CVE-2024-5000 to CVE-2024-5999
290 CVEs with public proof-of-concept exploits.
- CVE-2024-50021 PoCUser Submitted Posts < 20240516 - Admin+ Stored XSS
- CVE-2024-50031 PoCWP Stacker <= 1.8.5 - Stored XSS via CSRF
- CVE-2024-50041 PoCCM Popup Plugin for WordPress < 1.6.6 - Contributor+ Stored XSS
- CVE-2024-50051 PoCIncorrect Provision of Specified Functionality in GitLab
- CVE-2024-50092 PoCsWhatsUp Gold SetAdminPassword Improper Access Control Privilege Escalation Vulnerability
- CVE-2024-50171 PoCWhatsUp Gold AppProfileImport path traversal vulnerability
- CVE-2024-50261 PoCCM Tooltip Glossary < 4.3.4 - Admin+ Stored XSS
- CVE-2024-50281 PoCCM WordPress Search And Replace Plugin < 1.3.9 - Plugin Reset via CSRF
- CVE-2024-50291 PoCCM Table Of Contents – WordPress TOC Plugin < 1.2.4 - Stored XSS via CSRF
- CVE-2024-50301 PoCCM Table Of Contents – WordPress TOC Plugin < 1.2.3 - Settings Reset via CSRF
- CVE-2024-50321 PoCSULly < 4.3.1 - Reflected XSS
- CVE-2024-50331 PoCSULly < 4.3.1 - Admin+ Stored XSS via CSRF
- CVE-2024-50341 PoCSULly < 4.3.1 - Plugin Reset via CSRF
- CVE-2024-50431 PoCEmlog Pro setting.php unrestricted upload
- CVE-2024-50441 PoCEmlog Pro Cookie improper authentication
- CVE-2024-50451 PoCSourceCodester Online Birth Certificate Management System admin file access
- CVE-2024-50461 PoCSourceCodester Online Examination System registeracc.php sql injection
- CVE-2024-50471 PoCSourceCodester Student Management System controller.php unrestricted upload
- CVE-2024-50481 PoCcode-projects Budget Management index.php sql injection
- CVE-2024-50491 PoCCodezips E-Commerce Site editproduct.php unrestricted upload
- CVE-2024-50511 PoCSourceCodester Gas Agency Management System edituser.php sql injection
- CVE-2024-50571 PoCWordPress Easy Digital Downloads plugin <= 3.2.12 - SQL Injection vulnerability
- CVE-2024-50631 PoCPHPGurukul Online Course Registration System index.php sql injection
- CVE-2024-50641 PoCPHPGurukul Online Course Registration System news-details.php sql injection
- CVE-2024-50651 PoCPHPGurukul Online Course Registration System sql injection
- CVE-2024-50661 PoCPHPGurukul Online Course Registration System pincode-verification.php sql injection
- CVE-2024-50672 PoCsExposure of Sensitive Information to an Unauthorized Actor in GitLab
- CVE-2024-50691 PoCSourceCodester Simple Online Mens Salon Management System view_service.php sql injection
- CVE-2024-50711 PoCBookster <= 1.1.0 - Unauthenticated Appointment Status Update
- CVE-2024-50741 PoCWP eMember < 10.6.6 - Reflected XSS
- CVE-2024-50751 PoCWP eMember < 10.6.6 - Reflected XSS
- CVE-2024-50761 PoCWP eMember < 10.6.6 - Bulk Delete via CSRF
- CVE-2024-50771 PoCWP eMember < 10.6.6 - Stored XSS in Blacklist via CSRF
- CVE-2024-50791 PoCWP eMember < 10.6.7 - Unauthenticated Stored XSS via Member Registration
- CVE-2024-50801 PoCWP eMember < 10.6.6 - Admin+ Arbitrary File Upload
- CVE-2024-50811 PoCWP eMember <= v10.7.0 - Stored XSS via CSRF
- CVE-2024-50822 PoCsNexus Repository 2 - Remote Code Execution
- CVE-2024-50831 PoCNexus Repository 2 - Stored XSS
- CVE-2024-508412 PoCsHash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
- CVE-2024-50931 PoCSourceCodester Best House Rental Management System login.php sql injection
- CVE-2024-50941 PoCSourceCodester Best House Rental Management System view_payment.php sql injection
- CVE-2024-50951 PoCVictor Zsviot Camera MQTT Packet denial of service
- CVE-2024-50961 PoCHipcam Device MAC Address wifi.mac information disclosure
- CVE-2024-50971 PoCSourceCodester Simple Inventory System tableedit.php#page=editprice cross-site request forgery
- CVE-2024-50981 PoCSourceCodester Simple Inventory System login.php sql injection
- CVE-2024-50991 PoCSourceCodester Simple Inventory System updateprice.php sql injection
- CVE-2024-51001 PoCSourceCodester Simple Inventory System tableedit.php sql injection
- CVE-2024-51011 PoCSourceCodester Simple Inventory System updateproduct.php sql injection
- CVE-2024-51031 PoCCampcodes Complete Web-Based School Management System student_first_payment.php sql injection
- CVE-2024-51041 PoCCampcodes Complete Web-Based School Management System student_grade_wise.php sql injection
- CVE-2024-51051 PoCCampcodes Complete Web-Based School Management System student_payment_details.php sql injection
- CVE-2024-51061 PoCCampcodes Complete Web-Based School Management System student_payment_details3.php sql injection
- CVE-2024-51071 PoCCampcodes Complete Web-Based School Management System student_payment_details2.php sql injection
- CVE-2024-51081 PoCCampcodes Complete Web-Based School Management System student_payment_details4.php sql injection
- CVE-2024-51091 PoCCampcodes Complete Web-Based School Management System student_payment_history.php sql injection
- CVE-2024-51101 PoCCampcodes Complete Web-Based School Management System student_payment_invoice.php sql injection
- CVE-2024-51111 PoCCampcodes Complete Web-Based School Management System student_payment_invoice1.php sql injection
- CVE-2024-51121 PoCCampcodes Complete Web-Based School Management System student_profile.php sql injection
- CVE-2024-51131 PoCCampcodes Complete Web-Based School Management System student_profile1.php sql injection
- CVE-2024-51141 PoCCampcodes Complete Web-Based School Management System teacher_attendance_history1.php sql injection
- CVE-2024-51151 PoCCampcodes Complete Web-Based School Management System teacher_profile.php sql injection
- CVE-2024-51161 PoCSourceCodester Online Examination System save.php sql injection
- CVE-2024-51171 PoCSourceCodester Event Registration System portal.php sql injection
- CVE-2024-51181 PoCSourceCodester Event Registration System login.php sql injection
- CVE-2024-51191 PoCSourceCodester Event Registration System sql injection
- CVE-2024-51201 PoCSourceCodester Event Registration System sql injection
- CVE-2024-51211 PoCSourceCodester Event Registration System cross site scripting
- CVE-2024-51221 PoCSourceCodester Event Registration System sql injection
- CVE-2024-51231 PoCSourceCodester Event Registration System cross site scripting
- CVE-2024-51241 PoCTiming Attack Vulnerability in gaizhenbiao/chuanhuchatgpt
- CVE-2024-51341 PoCSourceCodester Electricity Consumption Monitoring Tool delete-bill.php sql injection
- CVE-2024-51351 PoCPHPGurukul Directory Management System index.php sql injection
- CVE-2024-51361 PoCPHPGurukul Directory Management System search-directory.php. cross site scripting
- CVE-2024-51371 PoCPHPGurukul Directory Management System Searchbar admin-profile.php cross site scripting
- CVE-2024-51381 PoCThe snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf…
- CVE-2024-51451 PoCSourceCodester Vehicle Management System HTTP POST Request newdriver.php unrestricted upload
- CVE-2024-51511 PoCSULly < 4.3.1 - Admin+ Stored XSS
- CVE-2024-51551 PoCInquiry Cart <= 3.4.2 - Stored XSS via CSRF
- CVE-2024-51571 PoCUse after free in Scheduling in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to execute arbitrary code inside a sandbox…
- CVE-2024-51581 PoCType Confusion in V8 in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to potentially perform arbitrary read/write via a…
- CVE-2024-51591 PoCHeap buffer overflow in ANGLE in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory read…
- CVE-2024-51671 PoCCM Email Registration Blacklist and Whitelist < 1.4.9 - Add/Delete Emails via CSRF Add and delete any item from blacklist/whitelist
- CVE-2024-51691 PoCVideo Widget <= 1.2.3 - Admin+ Stored XSS via Widget
- CVE-2024-51701 PoCLogo Manager For Enamad <= 0.7.1 - Admin+ Stored XSS via Widget
- CVE-2024-51721 PoCExpert Invoice <= 1.0.2 -Admin+ Stored XSS
- CVE-2024-51811 PoCCommand Injection in mudler/localai
- CVE-2024-51931 PoCRitlabs TinyWeb Server Request crlf injection
- CVE-2024-51941 PoCArris VAP2500 assoc_table.php command injection
- CVE-2024-51951 PoCArris VAP2500 diag_s.php command injection
- CVE-2024-51961 PoCArris VAP2500 tools_command.php command injection
- CVE-2024-51991 PoCSpotify Play Button <= 1.0 - Contributor+ Stored XSS
- CVE-2024-52001 PoCPostie < 1.9.71 - Admin+ Stored XSS
- CVE-2024-52172 PoCsKEVIncomplete Input Validation in GlideExpression Script
- CVE-2024-52301 PoCEnvaySoft FleetCart information disclosure
- CVE-2024-52311 PoCCampcodes Complete Web-Based School Management System teacher_salary_details.php sql injection
- CVE-2024-52321 PoCCampcodes Complete Web-Based School Management System teacher_salary_details2.php sql injection
- CVE-2024-52331 PoCCampcodes Complete Web-Based School Management System teacher_salary_details3.php sql injection
- CVE-2024-52341 PoCCampcodes Complete Web-Based School Management System teacher_salary_history1.php sql injection
- CVE-2024-52351 PoCCampcodes Complete Web-Based School Management System teacher_salary_invoice.php sql injection
- CVE-2024-52361 PoCCampcodes Complete Web-Based School Management System teacher_salary_invoice1.php sql injection
- CVE-2024-52371 PoCCampcodes Complete Web-Based School Management System timetable_grade_wise.php sql injection
- CVE-2024-52381 PoCCampcodes Complete Web-Based School Management System timetable_insert_form.php sql injection
- CVE-2024-52391 PoCCampcodes Complete Web-Based School Management System timetable_update_form.php sql injection
- CVE-2024-52401 PoCCampcodes Complete Web-Based School Management System unread_msg.php sql injection
- CVE-2024-52411 PoCHuashi Private Cloud CDN Live Streaming Acceleration Server ipconfig_new.php os command injection
- CVE-2024-52421 PoCTP-Link Omada ER605 Stack-based Buffer Overflow Remote Code Execution Vulnerability
- CVE-2024-52432 PoCsTP-Link Omada ER605 Buffer Overflow Remote Code Execution Vulnerability
- CVE-2024-52441 PoCTP-Link Omada ER605 Reliance on Security Through Obscurity Vulnerability
- CVE-2024-52461 PoCNETGEAR ProSAFE Network Management System Tomcat Remote Code Execution Vulnerability
- CVE-2024-52571 PoCImproper Access Control in GitLab
- CVE-2024-52744 PoCsKEVType Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a…
- CVE-2024-52763 PoCsSQL Injection Vulnerability in FileCatalyst Workflow 5.1.6 Build 135 (and earlier)
- CVE-2024-52791 PoCQiwen Netdisk File Rename cross site scripting
- CVE-2024-52801 PoCWP Affiliate Platform < 6.5.1 - POST Reflected XSS
- CVE-2024-52811 PoCWP Affiliate Platform < 6.5.1 - Reflected XSS via Affiliate Editing
- CVE-2024-52821 PoCWP Affiliate Platform < 6.5.1 - Reflected XSS via Registration Form
- CVE-2024-52831 PoCWP Affiliate Platform < 6.5.1 - Reflected XSS via Lead Editing
- CVE-2024-52841 PoCWP Affiliate Platform < 6.5.1 - Stored XSS via CSRF
- CVE-2024-52851 PoCWP Affiliate Platform < 6.5.2 - Affiliate Deletion via CSRF
- CVE-2024-52861 PoCWP Affiliate Platform < 6.5.1 - Reflected XSS via Banner Editing
- CVE-2024-52871 PoCWP Affiliate Platform < 6.5.1 - Profile Update via CSRF
- CVE-2024-52902 PoCsAn issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged…
- CVE-2024-53101 PoCJFinalCMS content cross site scripting
- CVE-2024-53152 PoCsMultiple vulnerabilities in DOLIBARR's ERP CMS
- CVE-2024-53182 PoCsMissing Authorization in GitLab
- CVE-2024-53241 PoCXootiX Framework <= Various Plugin Versions - Missing Authorization to Arbitrary Options Update
- CVE-2024-53262 PoCsPost Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.1.2 - Missing Authorization to Arbitrary Options Update
- CVE-2024-53332 PoCsThe Events Calendar < 6.8.2.1 - Unauthenticated Password Protected Event Disclosure
- CVE-2024-53341 PoCLocal File Read in stitionai/devika
- CVE-2024-53361 PoCRuijie RG-UAC vlan_add_commit.php addVlan os command injection
- CVE-2024-53371 PoCRuijie RG-UAC user_commit.php os command injection
- CVE-2024-53381 PoCRuijie RG-UAC online.php os command injection
- CVE-2024-53391 PoCRuijie RG-UAC online_check.php os command injection
- CVE-2024-53401 PoCRuijie RG-UAC sub_commit.php os command injection
- CVE-2024-53501 PoCanji-plus AJ-Report pageList sql injection
- CVE-2024-53511 PoCanji-plus AJ-Report Javascript getValueFromJs deserialization
- CVE-2024-53521 PoCanji-plus AJ-Report validationRules deserialization
- CVE-2024-53531 PoCanji-plus AJ-Report ZIP File decompress path traversal
- CVE-2024-53541 PoCanji-plus AJ-Report detailByCode information disclosure
- CVE-2024-53551 PoCanji-plus AJ-Report IGroovyHandler command injection
- CVE-2024-53562 PoCsanji-plus AJ-Report testTransform;swagger-ui sql injection
- CVE-2024-53571 PoCPHPGurukul Zoo Management System forgot-password.php sql injection
- CVE-2024-53581 PoCPHPGurukul Zoo Management System normal-search.php sql injection
- CVE-2024-53591 PoCPHPGurukul Zoo Management System foreigner-search.php sql injection
- CVE-2024-53601 PoCPHPGurukul Zoo Management System foreigner-bwdates-reports-details.php sql injection
- CVE-2024-53611 PoCPHPGurukul Zoo Management System normal-bwdates-reports-details.php sql injection
- CVE-2024-53621 PoCSourceCodester Online Hospital Management System departmentDoctor.php sql injection
- CVE-2024-53631 PoCSourceCodester Best House Rental Management System manage_user.php sql injection
- CVE-2024-53641 PoCSourceCodester Best House Rental Management System manage_tenant.php sql injection
- CVE-2024-53651 PoCSourceCodester Best House Rental Management System manage_payment.php sql injection
- CVE-2024-53661 PoCSourceCodester Best House Rental Management System edit-cate.php sql injection
- CVE-2024-53671 PoCKashipara College Management System each_extracurricula_activities.php cross site scripting
- CVE-2024-53681 PoCKashipara College Management System delete_faculty.php cross site scripting
- CVE-2024-53691 PoCKashipara College Management System submit_admin.php cross site scripting
- CVE-2024-53701 PoCKashipara College Management System submit_enroll_staff.php cross site scripting
- CVE-2024-53711 PoCKashipara College Management System submit_enroll_student.php cross site scripting
- CVE-2024-53721 PoCKashipara College Management System submit_extracurricular_activity.php cross site scripting
- CVE-2024-53731 PoCKashipara College Management System submit_login.php cross site scripting
- CVE-2024-53741 PoCKashipara College Management System submit_new_faculty.php cross site scripting
- CVE-2024-53751 PoCKashipara College Management System submit_student.php cross site scripting
- CVE-2024-53761 PoCKashipara College Management System view_each_faculty.php cross site scripting
- CVE-2024-53771 PoCSourceCodester Vehicle Management System newvehicle.php unrestricted upload
- CVE-2024-53781 PoCSourceCodester School Intramurals Student Attendance Management System manage_sy.php sql injection
- CVE-2024-53791 PoCJFinalCMS template cross site scripting
- CVE-2024-53811 PoCitsourcecode Student Information Management System view.php sql injection
- CVE-2024-53831 PoClakernote EasyAdmin upload cross site scripting
- CVE-2024-53901 PoCitsourcecode Online Student Enrollment System listofstudent.php sql injection
- CVE-2024-53911 PoCitsourcecode Online Student Enrollment System listofsubject.php sql injection
- CVE-2024-53921 PoCitsourcecode Online Student Enrollment System editSubject.php sql injection
- CVE-2024-53931 PoCitsourcecode Online Student Enrollment System listofcourse.php sql injection
- CVE-2024-53941 PoCitsourcecode Online Student Enrollment System newDept.php sql injection
- CVE-2024-53951 PoCitsourcecode Online Student Enrollment System listofinstructor.php sql injection
- CVE-2024-53961 PoCitsourcecode Online Student Enrollment System newfaculty.php sql injection
- CVE-2024-53971 PoCitsourcecode Online Student Enrollment System instructorSubjects.php sql injection
- CVE-2024-54102 PoCsStored Cross-Site Scripting
- CVE-2024-54112 PoCsCommand Injection
- CVE-2024-54171 PoCGutentor < 3.3.6 - Contributor+ Stored XSS
- CVE-2024-54203 PoCsStored Cross-Site Scripting in SEH Computertechnik utnserver Pro
- CVE-2024-54211 PoCAuthenticated Command Injection
- CVE-2024-54231 PoCUncontrolled Resource Consumption in GitLab
- CVE-2024-54291 PoCLogo Slider < 4.1.0 - Contributor+ Stored XSS
- CVE-2024-54301 PoCImproper Access Control in GitLab
- CVE-2024-54351 PoCGeneration of Error Message Containing Sensitive Information in GitLab
- CVE-2024-54371 PoCSourceCodester Simple Online Bidding System save_category cross site scripting
- CVE-2024-54401 PoCIf-So Dynamic Content Personalization < 1.8.0.3 - Contributor+ Shortcode Stored XSS
- CVE-2024-54421 PoCNextGEN Gallery < 3.59.3 - Admin+ Stored XSS
- CVE-2024-54441 PoCBible Text <= 0.2 - Contributor+ Stored XSS
- CVE-2024-54471 PoCPayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode <= 1.7 - Admin+ Stored XSS
- CVE-2024-54481 PoCPayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode <= 1.7 - Contributor+ Stored XSS
- CVE-2024-54501 PoCBug Library < 2.1.1 - Unauthenticated RCE
- CVE-2024-54521 PoCRCE via Property/Class Pollution in lightning-ai/pytorch-lightning
- CVE-2024-54582 PoCsFilter bypass in filter_var (FILTER_VALIDATE_URL)
- CVE-2024-54701 PoCImproper Access Control in GitLab
- CVE-2024-54721 PoCWP QuickLaTeX < 3.8.7 - Admin+ Stored XSS in Background Color field
- CVE-2024-54731 PoCSimple Photoswipe <= 0.1 - Admin+ Stored XSS
- CVE-2024-54751 PoCResponsive video embed < 0.5.1 - Contributor+ Stored XSS
- CVE-2024-54831 PoCLearnPress – WordPress LMS Plugin <= 4.2.6.8 - Basic Information Disclosure via JSON API
- CVE-2024-54882 PoCsSEOPress < 7.9 - Unauthenticated Object Injection
- CVE-2024-54991 PoCOut of bounds write in Streams API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a…
- CVE-2024-55151 PoCSourceCodester Stock Management System createBrand.php sql injection
- CVE-2024-55161 PoCitsourcecode Online Blood Bank Management System massage.php sql injection
- CVE-2024-55171 PoCitsourcecode Online Blood Bank Management System changepwd.php sql injection
- CVE-2024-55181 PoCitsourcecode Online Discussion Forum change_profile_picture.php unrestricted upload
- CVE-2024-55191 PoCItsourceCode Learning Management System Project In PHP login.php sql injection
- CVE-2024-55225 PoCsHTML5 Video Player < 2.5.27 - Unauthenticated SQLi
- CVE-2024-55281 PoCIncomplete Comparison with Missing Factors in GitLab
- CVE-2024-55291 PoCWP QuickLaTeX < 3.8.8 - Admin+ Stored XSS
- CVE-2024-55351 PoCSSL_select_next_proto buffer overread
- CVE-2024-55611 PoCPopup Maker < 1.19.1 - Admin+ Stored XSS
- CVE-2024-55701 PoCSimple Photoswipe <= 0.1 - Subscriber+ Arbitrary Settings Update
- CVE-2024-55731 PoCEasy Table of Contents < 2.0.66 - Admin+ Stored XSS
- CVE-2024-55751 PoCDitty < 3.1.43 - Author+ Stored XSS
- CVE-2024-55781 PoCTable of Contents Plus <= 2408 - Editor+ Stored XSS
- CVE-2024-55852 PoCsCommand injection via array-ish $command parameter of proc_open() (bypass CVE-2024-1874 fix)
- CVE-2024-55871 PoCCasdoor Configuration File app.conf file access
- CVE-2024-55881 PoCitsourcecode Learning Management System processscore.php sql injection
- CVE-2024-55891 PoCNetentsec NS-ASG Application Security Gateway sql injection
- CVE-2024-55901 PoCNetentsec NS-ASG Application Security Gateway JSON Content uploadiscuser.php sql injection
- CVE-2024-55951 PoCEssential Blocks < 4.7.0 - Contributor+ Stored XSS
- CVE-2024-56041 PoCBug Library < 2.1.2 - Admin+ Stored XSS
- CVE-2024-56061 PoCQuiz And Survey Master < 9.0.2 - Contributor+ SQLi
- CVE-2024-56261 PoCInline Related Posts < 3.7.0 - Reflected XSS
- CVE-2024-56271 PoCWordPress Plugin Tournamatch < 4.6.1 - Subscriber+ Stored XSS
- CVE-2024-56281 PoCAvada | Website Builder For WordPress & eCommerce <= 3.11.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via fusion_button…
- CVE-2024-56301 PoCInsert or Embed Articulate Content into WordPress < 4.3000000024 - Author+ Arbitrary File Upload
- CVE-2024-56331 PoCLongse model LBH30FE200W cameras, as well as products based on this device, provide an unrestricted access for an attacker located in the…
- CVE-2024-56351 PoCitsourcecode Bakery Online Ordering System index.php sql injection
- CVE-2024-56361 PoCitsourcecode Bakery Online Ordering System index.php sql injection
- CVE-2024-56441 PoCWordPress Plugin Tournamatch < 4.6.1 - Admin+ Stored XSS via Ladders
- CVE-2024-56531 PoCChanjet Smooth T+system keyEdit.aspx sql injection
- CVE-2024-56551 PoCImproper Access Control in GitLab
- CVE-2024-56572 PoCsCraftCMS Plugin - Two-Factor Authentication - Password Hash Disclosure
- CVE-2024-56582 PoCsCraftCMS Plugin - Two-Factor Authentication - TOTP Token Stays Valid After Use
- CVE-2024-56921 PoCOn Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed…
- CVE-2024-57131 PoCif-so < 1.8.0.4 - Reflected XSS
- CVE-2024-57151 PoCWP eMember < 10.6.7 - Reflected XSS via Member Edit
- CVE-2024-57211 PoCLogsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability
- CVE-2024-57271 PoCWidget4Call <= 1.0.7 - Reflected XSS
- CVE-2024-57281 PoCAnimated AL List <= 1.0.6 - Reflected XSS
- CVE-2024-57291 PoCSimple AL Slider <= 1.2.10 - Reflected XSS
- CVE-2024-57301 PoCPagerank Tools <= 1.1.5 - Reflected XSS
- CVE-2024-57321 PoCClash Proxy Port improper authentication
- CVE-2024-57331 PoCitsourcecode Online Discussion Forum register_me.php sql injection
- CVE-2024-57341 PoCitsourcecode Online Discussion Forum poster.php unrestricted upload
- CVE-2024-57351 PoCFull Path Disclosure in AdmirorFrames Joomla! Extension
- CVE-2024-57361 PoCSSRF in AdmirorFrames Joomla! Extension
- CVE-2024-57372 PoCsHTML Injection in AdmirorFrames Joomla! Extension
- CVE-2024-57441 PoCWP eMember < 10.6.7 - Reflected XSS
- CVE-2024-57451 PoCitsourcecode Bakery Online Ordering System unrestricted upload
- CVE-2024-57641 PoCNexus Repository 3 - Static hard-coded encryption passphrase used by default
- CVE-2024-57652 PoCsWpStickyBar <= 2.1.0 - Unauthenticated SQLi
- CVE-2024-57671 PoCSitetweet <= 0.2 - Stored XSS via CSRF
- CVE-2024-57711 PoCLabVantage LIMS POST Request sql injection
- CVE-2024-57721 PoCNetentsec NS-ASG Application Security Gateway deleteiscuser.php sql injection
- CVE-2024-57731 PoCNetentsec NS-ASG Application Security Gateway deletemacbind.php sql injection
- CVE-2024-57741 PoCSourceCodester Stock Management System Login index.php sql injection
- CVE-2024-57751 PoCSourceCodester Vehicle Management System updatebill.php sql injection
- CVE-2024-57991 PoCCM Pop-Up Banners for WordPress < 1.7.3 - Contributor+ Stored XSS
- CVE-2024-58021 PoCURL Shortener by MyThemeShop <= 1.0.17 - Admin+ Stored XSS
- CVE-2024-58063 PoCsMOVEit Transfer Authentication Bypass Vulnerability
- CVE-2024-58071 PoCBusiness Card <= 1.0.0 - Admin+ File Upload
- CVE-2024-58081 PoCWP Ajax Contact Form <= 2.2.2 - Arbitrary Email Deletion via CSRF
- CVE-2024-58091 PoCWP Ajax Contact Form <= 2.2.2 - Reflected Cross-Site Scripting
- CVE-2024-58111 PoCSimple Video Directory < 1.4.4 - Contributor+ Stored XSS
- CVE-2024-58271 PoCArbitrary File Write by Prompt Injection via DuckDB SQL in vanna-ai/vanna
- CVE-2024-58291 PoCsmallweigit Avue avueUeditor cross site scripting
- CVE-2024-58302 PoCsType Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory write via a…
- CVE-2024-58361 PoCInappropriate Implementation in DevTools in Google Chrome prior to 126.0.6478.54 allowed an attacker who convinced a user to install a…
- CVE-2024-58821 PoCUltimate Classified Listings < 1.3 - Unauthenticated LFI
- CVE-2024-58831 PoCUltimate Classified Listings < 1.3 - Reflected XSS
- CVE-2024-58931 PoCSourceCodester Cab Management System sql injection
- CVE-2024-58941 PoCSourceCodester Online Eyewear Shop manage_product.php sql injection
- CVE-2024-58951 PoCSourceCodester Employee and Visitor Gate Pass Logging System delete_users sql injection
- CVE-2024-58961 PoCSourceCodester Employee and Visitor Gate Pass Logging System save_users sql injection
- CVE-2024-58971 PoCSourceCodester Employee and Visitor Gate Pass Logging System cross site scripting
- CVE-2024-58981 PoCitsourcecode Payroll Management System print_payroll.php sql injection
- CVE-2024-59105 PoCsKEVExpedition: Missing Authentication Leads to Admin Account Takeover
- CVE-2024-59212 PoCsGlobalProtect App: Insufficient Certificate Validation Leads to Privilege Escalation
- CVE-2024-593211 PoCsGiveWP – Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution
- CVE-2024-59361 PoCOpen Redirect in imartinez/privategpt
- CVE-2024-59472 PoCsDeep Sea Electronics DSE855 Configuration Backup Missing Authentication Information Disclosure Vulnerability
- CVE-2024-59611 PoCReflected XSS in 2ClickPortal
- CVE-2024-59681 PoCPhoto Gallery by 10Web <= 1.8.27 - Admin+ Stored XSS
- CVE-2024-59731 PoCMasterStudy LMS < 3.3.24 - Privilege Escalation to Instructor
- CVE-2024-59752 PoCsCZ Loan Management <= 1.1 - Unauthenticated SQLi
- CVE-2024-59761 PoCSourceCodester Employee and Visitor Gate Pass Logging System log_employee sql injection
- CVE-2024-59811 PoCitsourcecode Online House Rental System manage_user.php sql injection
- CVE-2024-59831 PoCitsourcecode Online Bookstore bookPerPub.php sql injection
- CVE-2024-59841 PoCitsourcecode Online Bookstore book.php sql injection
- CVE-2024-59851 PoCSourceCodester Best Online News Portal index.php sql injection