CVE-2024-51000 to CVE-2024-51999
89 CVEs with public proof-of-concept exploits.
- CVE-2024-510261 PoCThe NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is…
- CVE-2024-510301 PoCA SQL injection vulnerability in manage_client.php and view_cab.php of Sourcecodester Cab Management System 1.0 allows remote attackers to…
- CVE-2024-510311 PoCA Cross-site Scripting (XSS) vulnerability in manage_account.php in Sourcecodester Cab Management System 1.0 allows remote authenticated…
- CVE-2024-510321 PoCA Cross-site Scripting (XSS) vulnerability in manage_recipient.php of Sourcecodester Toll Tax Management System 1.0 allows remote…
- CVE-2024-510371 PoCAn issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature in the password…
- CVE-2024-510601 PoCProjectworlds Online Admission System v1 is vulnerable to SQL Injection in index.php via the 'a_id' parameter.
- CVE-2024-510631 PoCPhpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection in add-teacher.php via the mobile number or email…
- CVE-2024-510641 PoCPhpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection via the tid parameter to admin/queries.php.
- CVE-2024-510651 PoCPhpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username parameter.
- CVE-2024-510661 PoCAn Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's Beauty Parlour Management System v1.1…
- CVE-2024-510741 PoCIncorrect access control in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to arbitrarily change…
- CVE-2024-510911 PoCCross Site Scripting vulnerability in seajs v.2.2.3 allows a remote attacker to execute arbitrary code via the seajs package
- CVE-2024-510921 PoCLibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's…
- CVE-2024-511111 PoCCross-Site Scripting (XSS) vulnerability in Pnetlab 5.3.11 allows an attacker to inject malicious scripts into a web page, which are…
- CVE-2024-511121 PoCOpen Redirect vulnerability in Pnetlab 5.3.11 allows an attacker to manipulate URLs to redirect users to arbitrary external websites via a…
- CVE-2024-511151 PoCDCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability.
- CVE-2024-511161 PoCTenda AC6 v2.0 V15.03.06.50 was discovered to contain a buffer overflow in the function 'formSetPPTPServer'.
- CVE-2024-511321 PoCAn XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute…
- CVE-2024-511411 PoCAn issue in TOTOLINK Bluetooth Wireless Adapter A600UB allows a local attacker to execute arbitrary code via the WifiAutoInstallDriver.exe…
- CVE-2024-511421 PoCCross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the…
- CVE-2024-511791 PoCAn issue in Open 5GS v.2.7.1 allows a remote attacker to cause a denial of service via the Network Function Virtualizations (NFVs) such as…
- CVE-2024-512112 PoCsSQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is…
- CVE-2024-512283 PoCsAn issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300RT…
- CVE-2024-512431 PoCThe eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deployment servers of…
- CVE-2024-513171 PoCAn issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function
- CVE-2024-513261 PoCSQL Injection vulnerability in projectworlds Travel management System v.1.0 allows a remote attacker to execute arbitrary code via the…
- CVE-2024-513271 PoCSQL Injection in loginform.php in ProjectWorld's Travel Management System v1.0 allows remote attackers to bypass authentication via SQL…
- CVE-2024-513281 PoCCross Site Scripting vulnerability in addcategory.php in projectworld's Travel Management System v1.0 allows remote attacker to inject…
- CVE-2024-513371 PoCCross Site Scripting vulnerability in Gibbon before v.27.0.01 and fixed in v.28.0.00 allows a remote attacker to obtain sensitive…
- CVE-2024-513581 PoCAn issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new…
- CVE-2024-513631 PoCInsecure deserialization in Hodoku v2.3.0 to v2.3.2 allows attackers to execute arbitrary code.
- CVE-2024-513641 PoCAn arbitrary file upload vulnerability in ModbusMechanic v3.0 allows attackers to execute arbitrary code via uploading a crafted .xml file.
- CVE-2024-513788 PoCsKEVgetresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass…
- CVE-2024-513791 PoCStored Cross-Site Scripting (XSS) vulnerability discovered in JATOS v3.9.3. The vulnerability exists in the description component of the…
- CVE-2024-513801 PoCStored Cross-Site Scripting (XSS) vulnerability discovered in the Properties Component of JATOS v3.9.3. This flaw allows an attacker to…
- CVE-2024-513811 PoCCross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators,…
- CVE-2024-513821 PoCCross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 allows an attacker to reset the administrator's password. This critical…
- CVE-2024-514061 PoCFloodlight SDN Open Flow Controller v.1.2 has an issue that allows local hosts to build fake LLDP packets that allow specific clusters to…
- CVE-2024-514071 PoCFloodlight SDN OpenFlow Controller v.1.2 has an issue that allows local hosts to construct false broadcast ports causing inter-host…
- CVE-2024-514091 PoCBuffer Overflow vulnerability in Tenda O3 v.1.0.0.5 allows a remote attacker to cause a denial of service via a network packet in a fixed…
- CVE-2024-514231 PoCCross Site Scripting vulnerability in Infor Global HR GHR v.11.23.03.00.21 and before allows a remote attacker to execute arbitrary code…
- CVE-2024-514281 PoCAn issue in Espressif Esp idf v5.3.0 allows attackers to cause a Denial of Service (DoS) via a crafted data channel packet.
- CVE-2024-514301 PoCCross Site Scripting vulnerability in online diagnostic lab management system using php v.1.0 allows a remote attacker to execute…
- CVE-2024-514311 PoCLB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily guessable.
- CVE-2024-514631 PoCIBM i server-side request forgery
- CVE-2024-514641 PoCIBM i authentication bypass
- CVE-2024-514782 PoCsUse of a Broken or Risky Cryptographic Algorithm in YesWiki
- CVE-2024-514801 PoCRedisTimeSeries Integer Overflow Remote Code Execution Vulnerability
- CVE-2024-514828 PoCsBoolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
- CVE-2024-514831 PoCchangedetection.io Path Traversal vulnerability
- CVE-2024-514841 PoCInsufficient Validation in Controllers (Activation/Deactivation) in Ampache
- CVE-2024-514851 PoCInsufficient Validation in Plugins (Activation/Deactivation) in Ampache
- CVE-2024-514861 PoCStored Cross-Site Scripting in Ampache
- CVE-2024-514871 PoCInsufficient Validation in Catalog (Activation/Deactivation) in Ampache
- CVE-2024-514881 PoCInsufficient Validation in Delete Message in Ampache
- CVE-2024-514891 PoCInsufficient Message Token Validation in Ampache
- CVE-2024-514901 PoCStored Cross-Site Scripting in Ampache
- CVE-2024-514911 PoCProcess crash during CRL-based revocation check on OS using separate mount point for temp Directory in notation-go
- CVE-2024-514942 PoCsLibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/app/Http/Controllers/Table/EditPortsController.php
- CVE-2024-514952 PoCsLibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/dev-overview-data.inc.php
- CVE-2024-514962 PoCsLibreNMS has a Reflected XSS ('Cross-site Scripting') in librenms/includes/html/pages/wireless.inc.php
- CVE-2024-514972 PoCsLibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/print-customoid.php
- CVE-2024-515011 PoCCRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributes
- CVE-2024-515021 PoCPanic Vulnerability in loona-hpack
- CVE-2024-515461 PoCCredentails Disclosure
- CVE-2024-515501 PoCData Validation / Sanitization
- CVE-2024-515676 PoCsKEVupgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication…
- CVE-2024-515683 PoCsCyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink.…
- CVE-2024-516651 PoCWordPress Magical Addons For Elementor plugin <= 1.2.1 - Server Side Request Forgery (SSRF) vulnerability
- CVE-2024-517351 PoCStored Cross-site Scripting to RCE on Osmedeus Web Server
- CVE-2024-517371 PoCRediSearch Integer Overflow with LIMIT or KNN arguments can lead to RCE
- CVE-2024-517391 PoCUsers enumeration allowed through Rest API in Combodo iTop
- CVE-2024-517472 PoCsArbitrary File Read and Delete in kanboard
- CVE-2024-517481 PoCRemote code execution through language setting in kanboard
- CVE-2024-517512 PoCsArbitrary file read with File and UploadButton components in Gradio
- CVE-2024-517741 PoCqBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.
- CVE-2024-517881 PoCWordPress The Novel Design Store Directory plugin <= 4.3.0 - Arbitrary File Upload vulnerability
- CVE-2024-517911 PoCWordPress Forms plugin <= 2.8.0 - Arbitrary File Upload vulnerability
- CVE-2024-517934 PoCsWordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability
- CVE-2024-518181 PoCWordPress Fancy Product Designer plugin <= 6.4.3 - Unauthenticated SQL Injection vulnerability
- CVE-2024-519772 PoCsUnauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., FUJIFILM Business Innovation,…
- CVE-2024-519784 PoCsAuthentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica…
- CVE-2024-519791 PoCAuthenticated stack based buffer overflow affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, Ricoh, and…
- CVE-2024-519801 PoCUnauthenticated Server Side Request Forgery (SSRF) via WS-Addressing affecting multiple models from Brother Industries, Ltd, FUJIFILM…
- CVE-2024-519811 PoCUnauthenticated Server Side Request Forgery (SSRF) via WS-Eventing affecting multiple models from Brother Industries, Ltd, FUJIFILM…
- CVE-2024-519821 PoCUnauthenticated Denial of Service (DoS) via malformed PJL request affecting multiple models from Brother Industries, Ltd, FUJIFILM…
- CVE-2024-519831 PoCUnauthenticated Denial of Service (DoS) via malformed WS-Scan request affecting multiple models from Brother Industries, Ltd, FUJIFILM…
- CVE-2024-519841 PoCAuthenticated disclosure of external service passwords via pass-back attack affecting multiple models from Brother Industries, Ltd,…
- CVE-2024-519962 PoCsSymphony has an Authentication Bypass via RememberMe