CVE-2024-50000 to CVE-2024-50999
75 CVEs with public proof-of-concept exploits.
- CVE-2024-502511 PoCnetfilter: nft_payload: sanitize offset and length before calling skb_checksum()
- CVE-2024-503301 PoCSQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote…
- CVE-2024-503341 PoCSemicolon Path Injection on API /api;/config
- CVE-2024-503351 PoCAuthenticated XSS in "Publish Key" Field Allowing Unauthorized Administrator User Creation in SuiteCRM
- CVE-2024-503402 PoCsAbility to change environment from query in symfony/runtime
- CVE-2024-503502 PoCsLibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/app/Http/Controllers/Table/EditPortsController.php
- CVE-2024-503512 PoCsLibreNMS has a Reflected XSS ('Cross-site Scripting') in librenms/includes/functions.php
- CVE-2024-503522 PoCsLibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/overview/services.inc.php
- CVE-2024-503541 PoCOut-of-memory during deserialization with crafted inputs
- CVE-2024-503551 PoCLibreNMS has a Persistent XSS from Insecure Input Sanitization Affects Multiple Endpoints
- CVE-2024-5037915 PoCsApache Tomcat: RCE due to TOCTOU issue in JSP compilation
- CVE-2024-503821 PoCBotan before 3.6.0, when certain LLVM versions are used, has compiler-induced secret-dependent control flow in lib/utils/ghash/ghash.cpp…
- CVE-2024-503831 PoCBotan before 3.6.0, when certain GCC versions are used, has a compiler-induced secret-dependent operation in lib/utils/donna128.h in…
- CVE-2024-503951 PoCMedia Streaming add-on
- CVE-2024-504041 PoCQsync Central
- CVE-2024-504271 PoCWordPress SurveyJS plugin <= 1.9.136 - Arbitrary File Upload vulnerability
- CVE-2024-504501 PoCWordPress MDTF – Meta Data and Taxonomies Filter plugin <= 1.3.3.4 - Bypass Vulnerability vulnerability
- CVE-2024-504731 PoCWordPress Ajar in5 Embed plugin <= 3.1.3 - Arbitrary File Upload vulnerability
- CVE-2024-504751 PoCWordPress Signup Page plugin <= 1.0 - Arbitrary Option Update to Privilege Escalation vulnerability
- CVE-2024-504761 PoCWordPress GRÜN spendino Spendenformular plugin <= 1.0.1 - Arbitrary Option Update to Privilege Escalation vulnerability
- CVE-2024-504773 PoCsWordPress Stacks Mobile App Builder plugin <= 5.2.3 - Account Takeover vulnerability
- CVE-2024-504781 PoCWordPress 1-Click Login: Passwordless Authentication plugin 1.4.5 - Broken Authentication vulnerability
- CVE-2024-504821 PoCWordPress Woocommerce Product Design plugin <= 1.0.0 - Arbitrary File Upload vulnerability
- CVE-2024-504831 PoCWordPress Meetup plugin <= 0.1 - Broken Authentication vulnerability
- CVE-2024-504851 PoCWordPress Exam Matrix plugin <= 1.5 - Privilege Escalation vulnerability
- CVE-2024-504881 PoCWordPress Token Login plugin <= 1.0.3 - Broken Authentication vulnerability
- CVE-2024-504901 PoCWordPress PegaPoll plugin <= 1.0.2 - Arbitrary Option Update to Privilege Escalation vulnerability
- CVE-2024-504911 PoCWordPress RSVP ME plugin <= 1.9.9 - SQL Injection vulnerability
- CVE-2024-504921 PoCWordPress ScottCart plugin <= 1.1 - Remote Code Execution (RCE) vulnerability
- CVE-2024-504931 PoCWordPress Automatic Translation plugin <= 1.0.4 - Arbitrary File Upload vulnerability
- CVE-2024-504986 PoCsWordPress WP Query Console plugin <= 1.0 - Remote Code Execution (RCE) vulnerability
- CVE-2024-505071 PoCWordPress DS.DownloadList plugin <= 1.3 - PHP Object Injection vulnerability
- CVE-2024-505081 PoCWordPress Woocommerce Product Design plugin <= 1.0.0 - Arbitrary File Download vulnerability
- CVE-2024-505091 PoCWordPress Woocommerce Product Design plugin <= 1.0.0 - Arbitrary File Deletion vulnerability
- CVE-2024-505101 PoCWordPress AR For Woocommerce plugin <= 6.3 - Arbitrary File Upload vulnerability
- CVE-2024-505261 PoCWordPress Multi Purpose Mail Form plugin <= 1.0.2 - Arbitrary File Upload vulnerability
- CVE-2024-505622 PoCsAn Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and…
- CVE-2024-506034 PoCsKEVAn issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special…
- CVE-2024-506081 PoCAn issue was discovered in Fluent Bit 3.1.9. When the Prometheus Remote Write input plugin is running and listening on an IP address and…
- CVE-2024-506091 PoCAn issue was discovered in Fluent Bit 3.1.9. When the OpenTelemetry input plugin is running and listening on an IP address and port, one…
- CVE-2024-506121 PoClibsndfile through 1.2.2 has an ogg_vorbis.c vorbis_analysis_wrote out-of-bounds read.
- CVE-2024-506131 PoClibsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encoder_close.
- CVE-2024-506141 PoCTinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp…
- CVE-2024-506151 PoCTinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp…
- CVE-2024-506238 PoCsKEVIn Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download…
- CVE-2024-506291 PoCImproper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and…
- CVE-2024-506331 PoCA Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted…
- CVE-2024-506481 PoCyshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to…
- CVE-2024-506491 PoCThe user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability.
- CVE-2024-506501 PoCpython_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different…
- CVE-2024-506511 PoCjava_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different…
- CVE-2024-506641 PoCgpac 2.4 contains a heap-buffer-overflow at isomedia/sample_descs.c:1799 in gf_isom_new_mpha_description in gpac/MP4Box.
- CVE-2024-506651 PoCgpac 2.4 contains a SEGV at src/isomedia/drm_sample.c:1562:96 in isom_cenc_get_sai_by_saiz_saio in MP4Box.
- CVE-2024-506671 PoCThe boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup,…
- CVE-2024-506721 PoCA NoSQL injection vulnerability in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows unauthenticated attackers to reset user and…
- CVE-2024-506771 PoCA cross-site scripting (XSS) vulnerability in OroPlatform CMS v5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted…
- CVE-2024-508031 PoCThe mediapool feature of the Redaxo Core CMS application v 5.17.1 is vulnerable to Cross Site Scripting(XSS) which allows a remote…
- CVE-2024-508041 PoCInsecure Permissions vulnerability in Micro-star International MSI Center Pro 2.1.37.0 allows a local attacker to execute arbitrary code…
- CVE-2024-508481 PoCAn XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to…
- CVE-2024-508492 PoCsA Stored Cross-Site Scripting (XSS) vulnerability in the "Rules" functionality of WorldServer v11.8.2 allows a remote authenticated…
- CVE-2024-508573 PoCsThe ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and enables CSRF…
- CVE-2024-508582 PoCsMultiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actions via the admin's…
- CVE-2024-508592 PoCsThe ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly formatted file, the…
- CVE-2024-508612 PoCsThe ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious code into the "TSIG…
- CVE-2024-509441 PoCInteger overflow vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f in the shopping cart…
- CVE-2024-509451 PoCAn improper access control vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f, allowing users to…
- CVE-2024-509601 PoCA command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352…
- CVE-2024-509661 PoCdingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addAdmin.
- CVE-2024-509672 PoCsThe /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability. An attacker can…
- CVE-2024-509681 PoCA business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1.0, which allows…
- CVE-2024-509691 PoCA Reflected cross-site scripting (XSS) vulnerability in browse.php of Code-projects Jonnys Liquor 1.0 allows remote attackers to inject…
- CVE-2024-509701 PoCA SQL injection vulnerability in orderview1.php of Itsourcecode Online Furniture Shopping Project 1.0 allows remote attackers to execute…
- CVE-2024-509711 PoCA SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary…
- CVE-2024-509721 PoCA SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute…
- CVE-2024-509861 PoCAn issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file.