CVE-2024-57000 to CVE-2024-57999
160 CVEs with public proof-of-concept exploits.
- CVE-2024-570111 PoCTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute" parameters in…
- CVE-2024-570121 PoCTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in…
- CVE-2024-570131 PoCTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "switch" parameter in…
- CVE-2024-570141 PoCTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "recHour" parameter in…
- CVE-2024-570151 PoCTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" parameter in…
- CVE-2024-570161 PoCTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "user" parameter in…
- CVE-2024-570171 PoCTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "pass" parameter in…
- CVE-2024-570181 PoCTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in…
- CVE-2024-570191 PoCTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "limit" parameter in…
- CVE-2024-570201 PoCTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sMinute" parameter in…
- CVE-2024-570211 PoCTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eHour" parameter in…
- CVE-2024-570221 PoCTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sHour" parameter in…
- CVE-2024-570231 PoCTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in…
- CVE-2024-570241 PoCTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eMinute" parameter in…
- CVE-2024-570251 PoCTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in…
- CVE-2024-570261 PoCTawkTo Widget Version <= 1.3.7 is vulnerable to Cross Site Scripting (XSS) due to processing user input in a way that allows JavaScript…
- CVE-2024-570301 PoCWegia < 3.2.0 is vulnerable to Cross Site Scripting (XSS) in /geral/documentos_funcionario.php via the id parameter.
- CVE-2024-570311 PoCWeGIA < 3.2.0 is vulnerable to SQL Injection in /funcionario/remuneracao.php via the id_funcionario parameter.
- CVE-2024-570321 PoCWeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old…
- CVE-2024-570331 PoCWeGIA < 3.2.0 is vulnerable to Cross Site Scripting (XSS) via the dados_addInfo parameter of documentos_funcionario.php.
- CVE-2024-570341 PoCWeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter.
- CVE-2024-570351 PoCWeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php.
- CVE-2024-570361 PoCTOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This…
- CVE-2024-570401 PoCTL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a hardcoded password for the root account which can be…
- CVE-2024-570452 PoCsA vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the…
- CVE-2024-570462 PoCsA vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the…
- CVE-2024-570831 PoCA prototype pollution in the component Module.mergeObjects (redoc/bundles/redoc.lib.js:2) of redoc <= 2.2.0 allows attackers to cause a…
- CVE-2024-570951 PoCSQL injection vulnerability in Go-CMS v.1.1.10 allows a remote attacker to execute arbitrary code via a crafted payload.
- CVE-2024-570971 PoCClassCMS 4.8 is vulnerable to Cross Site Scripting (XSS) in class/admin/channel.php.
- CVE-2024-570981 PoCMoss v0.1.3 version has an SQL injection vulnerability that allows attackers to inject carefully designed payloads into the order parameter.
- CVE-2024-570991 PoCClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in the classview…
- CVE-2024-571601 PoC07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html.
- CVE-2024-571611 PoC07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit.html
- CVE-2024-571751 PoCA Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 via the profile…
- CVE-2024-572401 PoCA Cross-Site Scripting (XSS) vulnerability in the Rendering Engine component in Apryse WebViewer v11.1 and earlier allows attackers to…
- CVE-2024-572413 PoCsDedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the input GET request…
- CVE-2024-572791 PoCA reflected Cross-Site Scripting (XSS) vulnerability has been identified in the LDAP User Manager <= ce92321, specifically in the…
- CVE-2024-573261 PoCA Reflected Cross-Site Scripting (XSS) vulnerability exists in the search.php file of the Online Pizza Delivery System 1.0. The…
- CVE-2024-573281 PoCA SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0. The vulnerability arises because the input…
- CVE-2024-573291 PoCHortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user…
- CVE-2024-573571 PoCAn issue in TPLINK TL-WPA 8630 TL-WPA8630(US)_V2_2.0.4 Build 20230427 allows a remote attacker to execute arbitrary code via function…
- CVE-2024-573731 PoCCross Site Request Forgery (CSRF) vulnerability in LifestyleStore v1.0 allows a remote attacker to execute unauthorized actions on behalf…
- CVE-2024-573761 PoCBuffer Overflow vulnerability in D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, DSR-1000N from 3.13 to 3.17B901C allows…
- CVE-2024-573781 PoCWazuh SIEM version 4.8.2 is affected by a broken access control vulnerability. This issue allows the unauthorized creation of internal…
- CVE-2024-573861 PoCCross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile picture function.
- CVE-2024-573941 PoCThe quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore a malicious file…
- CVE-2024-574081 PoCAn arbitrary file upload vulnerability in the component /comm/upload of cool-admin-java v1.0 allows attackers to execute arbitrary code…
- CVE-2024-574091 PoCA stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers to execute…
- CVE-2024-574231 PoCA Cross Site Scripting vulnerability in CloudClassroom-PHP Project v1.0 allows a remote attacker to execute arbitrary code via the exid…
- CVE-2024-574271 PoCPHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user…
- CVE-2024-574281 PoCA stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload…
- CVE-2024-574291 PoCA cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote…
- CVE-2024-574301 PoCAn SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate…
- CVE-2024-574501 PoCChestnutCMS <=1.5.0 is vulnerable to File Upload via the Create template function.
- CVE-2024-574511 PoCChestnutCMS <=1.5.0 has a directory traversal vulnerability in contentcore.controller.FileController#getFileList, which allows attackers…
- CVE-2024-574521 PoCChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows attackers to…
- CVE-2024-574872 PoCsIn Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types allowing an…
- CVE-2024-574981 PoCCross Site Scripting vulnerability in sayski ForestBlog 20241223 allows a remote attacker to escalate privileges via the article editing…
- CVE-2024-575142 PoCsThe TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listing paths in the…
- CVE-2024-575191 PoCAn issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in…
- CVE-2024-575212 PoCsSQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in…
- CVE-2024-575221 PoCSourceCodester Packers and Movers Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in Users.php. An attacker can inject…
- CVE-2024-575232 PoCsCross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create…
- CVE-2024-575291 PoCCross Site Scripting vulnerability in Jeppesen JetPlanner Pro v.1.6.2.20 allows a remote attacker to execute arbitrary code.
- CVE-2024-575361 PoCLinksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via wizard_status.
- CVE-2024-575371 PoCLinksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (page) is copied to the stack…
- CVE-2024-575381 PoCLinksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (anonymous_protect_status) is…
- CVE-2024-575391 PoCLinksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via userEmail.
- CVE-2024-575401 PoCLinksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (action) is copied to the stack…
- CVE-2024-575411 PoCLinksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (ipv6_protect_status) is copied…
- CVE-2024-575421 PoCLinksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via the field id_email_check_btn.
- CVE-2024-575431 PoCLinksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (dhcpstart_ip) is copied to the…
- CVE-2024-575441 PoCLinksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (lan_ipaddr) is copied to the…
- CVE-2024-575451 PoCLinksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (hidden_dhcp_num) is copied to…
- CVE-2024-575461 PoCAn issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validate link function.
- CVE-2024-575471 PoCInsecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the…
- CVE-2024-575481 PoCCMSimple 5.16 allows the user to edit log.php file via print page.
- CVE-2024-575491 PoCCMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request.
- CVE-2024-575801 PoCTenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.
- CVE-2024-575811 PoCTenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.
- CVE-2024-575821 PoCTenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the startIP parameter in the formSetPPTPServer function.
- CVE-2024-576011 PoCCross Site Scripting vulnerability in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to execute arbitrary code via the…
- CVE-2024-576021 PoCAn issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.
- CVE-2024-576032 PoCsAn issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the lack of rate limiting.
- CVE-2024-576042 PoCsAn issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.
- CVE-2024-576051 PoCCross Site Scripting vulnerability in Daylight Studio Fuel CMS v.1.5.2 allows an attacker to escalate privileges via the /fuel/blocks/ and…
- CVE-2024-576061 PoCSQL injection vulnerability in Beijing Guoju Information Technology Co., Ltd JeecgBoot v.3.7.2 allows a remote attacker to obtain…
- CVE-2024-576092 PoCsAn issue in Kanaries Inc Pygwalker before v.0.4.9.9 allows a remote attacker to obtain sensitive information and execute arbitrary code…
- CVE-2024-576103 PoCsA rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts,…
- CVE-2024-576151 PoCAn issue in the BATcalcbetween_intern component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2024-576161 PoCAn issue in the vscanf component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
- CVE-2024-576171 PoCAn issue in the dameraulevenshtein component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted…
- CVE-2024-576181 PoCAn issue in the bind_col_exp component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL…
- CVE-2024-576191 PoCAn issue in the atom_get_int component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL…
- CVE-2024-576201 PoCAn issue in the trimchars component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL…
- CVE-2024-576211 PoCAn issue in the GDKanalytical_correlation component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2024-576221 PoCAn issue in the exp_bin component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
- CVE-2024-576231 PoCAn issue in the HEAP_malloc component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL…
- CVE-2024-576241 PoCAn issue in the exp_atom component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL…
- CVE-2024-576251 PoCAn issue in the merge_table_prune_and_unionize component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS)…
- CVE-2024-576261 PoCAn issue in the mat_join2 component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL…
- CVE-2024-576271 PoCAn issue in the gc_col component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
- CVE-2024-576281 PoCAn issue in the exp_values_set_supertype component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2024-576291 PoCAn issue in the tail_type component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL…
- CVE-2024-576301 PoCAn issue in the exps_card component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL…
- CVE-2024-576311 PoCAn issue in the exp_ref component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
- CVE-2024-576321 PoCAn issue in the is_column_unique component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL…
- CVE-2024-576341 PoCAn issue in the exp_copy component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (DoS) via crafted SQL…
- CVE-2024-576351 PoCAn issue in the chash_array component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2024-576361 PoCAn issue in the itc_sample_row_check component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS)…
- CVE-2024-576371 PoCAn issue in the dfe_unit_gb_dependant component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service…
- CVE-2024-576381 PoCAn issue in the dfe_body_copy component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2024-576391 PoCAn issue in the dc_elt_size component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2024-576401 PoCAn issue in the dc_add_int component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2024-576411 PoCAn issue in the sqlexp component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted…
- CVE-2024-576421 PoCAn issue in the dfe_inx_op_col_def_table component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service…
- CVE-2024-576431 PoCAn issue in the box_deserialize_string component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service…
- CVE-2024-576441 PoCAn issue in the itc_hash_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2024-576451 PoCAn issue in the qi_inst_state_free component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS)…
- CVE-2024-576461 PoCAn issue in the psiginfo component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted…
- CVE-2024-576471 PoCAn issue in the row_insert_cast component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2024-576481 PoCAn issue in the itc_set_param_row component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS)…
- CVE-2024-576491 PoCAn issue in the qst_vec_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2024-576501 PoCAn issue in the qi_inst_state_free component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS)…
- CVE-2024-576511 PoCAn issue in the jp_add component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted…
- CVE-2024-576521 PoCAn issue in the numeric_to_dv component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2024-576531 PoCAn issue in the qst_vec_set_copy component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2024-576541 PoCAn issue in the qst_vec_get_int64 component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS)…
- CVE-2024-576551 PoCAn issue in the dfe_n_in_order component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2024-576561 PoCAn issue in the sqlc_add_distinct_node component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service…
- CVE-2024-576571 PoCAn issue in the sqlg_vec_upd component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2024-576581 PoCAn issue in the sql_tree_hash_1 component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2024-576591 PoCAn issue in the sqlg_parallel_ts_seq component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS)…
- CVE-2024-576601 PoCAn issue in the sqlo_expand_jts component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2024-576611 PoCAn issue in the sqlo_df component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted…
- CVE-2024-576621 PoCAn issue in the sqlg_hash_source component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2024-576631 PoCAn issue in the sqlg_place_dpipes component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS)…
- CVE-2024-576641 PoCAn issue in the sqlg_group_node component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via…
- CVE-2024-576731 PoCAn issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module and Linkdiscovery module
- CVE-2024-576981 PoCAn issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes without…
- CVE-2024-577031 PoCTenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi of the file…
- CVE-2024-577041 PoCTenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi of the file…
- CVE-2024-577081 PoCAn issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __proto__, and…
- CVE-2024-577192 PoCslunasvg v3.0.0 was discovered to contain a segmentation violation via the component blend_transformed_tiled_argb.isra.0.
- CVE-2024-577202 PoCslunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_blend.
- CVE-2024-577212 PoCslunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_path_add_path.
- CVE-2024-577222 PoCslunasvg v3.0.0 was discovered to contain a allocation-size-too-big bug via the component plutovg_surface_create.
- CVE-2024-577232 PoCslunasvg v3.0.0 was discovered to contain a segmentation violation via the component composition_source_over.
- CVE-2024-577242 PoCslunasvg v3.0.0 was discovered to contain a segmentation violation via the component gray_record_cell.
- CVE-2024-577261 PoCKEVSimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with…
- CVE-2024-577273 PoCsKEVSimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated…
- CVE-2024-577571 PoCJeeWMS before v2025.01.01 was discovered to contain a permission bypass in the component /interceptors/AuthInterceptor.cava.
- CVE-2024-577641 PoCMSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/add.
- CVE-2024-577661 PoCMSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/editField.
- CVE-2024-577781 PoCAn issue in Orbe ONetView Roeador Onet-1200 Orbe 1680210096 allows a remote attacker to escalate privileges via the servers response from…
- CVE-2024-577841 PoCAn issue in the component /php/script_uploads.php of Zenitel AlphaWeb XE v11.2.3.10 allows attackers to execute a directory traversal.
- CVE-2024-577851 PoCZenitel AlphaWeb XE v11.2.3.10 was discovered to contain a local file inclusion vulnerability via the component amc_uploads.php.
- CVE-2024-578223 PoCsIn Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in…
- CVE-2024-578233 PoCsIn Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in…
- CVE-2024-579721 PoCThe pairing API request handler in Microsoft HoloLens 1 (Windows Holographic) through 10.0.17763.3046 and HoloLens 2 (Windows Holographic)…