CVE-2024-53000 to CVE-2024-53999
76 CVEs with public proof-of-concept exploits.
- CVE-2024-530271 PoCBuffer Copy Without Checking Size of Input in WLAN Host
- CVE-2024-531412 PoCsnetfilter: ipset: add missing range check in bitmap_ip_uadt
- CVE-2024-532552 PoCsReflected Cross-site Scripting in /admin?page=media via file Parameter in BoidCMS
- CVE-2024-532571 PoCVitess allows HTML injection in /debug/querylogz & /debug/env
- CVE-2024-532591 PoCquic-go affected by an ICMP Packet Too Large Injection Attack on Linux
- CVE-2024-532671 PoCVulnerability with bundle verification in sigstore-java
- CVE-2024-532681 PoCLack of validation on openExternal allows 1 click remote code execution in joplin
- CVE-2024-532691 PoCHappy Eyeballs: Validate that additional_address are IP addresses instead of crashing when sorting in envoy
- CVE-2024-532701 PoCHTTP/1: sending overload crashes when the request is reset beforehand in envoy
- CVE-2024-532711 PoCHTTP/1.1 multiple issues with envoy.reloadable_features.http1_balsa_delay_reset in envoy
- CVE-2024-532721 PoCGHSL-2024-109: Reflected XSS in /login in habitica
- CVE-2024-532731 PoCGHSL-2024-110: Reflected XSS in /register in habitica
- CVE-2024-532741 PoCGHSL-2024-111: Reflected XSS in /home in habitica
- CVE-2024-533071 PoCA reflected cross-site scripting (XSS) vulnerability in the /mw/ endpoint of Evisions MAPS v6.10.2.267 allows attackers to execute…
- CVE-2024-533261 PoCLINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(), leading to code…
- CVE-2024-533331 PoCTOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. This vulnerability…
- CVE-2024-533341 PoCTOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in infostat.cgi.
- CVE-2024-533351 PoCTOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in downloadFlile.cgi.
- CVE-2024-533451 PoCAn authenticated arbitrary file upload vulnerability in Car Rental Management System v1.0 to v1.3 allows attackers to execute arbitrary…
- CVE-2024-533591 PoCAn issue in Zalo v23.09.01 allows attackers to obtain sensitive user information via a crafted GET request.
- CVE-2024-533641 PoCA SQL injection vulnerability was found in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/view-detail.php. This…
- CVE-2024-533651 PoCA stored cross-site scripting (XSS) vulnerability was identified in PHPGURUKUL Vehicle Parking Management System v1.13 in…
- CVE-2024-533751 PoCAn Authenticated Remote Code Execution (RCE) vulnerability affects the TP-Link Archer router series. A vulnerability exists in the…
- CVE-2024-533762 PoCsCyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field…
- CVE-2024-533821 PoCPrism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly…
- CVE-2024-533841 PoCA DOM Clobbering vulnerability in tsup v8.3.4 allows attackers to execute arbitrary code via a crafted script in the import.meta.url to…
- CVE-2024-533861 PoCStage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain…
- CVE-2024-533871 PoCA DOM Clobbering vulnerability in umeditor v1.2.3 allows attackers to execute arbitrary code via supplying a crafted HTML element.
- CVE-2024-533881 PoCA DOM Clobbering vulnerability in mavo v0.3.2 allows attackers to execute arbitrary code via supplying a crafted HTML element.
- CVE-2024-534061 PoCEspressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection phase, the device…
- CVE-2024-534071 PoCIn Phiewer 4.1.0, a dylib injection leads to Command Execution which allow attackers to inject dylib file potentially leading to remote…
- CVE-2024-534251 PoCA heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when…
- CVE-2024-534271 PoCdecNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which has a resultant…
- CVE-2024-534501 PoCRAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents.
- CVE-2024-534571 PoCA stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to…
- CVE-2024-534591 PoCSysax Multi Server 6.99 is vulnerable to Cross Site Scripting (XSS) via the /scgi?sid parameter.
- CVE-2024-534701 PoCMultiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/gateway_pagamento.php of WeGIA v3.2.0 allows…
- CVE-2024-534711 PoCMultiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/meio_pagamento.php of WeGIA v3.2.0 allows…
- CVE-2024-534721 PoCWeGIA v3.2.0 was discovered to contain a Cross-Site Request Forgery (CSRF).
- CVE-2024-534732 PoCsWeGIA 3.2.0 before 3998672 does not verify permission to change a password.
- CVE-2024-534761 PoCA race condition vulnerability in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f allows attackers to bypass inventory…
- CVE-2024-534801 PoCPhpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via the `emailcont` parameter.
- CVE-2024-534811 PoCA Cross Site Scripting (XSS) vulnerability in the profile.php of PHPGurukul Beauty Parlour Management System v1.1 allows remote attackers…
- CVE-2024-535041 PoCA SQL injection vulnerability has been identified in Siyuan 3.1.11 via the notebook parameter in /searchHistory.
- CVE-2024-535051 PoCA SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent.
- CVE-2024-535061 PoCA SQL injection vulnerability has been identified in Siyuan 3.1.11 via the ids array parameter in /batchGetBlockAttrs.
- CVE-2024-535071 PoCA SQL injection vulnerability was discovered in Siyuan 3.1.11 in /getHistoryItems.
- CVE-2024-535221 PoCBangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV pair in the HOSxPXE4.exe and HOS-WIN32.INI…
- CVE-2024-535261 PoCcomposio >=0.5.40 is vulnerable to Command Execution in composio_openai, composio_claude, and composio_julep via the handle_tool_calls…
- CVE-2024-535371 PoCAn issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager.
- CVE-2024-535531 PoCAn issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass authentication via crafted web requests.
- CVE-2024-535801 PoCiperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
- CVE-2024-535822 PoCsAn issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to execute a directory…
- CVE-2024-535841 PoCOpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.
- CVE-2024-535861 PoCAn issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a crafted HTTP request.…
- CVE-2024-535911 PoCAn issue in the login page of Seclore v3.27.5.0 allows attackers to bypass authentication via a brute force attack.
- CVE-2024-536151 PoCA command injection vulnerability in the video thumbnail rendering component of Karl Ward's files.gallery v0.3.0 through 0.11.0 allows…
- CVE-2024-536171 PoCA Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via uploading an HTML…
- CVE-2024-536191 PoCAn authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute arbitrary code via…
- CVE-2024-536201 PoCA cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execute arbitrary web…
- CVE-2024-536211 PoCA buffer overflow in the formSetCfm() function of Tenda AC1206 1200M 11ac US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 allows attackers to…
- CVE-2024-5367720 PoCsApache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload checks
- CVE-2024-536911 PoCQTS, QuTS hero
- CVE-2024-537031 PoCA vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web…
- CVE-2024-537043 PoCsKEVAn Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
- CVE-2024-538292 PoCsCross-Site Request Forgery in CodeChecker API
- CVE-2024-538612 PoCsIssuer field partial matches allowed in pyjwt
- CVE-2024-538622 PoCsArgo Workflows Allows Access to Archived Workflows with Fake Token in `client` mode
- CVE-2024-538662 PoCspnpm vulnerable to no-script global cache poisoning via overrides / `ignore-scripts` evasion
- CVE-2024-539004 PoCsMongoose before 8.8.3 can improperly use $where in match, leading to search injection.
- CVE-2024-539241 PoCPycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell, such as one…
- CVE-2024-539801 PoCSpoofed length byte traps CC2538 in endless loop
- CVE-2024-539901 PoCAsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s
- CVE-2024-539911 PoCPotential Backup file leaked via Nginx in Discourse
- CVE-2024-539951 PoCGHSL-2024-288: SickChill open redirect in login
- CVE-2024-539992 PoCsMobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" Functionality