 PoCCampcodes Complete Web-Based School Management System timetable_insert_form.php cross site scripting
- CVE-2024-45151 PoCCampcodes Complete Web-Based School Management System timetable_grade_wise.php cross site scripting
- CVE-2024-45161 PoCCampcodes Complete Web-Based School Management System timetable.php cross site scripting
- CVE-2024-45171 PoCCampcodes Complete Web-Based School Management System teacher_salary_invoice1.php cross site scripting
- CVE-2024-45181 PoCCampcodes Complete Web-Based School Management System teacher_salary_invoice.php cross site scripting
- CVE-2024-45191 PoCCampcodes Complete Web-Based School Management System teacher_salary_details3.php cross site scripting
- CVE-2024-45211 PoCCampcodes Complete Web-Based School Management System teacher_salary_details2.php cross site scripting
- CVE-2024-45221 PoCCampcodes Complete Web-Based School Management System teacher_salary_details.php cross site scripting
- CVE-2024-45231 PoCCampcodes Complete Web-Based School Management System teacher_attendance_history1.php cross site scripting
- CVE-2024-45241 PoCCampcodes Complete Web-Based School Management System student_payment_invoice.php cross site scripting
- CVE-2024-45251 PoCCampcodes Complete Web-Based School Management System student_payment_details4.php cross site scripting
- CVE-2024-45261 PoCCampcodes Complete Web-Based School Management System student_payment_details3.php cross site scripting
- CVE-2024-45271 PoCCampcodes Complete Web-Based School Management System student_payment_details2.php cross site scripting
- CVE-2024-45281 PoCSourceCodester Prison Management System user-record.php cross site scripting
- CVE-2024-45291 PoCBusiness Card <= 1.0.0 - Category Deletion via CSRF
- CVE-2024-45301 PoCBusiness Card <= 1.0.0 - Category Edit via CSRF
- CVE-2024-45311 PoCBusiness Card <= 1.0.0 - Card Edit via CSRF
- CVE-2024-45321 PoCBusiness Card <= 1.0.0 - Arbitrary Card Deletion via CSRF
- CVE-2024-45331 PoCKKProgressbar2 Free <= 1.1.4.2 - Admin+ SQL Injection
- CVE-2024-45341 PoCKKProgressbar2 Free <= 1.1.4.2 - Stored XSS via CSRF
- CVE-2024-45351 PoCKKProgressbar2 Free <= 1.1.4.2 - Progress Bar Deletion via CSRF
- CVE-2024-45471 PoCDelta Electronics DIAEnergie Unauthenticated SQL Injection
- CVE-2024-45482 PoCsDelta Electronics DIAEnergie SQL Injection
- CVE-2024-45491 PoCDelta Electronics DIAEnergie SQL Injection
- CVE-2024-45571 PoCUncontrolled Resource Consumption in GitLab
- CVE-2024-45581 PoCUse after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2024-45651 PoCAdvanced Custom Fields < 6.3 - Contributor+ Custom Field Access
- CVE-2024-457780 PoCsKEVArgument Injection in PHP-CGI
- CVE-2024-45821 PoCFaraday GM8181/GM828x NTP Service os command injection
- CVE-2024-45831 PoCFaraday GM8181/GM828x Request information disclosure
- CVE-2024-45841 PoCFaraday GM8181/GM828x command_port.ini information disclosure
- CVE-2024-45851 PoCDedeCMS member_type.php cross-site request forgery
- CVE-2024-45861 PoCDedeCMS shops_delivery.php cross-site request forgery
- CVE-2024-45871 PoCDedeCMS tpl.php cross-site request forgery
- CVE-2024-45881 PoCDedeCMS mytag_add.php cross-site request forgery
- CVE-2024-45891 PoCDedeCMS mytag_edit.php cross-site request forgery
- CVE-2024-45901 PoCDedeCMS sys_info.php cross-site request forgery
- CVE-2024-45911 PoCDedeCMS sys_group_add.php cross-site request forgery
- CVE-2024-45921 PoCDedeCMS sys_group_edit.php cross-site request forgery
- CVE-2024-45931 PoCDedeCMS sys_multiserv.php cross-site request forgery
- CVE-2024-45941 PoCDedeCMS sys_safe.php cross-site request forgery
- CVE-2024-45951 PoCSEMCMS function.php locate sql injection
- CVE-2024-46021 PoCEmbed Peertube Playlist < 1.10 - Editor+ Stored XSS
- CVE-2024-46121 PoCURL Redirection to Untrusted Site ('Open Redirect') in GitLab
- CVE-2024-46161 PoCWidget Bundle <= 2.0.0 - Unauthencated Reflected XSS
- CVE-2024-46202 PoCsArForms < 6.6 - Unauthenticated RCE
- CVE-2024-46211 PoCArForms < 6.6 - Admin+ Stored XSS
- CVE-2024-46271 PoCRank Math SEO < 1.0.219 - Authenticated Stored XSS
- CVE-2024-46441 PoCSourceCodester Prison Management System changepassword.php cross site scripting
- CVE-2024-46451 PoCSourceCodester Prison Management System changepassword.php cross site scripting
- CVE-2024-46461 PoCCampcodes Complete Web-Based School Management System student_payment_details.php cross site scripting
- CVE-2024-46471 PoCCampcodes Complete Web-Based School Management System student_first_payment.php cross site scripting
- CVE-2024-46481 PoCCampcodes Complete Web-Based School Management System student_exam_mark_update_form.php cross site scripting
- CVE-2024-46491 PoCCampcodes Complete Web-Based School Management System student_exam_mark_insert_form1.php cross site scripting
- CVE-2024-46501 PoCCampcodes Complete Web-Based School Management System student_due_payment.php cross site scripting
- CVE-2024-46511 PoCCampcodes Complete Web-Based School Management System student_attendance_history1.php cross site scripting
- CVE-2024-46521 PoCCampcodes Complete Web-Based School Management System show_teacher2.php cross site scripting
- CVE-2024-46531 PoCBlueNet Technology Clinical Browsing System outIndex.php sql injection
- CVE-2024-46541 PoCBlueNet Technology Clinical Browsing System cloudInterface.php sql injection
- CVE-2024-46551 PoCUltimate Blocks < 3.1.9 - Contributor+ Stored XSS
- CVE-2024-46601 PoCMissing Authorization in GitLab
- CVE-2024-46641 PoCWP Chat App < 3.6.5 - Admin+ Stored XSS
- CVE-2024-46651 PoCEventPrime – Events Calendar, Bookings and Tickets < 3.5.0 - Subscriber+ Arbitrary booking settings update
- CVE-2024-46721 PoCCampcodes Complete Web-Based School Management System show_student_subject.php cross site scripting
- CVE-2024-46731 PoCCampcodes Complete Web-Based School Management System show_student_grade_subject.php cross site scripting
- CVE-2024-46741 PoCCampcodes Complete Web-Based School Management System show_friend_request.php cross site scripting
- CVE-2024-46751 PoCCampcodes Complete Web-Based School Management System show_events.php cross site scripting
- CVE-2024-46761 PoCCampcodes Complete Web-Based School Management System range_grade_text.php cross site scripting
- CVE-2024-46771 PoCCampcodes Complete Web-Based School Management System my_student_exam_marks1.php cross site scripting
- CVE-2024-46781 PoCCampcodes Complete Web-Based School Management System find_friends.php cross site scripting
- CVE-2024-46811 PoCCampcodes Legal Case Management System Setting general-setting unrestricted upload
- CVE-2024-46821 PoCCampcodes Complete Web-Based School Management System exam_timetable_update_form.php cross site scripting
- CVE-2024-46831 PoCCampcodes Complete Web-Based School Management System exam_timetable_insert_form.php cross site scripting
- CVE-2024-46841 PoCCampcodes Complete Web-Based School Management System exam_timetable_grade_wise.php cross site scripting
- CVE-2024-46851 PoCCampcodes Complete Web-Based School Management System exam_timetable.php cross site scripting
- CVE-2024-46861 PoCCampcodes Complete Web-Based School Management System emarks_range_grade_update_form.php cross site scripting
- CVE-2024-46871 PoCCampcodes Complete Web-Based School Management System create_events.php cross site scripting
- CVE-2024-46881 PoCCampcodes Complete Web-Based School Management System conversation_history_admin.php cross site scripting
- CVE-2024-46991 PoCD-Link DAR-8000-10 importhtml.php deserialization
- CVE-2024-47012 PoCsPath Traversal vulnerability via File Uploads in Genie
- CVE-2024-47041 PoCContact Form 7 < 5.9.5 - Unauthenticated Open Redirect
- CVE-2024-47131 PoCCampcodes Complete Web-Based School Management System all_teacher.php cross site scripting
- CVE-2024-47141 PoCCampcodes Complete Web-Based School Management System update_subject.php cross site scripting
- CVE-2024-47151 PoCCampcodes Complete Web-Based School Management System update_grade.php cross site scripting
- CVE-2024-47161 PoCCampcodes Complete Web-Based School Management System update_exam.php cross site scripting
- CVE-2024-47171 PoCCampcodes Complete Web-Based School Management System update_classroom.php cross site scripting
- CVE-2024-47181 PoCCampcodes Complete Web-Based School Management System delete_student_grade_subject.php cross site scripting
- CVE-2024-47191 PoCCampcodes Complete Web-Based School Management System delete_record.php cross site scripting
- CVE-2024-47201 PoCCampcodes Complete Web-Based School Management System approve_petty_cash.php cross site scripting
- CVE-2024-47211 PoCCampcodes Complete Web-Based School Management System add_student_subject.php cross site scripting
- CVE-2024-47221 PoCCampcodes Complete Web-Based School Management System index.php cross site scripting
- CVE-2024-47231 PoCCampcodes Legal Case Management System case-status cross site scripting
- CVE-2024-47241 PoCCampcodes Legal Case Management System case-type cross site scripting
- CVE-2024-47251 PoCCampcodes Legal Case Management System client_user cross site scripting
- CVE-2024-47261 PoCCampcodes Legal Case Management System clients cross site scripting
- CVE-2024-47271 PoCCampcodes Legal Case Management System court-type cross site scripting
- CVE-2024-47281 PoCCampcodes Legal Case Management System court cross site scripting
- CVE-2024-47291 PoCCampcodes Legal Case Management System expense-type cross site scripting
- CVE-2024-47301 PoCCampcodes Legal Case Management System judge cross site scripting
- CVE-2024-47311 PoCCampcodes Legal Case Management System role cross site scripting
- CVE-2024-47321 PoCCampcodes Legal Case Management System service cross site scripting
- CVE-2024-47351 PoCCampcodes Legal Case Management System tasks cross site scripting
- CVE-2024-47361 PoCCampcodes Legal Case Management System tax cross site scripting
- CVE-2024-47371 PoCCampcodes Legal Case Management System vendor cross site scripting
- CVE-2024-47381 PoCCampcodes Legal Case Management System cross site scripting
- CVE-2024-47491 PoCWP eMember < 10.3.9 - Reflected XSS
- CVE-2024-47501 PoCBuddyBoss Platform < 2.6.0 - Insecure Direct Object Reference on Like Comment
- CVE-2024-47511 PoCWP Prayer II <= 2.4.7 - Settings Update via CSRF
- CVE-2024-47521 PoCEventON < 2.2.15 - Admin+ Stored Cross-Site Scripting via event subtitle
- CVE-2024-47531 PoCWP Secure Maintenance < 1.7 - Admin+ Stored XSS
- CVE-2024-47551 PoCGoogle CSE <= 1.0.7 - Admin+ Stored XSS
- CVE-2024-47561 PoCWP Backpack <= 2.1 - Admin+ Stored XSS
- CVE-2024-47571 PoCLogo Manager For Enamad <= 0.7.0 - Stored XSS via CSRF
- CVE-2024-47581 PoCMuslim Prayer Time BD <= 2.4 - Settings Reset via CSRF
- CVE-2024-47591 PoCMime Types Extended <= 0.11 - Author+ Stored XSS via SVG Upload
- CVE-2024-47601 PoCVoltage glitch during startup of the EEFC NVM controller can bypass the security bit
- CVE-2024-47612 PoCsKEVOut of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via…
- CVE-2024-47681 PoCA bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This…
- CVE-2024-47751 PoCAn iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid memory access and…
- CVE-2024-47841 PoCAuthentication Bypass by Primary Weakness in GitLab
- CVE-2024-47901 PoCDedeCMS path traversal
- CVE-2024-47911 PoCContemporary Control System BASrouter BACnet BASRT-B Application Protocol Data Unit denial of service
- CVE-2024-47921 PoCCampcodes Online Laundry Management System admin_class.php sql injection
- CVE-2024-47931 PoCCampcodes Online Laundry Management System manage_laundry.php sql injection
- CVE-2024-47941 PoCCampcodes Online Laundry Management System manage_receiving.php sql injection
- CVE-2024-47951 PoCCampcodes Online Laundry Management System manage_user.php sql injection
- CVE-2024-47961 PoCCampcodes Online Laundry Management System manage_inv.php sql injection
- CVE-2024-47971 PoCCampcodes Online Laundry Management System ajax.php cross site scripting
- CVE-2024-47981 PoCSourceCodester Online Computer and Laptop Store manage_brand.php sql injection
- CVE-2024-47991 PoCKashipara College Management System view_each_faculty.php sql injection
- CVE-2024-48001 PoCKashipara College Management System submit_student.php sql injection
- CVE-2024-48011 PoCKashipara College Management System submit_new_faculty.php sql injection
- CVE-2024-48021 PoCKashipara College Management System submit_extracurricular_activity.php sql injection
- CVE-2024-48031 PoCKashipara College Management System submit_admin.php sql injection
- CVE-2024-48041 PoCKashipara College Management System edit_user.php sql injection
- CVE-2024-48051 PoCKashipara College Management System edit_faculty.php sql injection
- CVE-2024-48061 PoCKashipara College Management System each_extracurricula_activities.php sql injection
- CVE-2024-48071 PoCKashipara College Management System delete_user.php sql injection
- CVE-2024-48081 PoCKashipara College Management System delete_faculty.php sql injection
- CVE-2024-48091 PoCSourceCodester Open Source Clinic Management System setting.php unrestricted upload
- CVE-2024-48131 PoCRuijie RG-UAC interface_commit.php os command injection
- CVE-2024-48141 PoCRuijie RG-UAC static_route_edit_commit.php os command injection
- CVE-2024-48151 PoCRuijie RG-UAC detail.php os command injection
- CVE-2024-48161 PoCRuijie RG-UAC gre_add_commit.php os command injection
- CVE-2024-48171 PoCCampcodes Online Laundry Management System HTTP Request Parameter manage_user.php resource injection
- CVE-2024-48181 PoCCampcodes Online Laundry Management System index.php file inclusion
- CVE-2024-48191 PoCCampcodes Online Laundry Management System admin_class.php improper authorization
- CVE-2024-48201 PoCSourceCodester Online Computer and Laptop Store unrestricted upload
- CVE-2024-48352 PoCsImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2024-48361 PoCLFI in sites managed by Edito CMS
- CVE-2024-48411 PoCPath Traversal in parisneo/lollms-webui
- CVE-2024-48531 PoCMismatched Memory Management Routines in editcap
- CVE-2024-48553 PoCsUse After Free in editcap
- CVE-2024-48561 PoCFS Product Inquiry <= 1.1.1 - Reflected XSS
- CVE-2024-48571 PoCFS Product Inquiry <= 1.1.1 - Unauthenticated Stored XSS
- CVE-2024-48601 PoCThe 'WordPress RSS Aggregator' WordPress Plugin, versions < 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerability due to the…
- CVE-2024-48751 PoCHT Mega – Absolute Addons For Elementor <= 2.5.2 - Missing Authorization to Options Update
- CVE-2024-487913 PoCsKEVJelly Template Injection Vulnerability in ServiceNow UI Macros
- CVE-2024-48831 PoCWhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability
- CVE-2024-48852 PoCsKEVWhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability
- CVE-2024-48861 PoCBuddyBoss Platform < 2.6.0 - Subscriber+ Comment on Private Post via IDOR
- CVE-2024-48983 PoCsInstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.38 - Missing Authorization to Unauthenticated API setup/Arbitrary Options…
- CVE-2024-48991 PoCSEOPress < 7.8 - Contributor+ Stored XSS
- CVE-2024-49001 PoCSEOPress < 7.8 - Contributor+ Open Redirect
- CVE-2024-49011 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2024-49031 PoCTongda OA delete.php sql injection
- CVE-2024-49041 PoCByzoro Smart S200 Management Platform userattestation.php unrestricted upload
- CVE-2024-49051 PoCKashipara College Management System view_students_each_detail.php sql injection
- CVE-2024-49061 PoCCampcodes Complete Web-Based School Management System show_student1.php sql injection
- CVE-2024-49071 PoCCampcodes Complete Web-Based School Management System show_student2.php sql injection
- CVE-2024-49081 PoCCampcodes Complete Web-Based School Management System student_attendance_history1.php sql injection
- CVE-2024-49091 PoCCampcodes Complete Web-Based School Management System student_due_payment.php sql injection
- CVE-2024-49101 PoCCampcodes Complete Web-Based School Management System student_exam_mark_insert_form1.php sql injection
- CVE-2024-49111 PoCCampcodes Complete Web-Based School Management System student_exam_mark_update_form.php sql injection
- CVE-2024-49121 PoCCampcodes Online Examination System addExamExe.php sql injection
- CVE-2024-49131 PoCCampcodes Online Examination System exam.php sql injection
- CVE-2024-49141 PoCCampcodes Online Examination System ranking-exam.php sql injection
- CVE-2024-49151 PoCCampcodes Online Examination System result.php sql injection
- CVE-2024-49161 PoCCampcodes Online Examination System selExamAttemptExe.php sql injection
- CVE-2024-49171 PoCCampcodes Online Examination System submitAnswerExe.php sql injection
- CVE-2024-49181 PoCCampcodes Online Examination System updateQuestion.php sql injection
- CVE-2024-49191 PoCCampcodes Online Examination System addCourseExe.php sql injection
- CVE-2024-49201 PoCSourceCodester Online Discussion Forum Site registerH.php unrestricted upload
- CVE-2024-49211 PoCSourceCodester Employee and Visitor Gate Pass Logging System unrestricted upload
- CVE-2024-49221 PoCSourceCodester Simple Image Stack Website cross site scripting
- CVE-2024-49231 PoCCodezips E-Commerce Site addproduct.php unrestricted upload
- CVE-2024-49241 PoCSassy social share < 3.3.63 Admin+ Stored Cross-Site scripting
- CVE-2024-49251 PoCSourceCodester School Intramurals Student Attendance Management System manage_course.php sql injection
- CVE-2024-49261 PoCSourceCodester School Intramurals Student Attendance Management System manage_student.php sql injection
- CVE-2024-49271 PoCSourceCodester Simple Online Bidding System unrestricted upload
- CVE-2024-49281 PoCSourceCodester Simple Online Bidding System sql injection
- CVE-2024-49291 PoCSourceCodester Simple Online Bidding System cross-site request forgery
- CVE-2024-49301 PoCSourceCodester Simple Online Bidding System sql injection
- CVE-2024-49311 PoCSourceCodester Simple Online Bidding System sql injection
- CVE-2024-49321 PoCSourceCodester Simple Online Bidding System sql injection
- CVE-2024-49331 PoCSourceCodester Simple Online Bidding System sql injection
- CVE-2024-49341 PoCQuiz And Survey Master < 9.0.2 - Contributor+ Stored XSS
- CVE-2024-49401 PoCOpen Redirect in gradio-app/gradio
- CVE-2024-49451 PoCSourceCodester Best Courier Management System view_parcel.php unrestricted upload
- CVE-2024-49461 PoCSourceCodester Online Art Gallery Management System adminHome.php unrestricted upload
- CVE-2024-49472 PoCsKEVType Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a…
- CVE-2024-49501 PoCInappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage…
- CVE-2024-495622 PoCsNexus Repository 3 - Path Traversal
- CVE-2024-49571 PoCFrontend Checklist <= 2.3.2 - Admin+ Stored XSS
- CVE-2024-49591 PoCFrontend Checklist <= 2.3.2 - Admin+ Stored XSS via Items
- CVE-2024-49601 PoCD-Link DAR-7000-40 licenseauthorization.php unrestricted upload
- CVE-2024-49611 PoCD-Link DAR-7000-40 onlineuser.php unrestricted upload
- CVE-2024-49621 PoCD-Link DAR-7000-40 resmanage.php unrestricted upload
- CVE-2024-49631 PoCD-Link DAR-7000-40 url.php unrestricted upload
- CVE-2024-49641 PoCD-Link DAR-7000-40 urlblist.php unrestricted upload
- CVE-2024-49651 PoCD-Link DAR-7000-40 resmanage.php os command injection
- CVE-2024-49661 PoCSourceCodester SchoolWebTech home.php unrestricted upload
- CVE-2024-49671 PoCSourceCodester Interactive Map with Marker delete-mark.php sql injection
- CVE-2024-49681 PoCSourceCodester Interactive Map with Marker Add Marker Marker Name cross site scripting
- CVE-2024-49691 PoCWidget Bundle <= 2.0.0 - Widget Disable/Enable via CSRF
- CVE-2024-49701 PoCWidget Bundle <= 2.0.0 - Admin+ Stored XSS
- CVE-2024-49721 PoCcode-projects Simple Chat System login.php sql injection
- CVE-2024-49731 PoCcode-projects Simple Chat System register.php sql injection
- CVE-2024-49741 PoCcode-projects Simple Chat System register.php cross site scripting
- CVE-2024-49751 PoCcode-projects Simple Chat System Message cross site scripting
- CVE-2024-49771 PoCIndex WP MySQL For Speed < 1.4.18 - Admin+ Reflected XSS
- CVE-2024-49901 PoCUnsafe Reflection in base Component class in yiisoft/yii2
- CVE-2024-49941 PoCCross-Site Request Forgery (CSRF) in GitLab