CVE-2024-54000 to CVE-2024-54999
60 CVEs with public proof-of-concept exploits.
- CVE-2024-540011 PoCKanboard allows a persistent HTML injection site scripting in settings page date format
- CVE-2024-540282 PoCsAn integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed…
- CVE-2024-540852 PoCsKEVRedfish Authentication Bypass
- CVE-2024-541351 PoCUntrusted Deserialization in ClipBucket-v5 Version 2.0 to 5.5.1 Revision 199
- CVE-2024-541361 PoCUntrusted Deserialization in ClipBucket-v5 Version 5.5.1 Revision 199 and Below
- CVE-2024-541401 PoCsigstore-java has a vulnerability with bundle verification
- CVE-2024-541412 PoCsphpMyFAQ Generates an Error Message Containing Sensitive Information if database server is not available
- CVE-2024-541451 PoCCacti has a SQL Injection vulnerability when request automation devices
- CVE-2024-541461 PoCCacti has a SQL Injection vulnerability when view host template
- CVE-2024-541482 PoCsGogs has a Path Traversal in file editing UI
- CVE-2024-541512 PoCsDirectus allows unauthenticated access to WebSocket events and operations
- CVE-2024-541522 PoCsAngular Expressions - Remote Code Execution when using locals
- CVE-2024-541601 PoCdashboards-reporting (aka Dashboards Reports) before 2.19.0.0, as shipped in OpenSearch before 2.19, allows XSS because Markdown is not…
- CVE-2024-542391 PoCWordPress Eyewear prescription form plugin <= 4.0.18 - Arbitrary Option Update to Privilege Escalation vulnerability
- CVE-2024-542622 PoCsWordPress Import Export For WooCommerce plugin <= 1.6.2 - Arbitrary File Upload vulnerability
- CVE-2024-542921 PoCWordPress Appsplate plugin <= 2.1.3 - SQL Injection vulnerability
- CVE-2024-543302 PoCsWordPress Hurrakify plugin <= 2.4 - Server Side Request Forgery (SSRF) vulnerability
- CVE-2024-543632 PoCsWordPress Wp NssUser Register plugin <= 1.0.0 - Privilege Escalation vulnerability
- CVE-2024-543692 PoCsWordPress Zita Site Builder plugin <= 1.0.2 - Arbitrary Plugin Installation and Activation vulnerability
- CVE-2024-543741 PoCWordPress Sogrid plugin <= 1.5.6 - Local File Inclusion vulnerability
- CVE-2024-543781 PoCWordPress Quietly Insights plugin <= 1.2.2 - Arbitrary Option Update to Privilege Escalation vulnerability
- CVE-2024-543791 PoCWordPress Minterpress plugin <= 1.0.5 - Arbitrary Option Update to Privilege Escalation vulnerability
- CVE-2024-543831 PoCWordPress WooCommerce - PDF Vouchers plugin < 4.9.9 - Broken Authentication vulnerability
- CVE-2024-543852 PoCsWordPress Radio Player plugin <= 2.0.83 - Server Side Request Forgery (SSRF) vulnerability
- CVE-2024-544981 PoCA path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS…
- CVE-2024-545071 PoCA type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2.…
- CVE-2024-546791 PoCCyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.
- CVE-2024-546871 PoCVtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in…
- CVE-2024-547561 PoCA remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to execute arbitrary…
- CVE-2024-547614 PoCsBigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.
- CVE-2024-547631 PoCAn access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information…
- CVE-2024-547641 PoCAn access control issue in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information…
- CVE-2024-547671 PoCAn access control issue in the component /juis_boxinfo.xml of AVM FRITZ!Box 7530 AX v7.59 allows attackers to obtain sensitive information…
- CVE-2024-547724 PoCsAn issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through…
- CVE-2024-547741 PoCDcat Admin v2.2.0-beta contains a cross-site scripting (XSS) vulnerability in /admin/articles/create.
- CVE-2024-547921 PoCA Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user…
- CVE-2024-547941 PoCThe script input feature of SpagoBI 3.5.1 allows arbitrary code execution.
- CVE-2024-547951 PoCSpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer…
- CVE-2024-548021 PoCIn Netgear WNR854T 1.5.2 (North America), the UPNP service (/usr/sbin/upnp) is vulnerable to stack-based buffer overflow in the M-SEARCH…
- CVE-2024-548031 PoCNetgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi,…
- CVE-2024-548041 PoCNetgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi,…
- CVE-2024-548051 PoCNetgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi,…
- CVE-2024-548061 PoCNetgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi which allows for the execution of system…
- CVE-2024-548071 PoCIn Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exec which parses the…
- CVE-2024-548081 PoCNetgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionService function due…
- CVE-2024-548091 PoCNetgear Inc WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the parse_st_header function due to use…
- CVE-2024-548191 PoCI, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due to improper input validation in…
- CVE-2024-548511 PoCTeedy <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF), due to the lack of CSRF protection.
- CVE-2024-548521 PoCWhen LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnerable to LDAP…
- CVE-2024-548792 PoCsSeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members…
- CVE-2024-548802 PoCsSeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register…
- CVE-2024-548872 PoCsTP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2 parameters at…
- CVE-2024-549071 PoCTOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Remote Code Execution in /bin/boa via formWsc.
- CVE-2024-549101 PoCHasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File recovery function.
- CVE-2024-549511 PoCMonica 4.1.2 is vulnerable to Cross Site Scripting (XSS). A malicious user can create a malformed contact and use that contact in the "HOW…
- CVE-2024-549941 PoCMonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_name parameters in…
- CVE-2024-549961 PoCMonicaHQ v4.1.2 was discovered to contain multiple authenticated Client-Side Injection vulnerabilities via the title and description…
- CVE-2024-549971 PoCMonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field at…
- CVE-2024-549981 PoCMonicaHQ v4.1.2 was discovered to contain an authenticated Client-Side Injection vulnerability via the Reason parameter at…
- CVE-2024-549991 PoCMonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General Information module.