CVE-2024-6000 to CVE-2024-6999
378 CVEs with public proof-of-concept exploits.
- CVE-2024-60031 PoCGuangdong Baolun Electronics IP Network Broadcasting Service Platform maps sql injection
- CVE-2024-60061 PoCZKTeco ZKBio CVSecurity V5000 Summer Schedule cross site scripting
- CVE-2024-60071 PoCNetentsec NS-ASG Application Security Gateway deleteiscgwrouteconf.php sql injection
- CVE-2024-60081 PoCitsourcecode Online Book Store edit_book.php sql injection
- CVE-2024-60091 PoCitsourcecode Event Calendar process.php regDelete sql injection
- CVE-2024-60131 PoCitsourcecode Online Book Store admin_delete.php sql injection
- CVE-2024-60141 PoCitsourcecode Document Management System edithis.php sql injection
- CVE-2024-60151 PoCitsourcecode Online House Rental System manage_user.php sql injection
- CVE-2024-60161 PoCitsourcecode Online Laundry Management System admin_class.php sql injection
- CVE-2024-60171 PoCMusic Request Manager <= 1.3 - Stored XSS via CSRF
- CVE-2024-60181 PoCMusic Request Manager <= 1.3 - Reflected XSS
- CVE-2024-60191 PoCMusic Request Manager <= 1.3 - Unauthenticated Stored XSS
- CVE-2024-60201 PoCSign-up Sheets < 2.2.13 - Reflected XSS
- CVE-2024-60211 PoCDonation Block for PayPal <= 2.1.0 - Unauthenticated Stored XSS
- CVE-2024-60221 PoCContentLock <= 1.0.3 - Settings Update via CSRF
- CVE-2024-60231 PoCContentLock <= 1.0.3 - Email Adding via CSRF
- CVE-2024-60241 PoCContentLock <= 1.0.3 - Groups/Emails Deletion via CSRF
- CVE-2024-60251 PoCQuiz and Survey Master < 9.0.5 - Contributor+ Stored XSS
- CVE-2024-60261 PoCSlider by 10Web < 1.2.56 - Editor+ Stored XSS
- CVE-2024-60282 PoCsQuiz Maker <= 6.5.8.3 - Unauthenticated SQL Injection via 'ays_questions' Parameter
- CVE-2024-60392 PoCsFeng Office Workspaces sql injection
- CVE-2024-60411 PoCitsourcecode Gym Management System manage_user.php sql injection
- CVE-2024-60421 PoCitsourcecode Real Estate Management System property-detail.php sql injection
- CVE-2024-60432 PoCsSourceCodester Best House Rental Management System admin_class.php login sql injection
- CVE-2024-60471 PoCKEVGeoVision EOL device - OS Command Injection
- CVE-2024-60491 PoCUnauthenticated Path Traversal
- CVE-2024-60501 PoCReflected XSS in SOWA OPAC
- CVE-2024-60561 PoCnasirkhan Laravel Starter Password Reset forgot-password observable response discrepancy
- CVE-2024-60581 PoCLabVantage LIMS cross site scripting
- CVE-2024-60591 PoCIngenico Estate Manager News Feed messages cross site scripting
- CVE-2024-60612 PoCsGPAC MP4Box isoffin_read.c isoffin_process infinite loop
- CVE-2024-60622 PoCsGPAC MP4Box load_text.c swf_svg_add_iso_sample null pointer dereference
- CVE-2024-60632 PoCsGPAC MP4Box dmx_m2ts.c m2tsdmx_on_event null pointer dereference
- CVE-2024-60642 PoCsGPAC MP4Box loader_xmt.c xmt_node_end use after free
- CVE-2024-60651 PoCitsourcecode Bakery Online Ordering System index.php sql injection
- CVE-2024-60661 PoCSourceCodester Best House Rental Management System payment_report.php sql injection
- CVE-2024-60671 PoCSourceCodester Music Class Enrollment System sql injection
- CVE-2024-60701 PoCif-so < 1.8.0.4 - Admin+ Stored XSS
- CVE-2024-60721 PoCWP eStore < 8.5.5 - Reflected XSS via $_SERVER['REQUEST_URI']
- CVE-2024-60731 PoCWP eStore < 8.5.5 - Reflected XSS in Discount Editing
- CVE-2024-60741 PoCWP eStore < 8.5.5 - Reflected XSS in Customer Editing
- CVE-2024-60751 PoCWP eStore < 8.5.5 - Coupon Deletion via CSRF
- CVE-2024-60761 PoCWP eStore < 8.5.5 - Reflected XSS in Category Editing
- CVE-2024-60821 PoCPHPVibe Global Options Page functionalities.global.php cross site scripting
- CVE-2024-60831 PoCPHPVibe Media Upload Page upload-mp3.php unrestricted upload
- CVE-2024-60841 PoCitsourcecode Pool of Bethesda Online Reservation System uploadImage unrestricted upload
- CVE-2024-60941 PoCWP ULike < 4.7.1 - Admin+ Stored XSS
- CVE-2024-60952 PoCsSSRF and Partial LFI in /models/apply Endpoint in mudler/localai
- CVE-2024-61091 PoCitsourcecode Tailoring Management System addmeasurement.php sql injection
- CVE-2024-61101 PoCitsourcecode Magbanua Beach Resort Online Reservation System controller.php unrestricted upload
- CVE-2024-61111 PoCitsourcecode Pool of Bethesda Online Reservation System login.php sql injection
- CVE-2024-61121 PoCitsourcecode Pool of Bethesda Online Reservation System index.php sql injection
- CVE-2024-61131 PoCitsourcecode Monbela Tourist Inn Online Reservation System login.php sql injection
- CVE-2024-61141 PoCitsourcecode Monbela Tourist Inn Online Reservation System controller.php unrestricted upload
- CVE-2024-61151 PoCitsourcecode Simple Online Hotel Reservation System add_room.php unrestricted upload
- CVE-2024-61161 PoCitsourcecode Simple Online Hotel Reservation System edit_room.php unrestricted upload
- CVE-2024-61272 PoCsBC Security Empire Path Traversal RCE
- CVE-2024-61281 PoCspa-cartcms Checkout Page checkout behavioral workflow
- CVE-2024-61291 PoCspa-cartcms Username login observable behavioral discrepancy
- CVE-2024-61301 PoCForm Maker by 10Web < 1.15.26 - Admin+ Stored XSS
- CVE-2024-61321 PoCPexels: Free Stock Photos <= 1.2.2 - Authenticated (Contributor+) Arbitrary File Upload
- CVE-2024-61331 PoCWP eStore < 8.5.6 - Reflected XSS in Customer Search
- CVE-2024-61341 PoCWP eStore < 8.5.6 - Reflected XSS in Product Editing
- CVE-2024-61361 PoCWP eStore < 8.5.6 - Settings Reset via CSRF
- CVE-2024-61371 PoCBT: Classic: SDP OOB access in get_att_search_list
- CVE-2024-61381 PoCSecure Copy Content Protection < 4.0.9 - Admin+ Stored XSS
- CVE-2024-61562 PoCsMark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust…
- CVE-2024-61581 PoCCategory Posts Widget (Free < 4.9.17, Pro < 4.9.13) - Admin+ Stored XSS
- CVE-2024-61592 PoCsPush Notification for Post and BuddyPress <=1.93 - Multiple Unauthenticated SQLi
- CVE-2024-61641 PoCFilter & Grids < 2.8.33 - Unauthenticated LFI
- CVE-2024-61651 PoCWANotifier < 2.6.1 - Admin+ Stored XSS
- CVE-2024-61811 PoCLabVantage LIMS cross site scripting
- CVE-2024-61821 PoCLabVantage LIMS cross site scripting
- CVE-2024-61841 PoCRuijie RG-UAC reboot_commit.php os command injection
- CVE-2024-61851 PoCRuijie RG-UAC commit.php get_ip_addr_details os command injection
- CVE-2024-61861 PoCRuijie RG-UAC commit.php os command injection
- CVE-2024-61871 PoCRuijie RG-UAC sub_commit.php os command injection
- CVE-2024-61882 PoCsParsec Automation TrackSYS pagedefinition direct request
- CVE-2024-61891 PoCTenda A301 WifiExtraSet fromSetWirelessRepeat stack-based overflow
- CVE-2024-61901 PoCitsourcecode Farm Management System Login index.php sql injection
- CVE-2024-61911 PoCitsourcecode Student Management System Login Page login.php sql injection
- CVE-2024-61921 PoCitsourcecode Loan Management System Login Page login.php sql injection
- CVE-2024-61931 PoCitsourcecode Vehicle Management System driverprofile.php sql injection
- CVE-2024-61941 PoCitsourcecode Tailoring Management System editmeasurement.php sql injection
- CVE-2024-61951 PoCitsourcecode Tailoring Management System orderadd.php sql injection
- CVE-2024-61961 PoCitsourcecode Banking Management System admin_class.php sql injection
- CVE-2024-62053 PoCsPayPlus Payment Gateway < 6.6.9 - Unauthenticated SQLi
- CVE-2024-62091 PoCunauthorized file access
- CVE-2024-62121 PoCSourceCodester Simple Student Attendance System student_form.php get_student cross site scripting
- CVE-2024-62131 PoCSourceCodester Food Ordering Management System Login Panel login.php sql injection
- CVE-2024-62141 PoCSourceCodester Food Ordering Management System add-item.php sql injection
- CVE-2024-62151 PoCSourceCodester Food Ordering Management System view-ticket-admin.php sql injection
- CVE-2024-62161 PoCSourceCodester Food Ordering Management System add-users.php sql injection
- CVE-2024-62171 PoCSourceCodester Food Ordering Management System user-router.php sql injection
- CVE-2024-62181 PoCitsourcecode Vehicle Management System busprofile.php sql injection
- CVE-2024-62191 PoCMark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its…
- CVE-2024-62201 PoC简数采集器 (Keydatas) <= 2.5.2 - Unauthenticated Arbitrary File Upload
- CVE-2024-62231 PoCSend email only on Reply to My Comment <= 1.0.6 - Reflected XSS
- CVE-2024-62241 PoCSend email only on Reply to My Comment <= 1.0.6 - Stored XSS via CSRF
- CVE-2024-62261 PoCWpStickyBar <= 2.1.0 - Reflected XSS
- CVE-2024-62281 PoCWANotifier < 2.6 - Subscriber+ LFI
- CVE-2024-62301 PoCPardakht Delkhah <= 2.9.8 - Form Fields Reset via CSRF
- CVE-2024-62311 PoCRequest a Quote < 2.4.1 - Admin+ Stored XSS
- CVE-2024-62321 PoCRegular-expression DoS when parsing TarFile headers
- CVE-2024-62351 PoCSensitive information disclosure
- CVE-2024-62391 PoCPoppler: pdfinfo: crash in broken documents when using -dests parameter
- CVE-2024-62411 PoCPear Admin Boot getDictItems sql injection
- CVE-2024-62431 PoCHTML Forms < 1.3.33 - Admin+ Stored XSS
- CVE-2024-62443 PoCspz-frontend-manager < 1.0.6 - CSRF change user profile picture
- CVE-2024-62501 PoCAbsolute Path Traversal in parisneo/lollms-webui
- CVE-2024-62521 PoCZorlan SkyCaiji Task cross site scripting
- CVE-2024-62531 PoCitsourcecode Online Food Ordering System purchase.php sql injection
- CVE-2024-62581 PoCBT: Missing length checks of net_buf in rfcomm_handle_data
- CVE-2024-62591 PoCBT: HCI: adv_ext_report Improper discarding in adv_ext_report
- CVE-2024-62651 PoCUsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress <= 1.2.10 - Unauthenticated SQL…
- CVE-2024-62661 PoCPear Admin Boot loadDictItem sql injection
- CVE-2024-62672 PoCsSourceCodester Service Provider Management System System Info Page index.php cross site scripting
- CVE-2024-62681 PoClahirudanushka School Management System Login Page login.php sql injection
- CVE-2024-62691 PoCRuijie RG-UAC HTTP POST Request sxh_vpnlic.php get_ip.addr_details command injection
- CVE-2024-62701 PoCCommunity Events < 1.5.1 - Admin+ Stored XSS
- CVE-2024-62711 PoCCommunity Events < 1.5 - Event Deletion via CSRF
- CVE-2024-62721 PoCSpiderContacts <= 1.1.7 - Reflected XSS
- CVE-2024-62732 PoCsSourceCodester Clinic Queuing System patient_side.php save_patient cross site scripting
- CVE-2024-62741 PoClahirudanushka School Management System Attendance Report Page attendancelist.php sql injection
- CVE-2024-62751 PoClahirudanushka School Management System Parent Page parent.php sql injection
- CVE-2024-62761 PoClahirudanushka School Management System Teacher Page teacher.php sql injection
- CVE-2024-62771 PoClahirudanushka School Management System Student Page student.php sql injection
- CVE-2024-62781 PoClahirudanushka School Management System Subject Page subject.php sql injection
- CVE-2024-62791 PoClahirudanushka School Management System Exam Results Page examresults-par.php sql injection
- CVE-2024-62801 PoCSourceCodester Simple Online Bidding System unrestricted upload
- CVE-2024-62892 PoCsWPS Hide Login < 1.9.16.4 - Hidden Login Page Disclosure
- CVE-2024-62911 PoCUse after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption…
- CVE-2024-62981 PoCremote code execution
- CVE-2024-63071 PoCWordPress Core < 6.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML API
- CVE-2024-63081 PoCitsourcecode Simple Online Hotel Reservation System index.php sql injection
- CVE-2024-63241 PoCInefficient Algorithmic Complexity in GitLab
- CVE-2024-63291 PoCImproper Encoding or Escaping of Output in GitLab
- CVE-2024-63303 PoCsGEO my WordPress < 4.4.0.2 - Unauthenticated RCE via LFI
- CVE-2024-63331 PoCAuthenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products
- CVE-2024-63341 PoCEasy Table of Contents < 2.0.67 - Editor+ Stored XSS
- CVE-2024-63351 PoCTracking Code Manager < 2.3.0- Admin+ Stored Cross-Site Scripting
- CVE-2024-63561 PoCIncorrect User Management in GitLab
- CVE-2024-63621 PoCUltimate Blocks < 3.2.0 - Contributor+ Stored XSS
- CVE-2024-63664 PoCsUser Profile Builder < 3.11.8 - Unauthenticated Media Upload
- CVE-2024-63671 PoCLabVantage LIMS POST Request cross site scripting
- CVE-2024-63681 PoCLabVantage LIMS POST Request cross site scripting
- CVE-2024-63691 PoCLabVantage LIMS POST Request cross site scripting
- CVE-2024-63701 PoCLabVantage LIMS POST Request cross site scripting
- CVE-2024-63711 PoCitsourcecode Pool of Bethesda Online Reservation System controller.php sql injection
- CVE-2024-63721 PoCitsourcecode Tailoring Management System customeradd.php sql injection
- CVE-2024-63731 PoCitsourcecode Online Food Ordering System addproduct.php unrestricted upload
- CVE-2024-63741 PoClahirudanushka School Management System Subject Page subject.php cross site scripting
- CVE-2024-63851 PoCImproper Access Control in GitLab
- CVE-2024-63864 PoCsWPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection
- CVE-2024-638780 PoCsOpenssh: regresshion - race condition in ssh allows rce/dos
- CVE-2024-63891 PoCExposure of Sensitive System Information to an Unauthorized Control Sphere in GitLab
- CVE-2024-63901 PoCQuiz and Survey Master (QSM) < 9.1.0 - Contributor+ Stored XSS
- CVE-2024-63931 PoCNextGEN Gallery < 3.59.5 - Admin+ Stored XSS
- CVE-2024-63961 PoCArbitrary File Overwrite and Data Exfiltration in aimhubio/aim
- CVE-2024-64021 PoCTenda A301 SetOnlineDevName fromSetWirelessRepeat stack-based overflow
- CVE-2024-64031 PoCTenda A301 SetOnlineDevName formWifiBasicSet stack-based overflow
- CVE-2024-64081 PoCSlider by 10Web < 1.2.57 - Editor+ Stored XSS
- CVE-2024-64091 PoCOpenssh: possible remote code execution due to a race condition in signal handling affecting red hat enterprise linux 9
- CVE-2024-64121 PoCHTML Forms – Simple WordPress Forms Plugin < 1.3.34 - Bulk Delete via CSRF
- CVE-2024-64141 PoCParsec Automation TrakSYS Export Page contentpage direct request
- CVE-2024-64151 PoCIngenico Estate Manager New Widget cross site scripting
- CVE-2024-64161 PoCSeaCMS sql injection
- CVE-2024-64171 PoCSourceCodester Simple Online Bidding System sql injection
- CVE-2024-64181 PoCSourceCodester Medicine Tracker System sql injection
- CVE-2024-64191 PoCSourceCodester Medicine Tracker System sql injection
- CVE-2024-64202 PoCsHide My WP Ghost < 5.2.02 - Hidden Login Page Disclosure
- CVE-2024-64381 PoCHitout Carsale OrderController.java sql injection
- CVE-2024-64391 PoCSourceCodester Home Owners Collection Management System unrestricted upload
- CVE-2024-64401 PoCSourceCodester Home Owners Collection Management System sql injection
- CVE-2024-64431 PoCzephyr: out-of-bound read in utf8_trunc
- CVE-2024-64461 PoCBusiness Logic Errors in GitLab
- CVE-2024-64511 PoCAI Engine < 2.5.1 - Admin+ RCE
- CVE-2024-64521 PoClinlinjava litemall AdminGoodscontroller.java sql injection
- CVE-2024-64531 PoCitsourcecode Farm Management System sql injection
- CVE-2024-64591 PoCNews Element Elementor Blog Magazine < 1.0.6 - Unauthenticated LFI
- CVE-2024-64604 PoCsGrow by Tradedoubler <= 2.0.21 - Unauthenticated LFI
- CVE-2024-64621 PoCDL Yandex Metrika <= 1.2 - Admin+ Stored XSS
- CVE-2024-64711 PoCSourceCodester Online Tours & Travels Management sms_setting.php sql injection
- CVE-2024-64731 PoCDLL Hijacking in Yandex Browser
- CVE-2024-64771 PoCUsersWP < 1.2.12 - Users Information Disclosure
- CVE-2024-64781 PoCCTT Expresso para WooCommerce < 3.2.13 - Admin+ Stored XSS
- CVE-2024-64811 PoCSearch Filter Pro < 2.5.18 - Admin+ Stored XSS
- CVE-2024-64852 PoCsXSS in Bootstrap button component
- CVE-2024-64861 PoCImageMagick Engine < 1.7.11 - Administrator+ OS Command Injection
- CVE-2024-64871 PoCInline Related Posts < 3.8.0 - Admin+ Stored XSS
- CVE-2024-64901 PoCMaster Slider – Responsive Touch Slider <= 3.9.10 - CSRF to slider deletion
- CVE-2024-64931 PoCNinjaTeam Header Footer Custom Code < 1.2 - Admin+ Stored XSS
- CVE-2024-64941 PoCWordPress File Upload < 4.24.8 - Unauthenticated Stored XSS
- CVE-2024-64961 PoCLight Poll <= 1.0.0 - Polls Deletion via CSRF
- CVE-2024-64981 PoCCollectChat < 2.4.4 - Admin+ XSS
- CVE-2024-65021 PoCIncorrect Provision of Specified Functionality in GitLab
- CVE-2024-65111 PoCy_project RuoYi Content-Type isJsonRequest cross site scripting
- CVE-2024-65163 PoCsCross Site Scripting XSS
- CVE-2024-65172 PoCsContact Form 7 Math Captcha <= 2.0.1 - Reflected XSS
- CVE-2024-65232 PoCsZKTeco BioTime system-group-add cross site scripting
- CVE-2024-65241 PoCShopXO Uploader.php server-side request forgery
- CVE-2024-65251 PoCD-Link DAR-7000 decodmail.php deserialization
- CVE-2024-65262 PoCsCodeIgniter Ecommerce-CodeIgniter-Bootstrap cross site scripting
- CVE-2024-65292 PoCsUltimate Classified Listings < 1.4 - Reflected XSS
- CVE-2024-65301 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2024-65332 PoCsDirectus 10.13.0 - DOM-Based cross-site scripting (XSS) via layout_options
- CVE-2024-65341 PoCDirectus 10.13.0 - Insecure object reference via PATH presets
- CVE-2024-65362 PoCsZephyr Project Manager < 3.3.99 - Editor+ XSS
- CVE-2024-65391 PoCheyewei SpringBootCMS Guestbook guestbook cross site scripting
- CVE-2024-65551 PoCWP Popups – WordPress Popup builder <= 2.2.0.1 - Unauthenticated Full Path Disclosure
- CVE-2024-65651 PoCAForms <= 2.2.6 - Unauthenticated Full Path Disclosure
- CVE-2024-65691 PoCCampaign Monitor for WordPress <= 2.8.15 - Unauthenticated Full Path Disclosure
- CVE-2024-65841 PoCJetpack Boost < 3.4.7 - Admin+ SSRF
- CVE-2024-65861 PoCLightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and share dashboards. A…
- CVE-2024-65871 PoCSSRF in berriai/litellm
- CVE-2024-65921 PoCWatchGuard Firebox Single Sign-On Agent Protocol Authorization Bypass
- CVE-2024-65931 PoCWatchGuard Firebox Single Sign-On Agent Management Interface Authentication Bypass
- CVE-2024-65941 PoCWatchGuard Firebox Single Sign-On Client Denial-of-Service
- CVE-2024-66021 PoCMemory corruption in NSS
- CVE-2024-66071 PoCLeaving pointerlock by pressing the escape key could be prevented
- CVE-2024-66171 PoCNinjaTeam Header Footer Custom Code <= 1.2 - Admin+ Stored XSS via CSS Styles
- CVE-2024-66244 PoCsJSON API User <= 3.9.3 - Unauthenticated Privilege Escalation
- CVE-2024-66441 PoCzmops ArgusDBM AviatorScript CalculateAlarm.java getDefaultClassLoader deserialization
- CVE-2024-66451 PoCWuKongOpenSource Wukong_nocode AviatorScript ExpressionUtil.java deserialization
- CVE-2024-66462 PoCsNetgear WN604 Web Interface downloadFile.php information disclosure
- CVE-2024-66471 PoCCroogo Setting Theme unrestricted upload
- CVE-2024-66481 PoCPath Traversal in AP Page Builder
- CVE-2024-66491 PoCSourceCodester Employee and Visitor Gate Pass Logging System Users.php save_users cross-site request forgery
- CVE-2024-66501 PoCSourceCodester Employee and Visitor Gate Pass Logging System Master.php save_designation cross site scripting
- CVE-2024-66513 PoCsWordPress File Upload < 4.24.8 - Reflected XSS
- CVE-2024-66521 PoCitsourcecode Gym Management System manage_member.php sql injection
- CVE-2024-66531 PoCcode-projects Simple Task List Login loginForm.php sql injection
- CVE-2024-66651 PoCkbucket < 4.1.6 - Admin+ Stored XSS
- CVE-2024-66671 PoCkbucket < 4.1.5 - Reflected XSS
- CVE-2024-66681 PoCprofilepro <= 1.3 - Subscriber+ Stored Cross Site Scripting
- CVE-2024-66703 PoCsKEVWhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability
- CVE-2024-66711 PoCWhatsUp Gold GetStatisticalMonitorList SQL Injection Authentication Bypass Vulnerability
- CVE-2024-66761 PoCwitmy my-springsecurity-plus user sql injection
- CVE-2024-66782 PoCsAuthentication Bypass by Spoofing in GitLab
- CVE-2024-66791 PoCwitmy my-springsecurity-plus role sql injection
- CVE-2024-66801 PoCwitmy my-springsecurity-plus build sql injection
- CVE-2024-66811 PoCwitmy my-springsecurity-plus dept sql injection
- CVE-2024-66851 PoCAuthorization Bypass Through User-Controlled Key in GitLab
- CVE-2024-66902 PoCsWP Content Copy Protection & No Right Click (premium) < 15.3 - Open Redirect
- CVE-2024-66931 PoCWP Content Copy Protection & No Right Click (premium) <= 15.0 - Admin+ Stored XSS
- CVE-2024-66951 PoCprofile-builder <= 3.11.8 - Unauthenticated Privilege Escalation
- CVE-2024-67061 PoCOpen WebUI Stored Cross-Site Scripting
- CVE-2024-67071 PoCOpen WebUI Arbitrary File Upload + Path Traversal
- CVE-2024-67081 PoCProfile Builder <= 3.12.0 - Admin+ Stored Cross Site Scripting
- CVE-2024-67101 PoCDitty < 3.1.45 - Author+ Stored XSS
- CVE-2024-67111 PoCEvent Tickets with Ticket Scanner < 2.3.8 - Admin+ Stored XSS
- CVE-2024-67121 PoCMapFig Studio <= 0.2.1 - Stored XSS via CSRF
- CVE-2024-67131 PoCPVN Auth Popup <= 1.0.0 - Admin+ Stored XSS
- CVE-2024-67151 PoCDitty 3.1.39-3.1.45 - Author+ Stored XSS
- CVE-2024-67181 PoCPVN Auth Popup <= 1.0.0 - Contributor+ XSS via Shortcode
- CVE-2024-67191 PoCOffload Videos – Bunny.net, AWS S3 <= 1.0.1 Subscriber+ CSRF
- CVE-2024-67201 PoCLight Poll <= 1.0.0 - Poll Answers Deletion via CSRF
- CVE-2024-67221 PoCChatbot Support AI <= 1.0.2 - Admin+ Stored XSS
- CVE-2024-67231 PoCAI Engine < 2.4.8 - Admin+ SQLi
- CVE-2024-67241 PoCGenerate Images – Magic Post Thumbnail < 5.2.8 - Admin+ Stored XSS
- CVE-2024-67281 PoCitsourcecode Tailoring Management System typeedit.php sql injection
- CVE-2024-67291 PoCSourceCodester Kortex Lite Advocate Office Management System add_act.php sql injection
- CVE-2024-67301 PoCNanjing Xingyuantu Technology SparkShop uploadFile unrestricted upload
- CVE-2024-67311 PoCSourceCodester Student Study Center Desk Management System Master.php sql injection
- CVE-2024-67321 PoCSourceCodester Student Study Center Desk Management System Users.php sql injection
- CVE-2024-67331 PoCitsourcecode Tailoring Management System templateedit.php sql injection
- CVE-2024-67341 PoCitsourcecode Tailoring Management System templateadd.php sql injection
- CVE-2024-67351 PoCitsourcecode Tailoring Management System setgeneral.php sql injection
- CVE-2024-67361 PoCSourceCodester Employee and Visitor Gate Pass Logging System view_employee.php sql injection
- CVE-2024-67451 PoCcode-projects Simple Ticket Booking Login adminauthenticate.php sql injection
- CVE-2024-67462 PoCsNaiboWang EasySpider HTTP GET Request server.js path traversal
- CVE-2024-67531 PoCSocial Auto Poster <= 5.3.14 - Unauthenticated Stored Cross-Site Scripting
- CVE-2024-67632 PoCsJetty URI parsing of invalid authority
- CVE-2024-67661 PoCShortcodes Ultimate Pro < 7.2.1 - Contributor+ Stored XSS
- CVE-2024-67681 PoCDenial of Service in CLFS.sys
- CVE-2024-67692 PoCsMedium to High Integrity Privilege Escalation in Microsoft Windows
- CVE-2024-67721 PoCInappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to perform out of bounds memory…
- CVE-2024-67741 PoCUse after free in Screen Capture in Google Chrome prior to 126.0.6478.182 allowed a remote attacker who convinced a user to engage in…
- CVE-2024-67751 PoCUse after free in Media Stream in Google Chrome prior to 126.0.6478.182 allowed a remote attacker who convinced a user to engage in…
- CVE-2024-67761 PoCUse after free in Audio in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2024-67771 PoCUse after free in Navigation in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious…
- CVE-2024-67782 PoCsRace in DevTools in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to…
- CVE-2024-67812 PoCsCalibre Arbitrary File Read
- CVE-2024-67827 PoCsCalibre Remote Code Execution
- CVE-2024-67831 PoCVue client-side XSS via prototype pollution
- CVE-2024-67921 PoCWP ULike < 4.7.2.1 - Subscriber+ Stored-XSS
- CVE-2024-67971 PoCDL Robots.txt <= 1.2 - Admin+ Stored XSS
- CVE-2024-67981 PoCDL Verification <= 1.2 - Admin+ Stored XSS
- CVE-2024-68011 PoCSourceCodester Online Student Management System add-students.php unrestricted upload
- CVE-2024-68021 PoCSourceCodester Computer Laboratory Management System Master.php sql injection
- CVE-2024-68031 PoCitsourcecode Document Management System insert.php sql injection
- CVE-2024-68071 PoCSourceCodester Student Study Center Desk Management System HTTP POST Request Users.php cross site scripting
- CVE-2024-68081 PoCitsourcecode Simple Task List signUp.php insertUserRecord sql injection
- CVE-2024-68091 PoCSimple Video Directory < 1.4.3 - Unauthenticated SQLi
- CVE-2024-68261 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2024-68301 PoCSourceCodester Simple Inventory Management System Order action.php sql injection
- CVE-2024-68421 PoCExposure of Sensitive Information in mintplex-labs/anything-llm
- CVE-2024-68431 PoCSmartSearch WP <= 2.4.4 - Unauthenticated Stored XSS
- CVE-2024-68452 PoCsSmartSearchWP < 2.4.6 - Unauthenticated OpenAI Key Disclosure
- CVE-2024-68462 PoCsSmartSearchWP <= 2.4.4 - Unauthenticated Log Purge
- CVE-2024-68471 PoCSmartSearch WP <= 2.4.4 - Unauthenticated SQLi
- CVE-2024-68481 PoCPost and Page Builder by BoldGrid – Visual Drag and Drop Editor <= 1.26.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via…
- CVE-2024-68501 PoCCarousel Slider < 2.2.14 - Editor+ Stored XSS
- CVE-2024-68521 PoCWP MultiTasking <= 0.1.12 - Settings Update via CSRF
- CVE-2024-68531 PoCWP MultiTasking <= 0.1.12 - Welcome Popup Update via CSRF
- CVE-2024-68551 PoCWP MultiTasking <= 0.1.12 - Exit Popup Update via CSRF
- CVE-2024-68561 PoCWP MultiTasking <= 0.1.12 - SMTP Settings Update via CSRF
- CVE-2024-68571 PoCWP MultiTasking <= 0.1.12 - Header/Footer/Body Script Update via CSRF
- CVE-2024-68591 PoCWP MultiTasking <= 0.1.12 - Reflected XSS via Shortcode
- CVE-2024-68601 PoCWP MultiTasking <= 0.1.12 - Permalink Suffix Update via CSRF
- CVE-2024-68791 PoCQuiz and Survey Master (QSM) < 9.1.1 - Contributor+ Stored XSS
- CVE-2024-68841 PoCGutenberg Blocks with AI by Kadence WP < 3.2.39 - Contributor+ Stored XSS
- CVE-2024-68861 PoCInproper Sanitation of field leading to stored XSS
- CVE-2024-68871 PoCGiveaways and Contests by RafflePress < 1.12.16 - Editor+ Stored XSS
- CVE-2024-68881 PoCSecure Copy Content Protection and Content Locking < 4.1.7 - Admin+ Stored XSS
- CVE-2024-68891 PoCSecure Copy Content Protection and Content Locking < 4.1.7 - Admin+ Stored XSS
- CVE-2024-68901 PoCJournyx Unauthenticated Password Reset Bruteforce
- CVE-2024-68911 PoCJournyx Authenticated Remote Code Execution
- CVE-2024-68921 PoCJournyx Reflected Cross Site Scripting
- CVE-2024-68932 PoCsJournyx Unauthenticated XML External Entities Injection
- CVE-2024-68981 PoCSourceCodester Record Management System index.php sql injection
- CVE-2024-68991 PoCSourceCodester Record Management System view_info.php sql injection
- CVE-2024-69001 PoCSourceCodester Record Management System edit_emp.php sql injection
- CVE-2024-69011 PoCSourceCodester Record Management System entry.php sql injection
- CVE-2024-69021 PoCSourceCodester Record Management System sort_user.php sql injection
- CVE-2024-69031 PoCSourceCodester Record Management System sort1_user.php sql injection
- CVE-2024-69041 PoCSourceCodester Record Management System sort2_user.php sql injection
- CVE-2024-69051 PoCSourceCodester Record Management System view_info_user.php sql injection
- CVE-2024-69061 PoCSourceCodester Record Management System add_leave_non_user.php sql injection
- CVE-2024-69071 PoCSourceCodester Record Management System sort.php cross site scripting
- CVE-2024-69101 PoCEventON < 2.2.17 - Admin+ Stored XSS
- CVE-2024-69113 PoCsUnauthenticated Local File Inclusion
- CVE-2024-69122 PoCsHardcoded MSSQL Credentials
- CVE-2024-69132 PoCsExecution with Unnecessary Privileges
- CVE-2024-69221 PoCServer-Side Request Forgery in Automation 360
- CVE-2024-69242 PoCsTrueBooker < 1.0.3 - Multiple Unauthenticated SQLi
- CVE-2024-69251 PoCTrueBooker < 1.0.3 - Settings Update via CSRF
- CVE-2024-69262 PoCsViral Signup <= 2.1 - Unauthenticated SQLi
- CVE-2024-69271 PoCViral Signup <= 2.1 - Admin+ Stored XSS
- CVE-2024-69282 PoCsOpti Marketing <= 2.0.9 - Unauthenticated SQLi
- CVE-2024-69321 PoCClassCMS cross site scripting
- CVE-2024-69331 PoCLimeSurvey Survey General Settings updatesurveylocalesettings_generalsettings actionUpdateSurveyLocaleSettingsGeneralSettings sql injection
- CVE-2024-69341 PoCformtools.org Form Tools cross site scripting
- CVE-2024-69351 PoCformtools.org Form Tools User Settings Page cross site scripting
- CVE-2024-69361 PoCformtools.org Form Tools Setting code injection
- CVE-2024-69371 PoCformtools.org Form Tools Import Option List edit.php curl_exec file inclusion
- CVE-2024-69381 PoCSiYuan PDF PDF.js cross site scripting
- CVE-2024-69391 PoCXinhu RockOA tpl_upload.html okla cross site scripting
- CVE-2024-69401 PoCDedeCMS article_template_rand.php code injection
- CVE-2024-69411 PoCThinkSAAS do.php cross site scripting
- CVE-2024-69421 PoCThinkSAAS Admin Panel Security Center anti.php cross site scripting
- CVE-2024-69431 PoCZhongBangKeJi CRMEB CopyTaobaoServices.php downloadImage deserialization
- CVE-2024-69441 PoCZhongBangKeJi CRMEB PublicController.php get_image_base64 deserialization
- CVE-2024-69451 PoCFlute CMS Avatar Upload Page ImagesController.php unrestricted upload
- CVE-2024-69461 PoCFlute CMS list code injection
- CVE-2024-69471 PoCFlute CMS Notification ContentParser.php replaceContent code injection
- CVE-2024-69481 PoCGargaj wuhu Slide Editor slideeditor.php unrestricted upload
- CVE-2024-69491 PoCGargaj wuhu path traversal
- CVE-2024-69501 PoCPrain HTTP POST Request ?import code injection
- CVE-2024-69511 PoCSourceCodester Simple Online Book Store System admin_delete.php sql injection
- CVE-2024-69521 PoCitsourcecode University Management System sql injection
- CVE-2024-69531 PoCitsourcecode Tailoring Management System sms.php sql injection
- CVE-2024-69541 PoCSourceCodester Record Management System sort1.php cross site scripting
- CVE-2024-69551 PoCSourceCodester Record Management System sort2.php cross site scripting
- CVE-2024-69561 PoCitsourcecode University Management System view_cgpa.php sql injection
- CVE-2024-69571 PoCitsourcecode University Management System Login functions.php sql injection
- CVE-2024-69581 PoCitsourcecode University Management System Avatar File st_update.php unrestricted upload
- CVE-2024-69621 PoCTenda O3 formQosSet stack-based overflow
- CVE-2024-69631 PoCTenda O3 formexeCommand stack-based overflow
- CVE-2024-69641 PoCTenda O3 fromDhcpSetSer stack-based overflow
- CVE-2024-69651 PoCTenda O3 fromVirtualSet stack-based overflow
- CVE-2024-69661 PoCitsourcecode Online Blood Bank Management System Login login.php sql injection
- CVE-2024-69671 PoCSourceCodester Employee and Visitor Gate Pass Logging System sql injection
- CVE-2024-69681 PoCSourceCodester Clinics Patient Management System print_patients_visits.php sql injection
- CVE-2024-69691 PoCSourceCodester Clinics Patient Management System get_patient_history.php sql injection
- CVE-2024-69701 PoCitsourcecode Tailoring Management System staffcatadd.php sql injection
- CVE-2024-69831 PoCRemote Code Execution in mudler/localai
- CVE-2024-69841 PoCAn issue was discovered in Juju that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to…