CVE-2024-56000 to CVE-2024-56999
54 CVEs with public proof-of-concept exploits.
- CVE-2024-560581 PoCWordPress VRPConnector plugin <= 2.0.1 - PHP Object Injection vulnerability
- CVE-2024-560591 PoCWordPress Partners plugin <= 0.2.0 - PHP Object Injection vulnerability
- CVE-2024-560642 PoCsWordPress WP SuperBackup plugin <= 2.3.3 - Unauthenticated Arbitrary File Upload vulnerability
- CVE-2024-560671 PoCWordPress WP SuperBackup plugin <= 2.3.3 - Unauthenticated Backup File Download Vulnerability
- CVE-2024-560711 PoCWordPress Simple Dashboard plugin <= 2.0 - Privilege Escalation vulnerability
- CVE-2024-561141 PoCCanlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a…
- CVE-2024-561151 PoCA vulnerability in Amiro.CMS before 7.8.4 exists due to the failure to take measures to neutralize special elements. It allows remote…
- CVE-2024-561161 PoCA Cross-Site Request Forgery vulnerability in Amiro.CMS before 7.8.4 allows remote attackers to create an administrator account.
- CVE-2024-561371 PoCMaxKB RCE vulnerability in function library
- CVE-2024-561442 PoCsStored XSS-LibreNMS-Display Name 2 in librenms
- CVE-2024-561456 PoCsKEVRCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
- CVE-2024-561592 PoCsServer source code is exposed to the public if sourcemaps are enabled
- CVE-2024-561981 PoCpath-sanitizer allows bypassing the existing filters to achieve path-traversal vulnerability
- CVE-2024-561992 PoCsphpMyFAQ Vulnerable to Stored HTML Injection at FAQ
- CVE-2024-562491 PoCWordPress WPMasterToolKit plugin <= 1.13.1 - Arbitrary File Upload vulnerability
- CVE-2024-562642 PoCsWordPress ACF City Selector plugin <= 1.14.0 - Arbitrary File Upload vulnerability
- CVE-2024-562781 PoCWordPress WP Ultimate Exporter plugin <= 2.9.1 - Remote Code Execution (RCE) vulnerability
- CVE-2024-562891 PoCWordPress Groundhogg plugin <= 3.7.3.3 - Reflected Cross Site Scripting (XSS) vulnerability
- CVE-2024-563251 PoCApache Pinot: Authentication bypass issue. If the path does not contain / and contain . authentication is not required
- CVE-2024-563313 PoCsLocal File Inclusion (LFI) via Improper URL Handling in uptime-kuma's `Real-Browser` monitor
- CVE-2024-563341 PoCCommand injection vulnerability in getWindowsIEEE8021x (SSID) function in systeminformation
- CVE-2024-563481 PoCIn JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents
- CVE-2024-563611 PoCStored Cross-Site Scripting (XSS) in lgsl v7.0
- CVE-2024-563661 PoCPhpSpreadsheet vulnerable to unauthorized reflected XSS in the Accounting.php file
- CVE-2024-563761 PoCA stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users to inject…
- CVE-2024-563771 PoCA stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts…
- CVE-2024-563781 PoClibpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.
- CVE-2024-564081 PoCPhpSpreadsheet allows unauthorized reflected XSS in `Convert-Online.php` file
- CVE-2024-564091 PoCPhpSpreadsheet vulnerable to unauthorized reflected XSS in Currency.php file
- CVE-2024-564262 PoCsAn issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480,…
- CVE-2024-564281 PoCThe local iLabClient database in itech iLabClient 3.7.1 allows local attackers to read cleartext credentials (from the CONFIGS table) for…
- CVE-2024-564291 PoCitech iLabClient 3.7.1 relies on the hard-coded YngAYdgAE/kKZYu2F2wm6w== key (found in iLabClient.jar) for local users to read or write to…
- CVE-2024-564301 PoCOpenFHE through 1.2.3 has a NULL pointer dereference in BinFHEContext::EvalFloor in lib/binfhe-base-scheme.cpp.
- CVE-2024-564311 PoCoc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by…
- CVE-2024-564331 PoCshadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first…
- CVE-2024-565071 PoCReflected Cross-Site Scripting (XSS) Vulnerability in LinkAce
- CVE-2024-565081 PoCFile Upload Vulnerability Leading to XSS in LinkAce v1.15.5
- CVE-2024-565113 PoCsDataEase has an unauthorized vulnerability
- CVE-2024-565122 PoCsApache NiFi: Missing Complete Authorization for Parameter and Service References
- CVE-2024-565171 PoCLGSL has a reflected XSS at /lgsl_files/lgsl_list.php
- CVE-2024-565271 PoCAn issue was discovered in TCPDF before 6.8.0. The Error function lacks an htmlspecialchars call for the error message.
- CVE-2024-567321 PoCHarfBuzz heap-buffer-overflow on hb_cairo_glyphs_from_buffer
- CVE-2024-568001 PoCFirecrawl has SSRF Vulnerability via malicious scrape target
- CVE-2024-568011 PoCTasklists has Blind SQL Injection in /ajax/reorder.php
- CVE-2024-568281 PoCFile Upload vulnerability in ChestnutCMS through 1.5.0. Based on the code analysis, it was determined that the /api/member/avatar API…
- CVE-2024-568822 PoCsSage DPW before 2024_12_000 is vulnerable to Cross Site Scripting (XSS). Low-privileged Sage users with employee role privileges can…
- CVE-2024-568832 PoCsSage DPW before 2024_12_001 is vulnerable to Incorrect Access Control. The implemented role-based access controls are not always enforced…
- CVE-2024-568891 PoCIncorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers…
- CVE-2024-568971 PoCImproper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API…
- CVE-2024-568981 PoCBroken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low privilege users…
- CVE-2024-569011 PoCA Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less that allows attackers…
- CVE-2024-569021 PoCInformation disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account…
- CVE-2024-569151 PoCNetbox Community v4.1.7 and fixed in v.4.2.2 is vulnerable to Cross Site Scripting (XSS) via the RSS feed widget.
- CVE-2024-569241 PoCA Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary…