CVE-2024-52000 to CVE-2024-52999
67 CVEs with public proof-of-concept exploits.
- CVE-2024-520001 PoCReflected Cross-site Scripting exploit in Combodo iTop
- CVE-2024-520021 PoCCross-Site Request Forgery (CSRF) in several iTop pages
- CVE-2024-520031 PoCX-Forwarded-Prefix Header still allows for Open Redirect in traefik
- CVE-2024-520051 PoCThe sideband payload is passed unfiltered to the terminal in git
- CVE-2024-520091 PoCGit credentials are exposed in atlantis logs
- CVE-2024-520102 PoCsZoraxy has an authenticated command injection in the Web SSH feature
- CVE-2024-520331 PoCExposure of sensitive system information to an unauthorized control sphere issue exists in Rakuten Turbo 5G firmware version V1.3.18 and…
- CVE-2024-520352 PoCsAn integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. A specially…
- CVE-2024-520461 PoCApache MINA: MINA applications using unbounded deserialization may allow RCE
- CVE-2024-522691 PoCAI Assistant PDF Document Spoofing in DocuSign
- CVE-2024-522703 PoCsPDF Document Spoofing in DropBox Sign(HelloSign)
- CVE-2024-522721 PoCDenial of Service on Tenda AC6V2 Due To Stack Overflow
- CVE-2024-522731 PoCDenial of Service on Tenda AC6V2 Due To Stack Overflow
- CVE-2024-522741 PoCDenial of Service on Tenda AC6V2 Due To Stack Overflow
- CVE-2024-522751 PoCDenial of Service on Tenda AC6V2 Due To Stack Overflow
- CVE-2024-522763 PoCsPDF Document Spoofing in DocuSign
- CVE-2024-522902 PoCsStored XSS in Configuration Key Functionality
- CVE-2024-522912 PoCsCraft has a Local File System Validation Bypass Leading to File Overwrite, Sensitive File Access, and Potential Code Execution
- CVE-2024-522921 PoCCraft Allows Attackers to Read Arbitrary System Files
- CVE-2024-522932 PoCsCraft has a Potential Remote Code Execution via missing path normalization & Twig SSTI
- CVE-2024-522941 PoCkhoj has an IDOR in subscription management that allows unauthorized subscription modifications
- CVE-2024-522951 PoCDataEase has a forged JWT token vulnerability
- CVE-2024-523014 PoCsLaravel allows environment manipulation via query string
- CVE-2024-523022 PoCscommon-user-management Unrestricted File Upload Leading to Remote Code Execution (RCE)
- CVE-2024-523051 PoCUnoPim Stored XSS : Cookie hijacking through Create User function
- CVE-2024-523161 PoCApache Tomcat: Authentication bypass when using Jakarta Authentication API
- CVE-2024-523171 PoCApache Tomcat: Request/response mix-up with HTTP/2
- CVE-2024-523181 PoCApache Tomcat: Incorrect JSP tag recycling leads to XSS
- CVE-2024-523751 PoCWordPress Datasets Manager by Arttia Creative plugin <= 1.5 - Arbitrary File Upload vulnerability
- CVE-2024-523802 PoCsWordPress Picsmize plugin <= 1.0.0 - Arbitrary File Upload vulnerability
- CVE-2024-523821 PoCWordPress Matix Popup Builder plugin <= 1.0.0 - Arbitrary Option Update to Privilege Escalation vulnerability
- CVE-2024-524021 PoCWordPress Exclusive Content Password Protect plugin <= 1.1.0 - CSRF to Arbitrary File Upload vulnerability
- CVE-2024-524291 PoCWordPress WP Quick Setup plugin <= 2.0 - Arbitrary Plugin and Theme Installation to Remote Code Execution vulnerability
- CVE-2024-524301 PoCWordPress Lis Video Gallery plugin <= 0.2.1 - PHP Object Injection vulnerability
- CVE-2024-524332 PoCsWordPress My Geo Posts Free plugin <= 1.2 - PHP Object Injection vulnerability
- CVE-2024-524752 PoCsWordPress Wawp plugin < 3.0.18 - Account Takeover vulnerability
- CVE-2024-525062 PoCsGraylog can leak other users' reports via concurrent PDF report rendering
- CVE-2024-525101 PoCNextcloud Desktop client behaves incorrectly if the initial end-to-end-encryption signature is empty
- CVE-2024-525262 PoCsLibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/services.inc.php
- CVE-2024-525311 PoCGNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in…
- CVE-2024-525441 PoCLorex 2K Indoor Wi-Fi Security Camera - Stack buffer overflow
- CVE-2024-525451 PoCLorex 2K Indoor Wi-Fi Security Camera - Out of bounds heap read
- CVE-2024-525461 PoCLorex 2K Indoor Wi-Fi Security Camera - Null pointer dereference
- CVE-2024-525471 PoCLorex 2K Indoor Wi-Fi Security Camera - Stack buffer overflow
- CVE-2024-525481 PoCLorex 2K Indoor Wi-Fi Security Camera - Code signing bypass
- CVE-2024-525501 PoCJenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main…
- CVE-2024-525811 PoCLitestar allows unbounded resource consumption (DoS vulnerability)
- CVE-2024-525882 PoCsStrapi allows Server-Side Request Forgery in Webhook function
- CVE-2024-525961 PoCSimpleSAMLphp xml-common XXE vulnerability
- CVE-2024-525971 PoC2FAuth vulnerable to stored cross-site scripting via SVG upload and direct access render
- CVE-2024-525981 PoC2FAuth vulnerable to Server Side Request Forgery + URI validation bypass in 2fauth /api/v1/twofaccounts/preview
- CVE-2024-526131 PoCA heap-based buffer under-read in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Service (DoS) via a…
- CVE-2024-527012 PoCsA stored cross-site scripting (XSS) vulnerability in the Configuration page of Piwigo v14.5.0 allows attackers to execute arbitrary web…
- CVE-2024-527022 PoCsA stored cross-site scripting (XSS) vulnerability in the component install\index.php of MyBB v1.8.38 allows attackers to execute arbitrary…
- CVE-2024-527112 PoCsDI-8100 v16.07.26A1 is vulnerable to Buffer Overflow In the ip_position_asp function via the ip parameter.
- CVE-2024-527141 PoCTenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the function 'fromSetSysTime.
- CVE-2024-527622 PoCsA cross-site scripting (XSS) vulnerability in the component /master/header.php of Ganglia-web v3.73 to v3.76 allows attackers to execute…
- CVE-2024-527632 PoCsA cross-site scripting (XSS) vulnerability in the component /graph_all_periods.php of Ganglia-web v3.73 to v3.75 allows attackers to…
- CVE-2024-527651 PoCH3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter.
- CVE-2024-527941 PoCMagnific lightbox susceptible to Cross-site Scripting in Discourse
- CVE-2024-528001 PoCPotential XXE (XML External Entity Injection) vulnerability in veraPDF CLI
- CVE-2024-528032 PoCsLLama Factory Remote OS Command Injection Vulnerability
- CVE-2024-528061 PoCSimpleSAMLphp SAML2 has an XXE in parsing SAML messages
- CVE-2024-528101 PoCPrototype Pollution in @intlify/shared >=9.7.0 <= 10.0.4
- CVE-2024-528752 PoCsAn issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertException.cs and…
- CVE-2024-528831 PoCAn issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive…
- CVE-2024-529491 PoCiptraf-ng 1.2.1 has a stack-based buffer overflow. In src/ifaces.c, the strcpy function consistently fails to control the size, and it is…