CVE-2024-58000 to CVE-2024-58999
59 CVEs with public proof-of-concept exploits.
- CVE-2024-581341 PoCMojolicious versions from 0.999922 for Perl uses a hard coded string, or the application's class name, as an HMAC session cookie secret by…
- CVE-2024-581351 PoCMojolicious versions from 7.28 through 9.45 for Perl will generate weak HMAC session cookie secrets via "mojo generate app" by default
- CVE-2024-581362 PoCsKEVYii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited…
- CVE-2024-582392 PoCstls: stop recv() if initial process_rx_list gave us non-DATA
- CVE-2024-582581 PoCSugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur.
- CVE-2024-582751 PoCEasywall 0.3.1 - Authentication Bypass via Command Injection in /ports-save Endpoint
- CVE-2024-582761 PoCObi08-Enrollment System 1.0 login.php SQL Injection
- CVE-2024-582771 PoCR Radio Network FM Transmitter 1.07 System Settings Disclosure
- CVE-2024-582781 PoCIndigoSTAR Software - perl2exe <= V30.10C - Arbitrary Code Execution
- CVE-2024-582791 PoCappRain CMF 4.0.5 Authenticated Remote Code Execution via Filemanager Upload
- CVE-2024-582801 PoCCMSimple 5.15 Remote Command Execution via Extensions Configuration
- CVE-2024-582811 PoCDotclear 2.29 Remote Code Execution via Authenticated File Upload
- CVE-2024-582821 PoCSerendipity 2.5.0 Remote Code Execution via Authenticated Media Upload
- CVE-2024-582831 PoCWBCE CMS 1.6.2 Remote Code Execution via Elfinder File Upload
- CVE-2024-582841 PoCPopojiCMS 2.0.1 Remote Command Execution via Authenticated Metadata Settings
- CVE-2024-582851 PoCChyrp 2.5.2 Stored Cross-Site Scripting Vulnerability via Post Title
- CVE-2024-582861 PoCdizqueTV 1.5.3 Remote Code Execution via FFMPEG Executable Path
- CVE-2024-582871 PoCreNgine 2.2.0 Authenticated Command Injection via Scan Engine Configuration
- CVE-2024-582881 PoCGenexus Protection Server 9.7.2.10 Unquoted Service Path Privilege Escalation
- CVE-2024-582891 PoCMicroweber 2.0.15 Stored Cross-Site Scripting via User Profile Fields
- CVE-2024-582902 PoCsXhibiter NFT Marketplace 1.10.2 SQL Injection via Collections Endpoint
- CVE-2024-582911 PoCFlatboard 3.2 Authenticated Stored Cross-Site Scripting via Forum Information Field
- CVE-2024-582921 PoCXMB Forum 1.9.12.06 Persistent Cross-Site Scripting via Admin Templates
- CVE-2024-582931 PoCAkaunting 3.1.8 Server-Side Template Injection via Multiple Form Fields
- CVE-2024-582941 PoCFreePBX 16 Authenticated Remote Code Execution via API Module
- CVE-2024-582951 PoCElkArte Forum 1.1.9 Authenticated Remote Code Execution via Theme Upload
- CVE-2024-582962 PoCsCE Phoenix v3.0.1 Stored Cross-Site Scripting via admin/currencies.php
- CVE-2024-582971 PoCPyroCMS v3.0.1 Stored Cross-Site Scripting via Admin Redirects
- CVE-2024-582981 PoCCompuware iStrobe Web 20.13 Pre-Auth Remote Code Execution via File Upload
- CVE-2024-582991 PoCPCMan FTP Server 2.0 Remote Buffer Overflow via 'pwd' Command
- CVE-2024-583001 PoCSiklu MultiHaul TG Series < 2.0.0 Unauthenticated Credential Disclosure Vulnerability
- CVE-2024-583011 PoCPurei CMS 1.0 SQL Injection via Multiple Vulnerable Endpoints
- CVE-2024-583021 PoCFoF Pretty Mail 1.1.2 Local File Inclusion via Email Template Settings
- CVE-2024-583031 PoCFoF Pretty Mail 1.1.2 Server Side Template Injection via Email Template Settings
- CVE-2024-583041 PoCSPA-CART CMS 1.9.0.3 Stored Cross-Site Scripting
- CVE-2024-583051 PoCWonderCMS 4.3.2 Cross-Site Scripting Remote Code Execution via Module Installation
- CVE-2024-583061 PoCminaliC 2.0.0 Denial of Service Vulnerability via Large GET Request
- CVE-2024-583071 PoCCSZCMS 1.3.0 Authenticated SQL Injection via Members View Endpoint
- CVE-2024-583081 PoCQuick.CMS 6.7 SQL Injection Authentication Bypass via Admin Login
- CVE-2024-583091 PoCxbtitFM 4.1.18 Unauthenticated SQL Injection in shoutedit.php
- CVE-2024-583101 PoCAPC Network Management Card 4 Path Traversal via Directory Traversal
- CVE-2024-583111 PoCDormakaba Saflok System 6000 Key Generation Cryptographic Weakness
- CVE-2024-583121 PoCxbtitFM 4.1.18 Unauthenticated Path Traversal in nfogen.php
- CVE-2024-583131 PoCxbtitFM 4.1.18 Insecure File Upload in file_hosting Feature
- CVE-2024-583141 PoCAtcom 2.7.x.x Authenticated Command Injection via Web Configuration CGI
- CVE-2024-583151 PoCTosibox Key Service 3.3.0 Local Privilege Escalation via Unquoted Service Path
- CVE-2024-583161 PoCOnline Shopping System Advanced 1.0 SQL Injection via Payment Success Parameter
- CVE-2024-583361 PoCAkuvox Smart Intercom S539 Unauthenticated Video Stream Disclosure
- CVE-2024-583371 PoCAkuvox Smart Intercom S539 Improper Access Control via ServicesHTTPAPI
- CVE-2024-583381 PoCAnevia Flamingo XL 3.2.9 Remote Root Jailbreak via Traceroute Command
- CVE-2024-583391 PoCLlamaIndex <= 0.12.2 VannaQueryEngine SQL Execution Allows Resource Exhaustion
- CVE-2024-583401 PoCLangChain <= 0.3.1 MRKLOutputParser ReDoS
- CVE-2024-583411 PoCOpenCart Core 4.0.2.3 SQL Injection via search Parameter
- CVE-2024-583431 PoCVision Helpdesk before 5.7.0 (patched in 5.6.10) allows attackers to read user profiles via modified serialized cookie data to…
- CVE-2024-583441 PoCCarbon Forum 5.9.0 Persistent XSS via Forum Name Field
- CVE-2024-583481 PoCWordPress Background Image Cropper 1.2 Remote Code Execution
- CVE-2024-583491 PoCWordPress Theme Travelscape 1.0.3 Arbitrary File Upload
- CVE-2024-583523 PoCsLandray OA Unauthenticated HQL Injection via wechatLoginHelper.do
- CVE-2024-583741 PoCHongjing e-HR Unauthenticated SQL Injection via getSdutyTree