CVE-2024-55000 to CVE-2024-55999
78 CVEs with public proof-of-concept exploits.
- CVE-2024-550001 PoCSourcecodester House Rental Management system v1.0 is vulnerable to Cross Site Scripting (XSS) in rental/manage_categories.php.
- CVE-2024-550081 PoCJATOS 3.9.4 contains a denial-of-service (DoS) vulnerability in the authentication system, where an attacker can prevent legitimate users…
- CVE-2024-550091 PoCA reflected cross-site scripting (XSS) vulnerability in AutoBib - Bibliographic collection management system 3.1.140 and earlier allows…
- CVE-2024-550401 PoCCross Site Scripting vulnerability in Sensaphone WEB600 Monitoring System v.1.6.5.H and before allows a remote attacker to execute…
- CVE-2024-550561 PoCA stored cross-site scripting (XSS) vulnerability was identified in Phpgurukul Online Birth Certificate System 1.0 in…
- CVE-2024-550571 PoCPhpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements which can lead to unauthorized access to…
- CVE-2024-550581 PoCAn insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1.0. This…
- CVE-2024-550591 PoCA stored HTML Injection vulnerability was identified in PHPGurukul Online Birth Certificate System v1.0 in /user/certificate-form.php.
- CVE-2024-550601 PoCA cross-site scripting (XSS) vulnerability in the component index.php of Rafed CMS Website v1.44 allows attackers to execute arbitrary web…
- CVE-2024-550741 PoCThe edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG…
- CVE-2024-550751 PoCGrocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI,…
- CVE-2024-550761 PoCGrocy through 4.3.0 has no CSRF protection, as demonstrated by changing the Administrator's password.
- CVE-2024-550992 PoCsA SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers…
- CVE-2024-551001 PoCA stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Online Nurse Hiring System v1.0 allows attackers…
- CVE-2024-551031 PoCOnline Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile.php via the…
- CVE-2024-551041 PoCOnline Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin/add-nurse.php via…
- CVE-2024-551601 PoCGFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/operLog/list.
- CVE-2024-551921 PoCOpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component OpenImageIO_v3_1_0::farmhash::inlined::Fetch64(char…
- CVE-2024-551931 PoCOpenImageIO v3.1.0.0dev was discovered to contain a segmentation violation via the component /OpenImageIO/string_view.h.
- CVE-2024-551941 PoCOpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h.
- CVE-2024-552111 PoCAn issue in Think Router Tk-Rt-Wr135G V3.0.2-X000 allows attackers to bypass authentication via a crafted cookie.
- CVE-2024-552152 PoCsAn issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization interface /auth/register.
- CVE-2024-552182 PoCsIceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter.
- CVE-2024-552271 PoCA cross-site scripting (XSS) vulnerability in the Events/Agenda module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web…
- CVE-2024-552281 PoCA cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web…
- CVE-2024-552311 PoCAn IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to…
- CVE-2024-552321 PoCAn IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users…
- CVE-2024-552381 PoCOpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the…
- CVE-2024-552391 PoCA reflected Cross-Site Scripting vulnerability in the standard documentation upload functionality in Portabilis i-Educar 2.9 allows…
- CVE-2024-552701 PoCphpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata parameter.
- CVE-2024-552711 PoCA Cross-Site Request Forgery (CSRF) vulnerability has been identified in phpgurukul Gym Management System 1.0. This issue is present in…
- CVE-2024-554151 PoCDevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.
- CVE-2024-554161 PoCDevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on…
- CVE-2024-554171 PoCDevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via…
- CVE-2024-554511 PoCA Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in UJCMS 9.6.3. The…
- CVE-2024-554521 PoCA URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of new block /…
- CVE-2024-554561 PoClunasvg v3.0.1 was discovered to contain a segmentation violation via the component gray_find_cell
- CVE-2024-554572 PoCsMasterSAM Star Gate 11 is vulnerable to directory traversal via /adama/adama/downloadService. An attacker can exploit this vulnerability…
- CVE-2024-554661 PoCAn arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional…
- CVE-2024-554881 PoCA stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2024-554961 PoCA vulnerability has been found in the 1000projects Bookstore Management System PHP MySQL Project 1.0. This issue affects some unknown…
- CVE-2024-555031 PoCAn issue in termius before v.9.9.0 allows a local attacker to execute arbitrary code via a crafted script to the DYLD_INSERT_LIBRARIES…
- CVE-2024-555041 PoCAn issue in RAR Extractor - Unarchiver Free and Pro v.6.4.0 allows local attackers to inject arbitrary code potentially leading to remote…
- CVE-2024-555061 PoCAn IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary…
- CVE-2024-555071 PoCAn issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.
- CVE-2024-555091 PoCSQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate…
- CVE-2024-555111 PoCA null pointer dereference vulnerability in Macrium Reflect prior to 8.1.8017 allows a local attacker to cause a system crash or…
- CVE-2024-555441 PoCAuthenticated Command Injection
- CVE-2024-555451 PoCReflected Cross-Site Scripting
- CVE-2024-555461 PoCStored Cross-Site Scripting
- CVE-2024-555501 PoCKEVMitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to…
- CVE-2024-555552 PoCsInvoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_KEY. This is…
- CVE-2024-555562 PoCsA vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote command execution on…
- CVE-2024-555571 PoCui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credentials.
- CVE-2024-555871 PoCpython-libarchive through 4.2.1 allows directory traversal (to create files) in extract in zip.py for ZipFile.extractall and…
- CVE-2024-5559111 PoCsKEVAn Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and…
- CVE-2024-556021 PoCPenDoc vulnerable to Arbitrary File Read on updating and downloading templates using Path Traversal
- CVE-2024-556031 PoCInsufficient session invalidation in Kanboard
- CVE-2024-556301 PoCDOM Clobbering leads to temporary DOS in the note viewer in Joplin
- CVE-2024-556511 PoCi-Educar Stored Cross-Site Scripting vulnerability
- CVE-2024-556531 PoCpwndoc's UnhandledPromiseRejection on audits causes Denial of Service (DoS)
- CVE-2024-556561 PoCRedisBloom Integer Overflow Remote Code Execution Vulnerability
- CVE-2024-556611 PoCLaravel Pulse Allows Remote Code Execution via Unprotected Query Method
- CVE-2024-558751 PoChttp4k has a potential XXE (XML External Entity Injection) vulnerability
- CVE-2024-558893 PoCsphpMyFAQ Vulnerable to Unintended File Download Triggered by Embedded Frames
- CVE-2024-558902 PoCsD-Tale allows Remote Code Execution through the Custom Filter Input
- CVE-2024-559472 PoCsGogs has a Path Traversal in file update API
- CVE-2024-559565 PoCsKEVIn Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute…
- CVE-2024-559633 PoCsAn issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on…
- CVE-2024-559641 PoCAn issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image leads to remote…
- CVE-2024-559682 PoCsAn issue was discovered in DTEX DEC-M (DTEX Forwarder) 6.1.1. The com.dtexsystems.helper service, responsible for handling privileged…
- CVE-2024-559721 PoCWordPress eTemplates plugin <= 0.2.1 - SQL Injection vulnerability
- CVE-2024-559761 PoCWordPress Critical Site Intel plugin <= 1.0 - SQL Injection vulnerability
- CVE-2024-559781 PoCWordPress Code Generator Pro plugin <= 1.2 - SQL Injection vulnerability
- CVE-2024-559801 PoCWordPress Wr Age Verification plugin <= 2.0.0 - SQL Injection vulnerability
- CVE-2024-559811 PoCWordPress Nabz Image Gallery plugin <= v1.00 - SQL Injection vulnerability
- CVE-2024-559821 PoCWordPress Share Buttons – Social Media plugin <= 1.0.2 - SQL Injection vulnerability
- CVE-2024-559881 PoCWordPress Navayan CSV Export Plugin <= 1.0.9 - SQL Injection vulnerability