CVE-2024-7000 to CVE-2024-7999
419 CVEs with public proof-of-concept exploits.
- CVE-2024-70082 PoCsCalibre Reflected Cross-Site Scripting (XSS)
- CVE-2024-70142 PoCsImproper multimedia file attachment validation in Telegram for Android app
- CVE-2024-70181 PoCHeap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2024-70191 PoCInappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in…
- CVE-2024-70201 PoCInappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a…
- CVE-2024-70221 PoCUninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a…
- CVE-2024-70231 PoCInsufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform privilege escalation…
- CVE-2024-70241 PoCInappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform a sandbox…
- CVE-2024-70295 PoCsCommand Injection in AVTech AVM1203 (IP Camera)
- CVE-2024-70521 PoCForminator < 1.38.3 - Admin+ Stored XSS
- CVE-2024-70551 PoCFFmpeg pnmdec.c pnm_decode_frame heap-based overflow
- CVE-2024-70561 PoCWPForms < 1.9.1.6 - Admin+ Stored XSS
- CVE-2024-70571 PoCImproper Access Control in GitLab
- CVE-2024-70651 PoCSpina CMS cross-site request forgery
- CVE-2024-70661 PoCF-logic DataCube3 HTTP POST Request config_time_sync.php os command injection
- CVE-2024-70671 PoCkirilkirkov Ecommerce-Laravel-Bootstrap Cart.php getCartProductsIds deserialization
- CVE-2024-70681 PoCSourceCodester Insurance Management System update_sub_category cross site scripting
- CVE-2024-70691 PoCSourceCodester Employee and Visitor Gate Pass Logging System sql injection
- CVE-2024-70801 PoCSourceCodester Insurance Management System direct request
- CVE-2024-70811 PoCitsourcecode Tailoring Management System expcatadd.php sql injection
- CVE-2024-70821 PoCeasy-table-of-contents < 2.0.68 - Editor+ Stored XSS
- CVE-2024-70831 PoCEmail Encoder < 2.3.4 - Admin+ Stored XSS
- CVE-2024-70841 PoCAjax Search Lite < 4.12.1 - Admin+ Stored XSS
- CVE-2024-70941 PoCJS Help Desk – The Ultimate Help Desk & Support Plugin <= 2.8.6 - Unauthenticated PHP Code Injection to Remote Code Execution
- CVE-2024-70971 PoCIncorrect Authorization in Multiple WSO2 Products via SOAP Admin Service Allowing Unauthorized User Signup
- CVE-2024-71021 PoCExecution with Unnecessary Privileges in GitLab
- CVE-2024-71051 PoCForIP Tecnologia Administração PABX Lista Ura Page detalheIdUra sql injection
- CVE-2024-71061 PoCSpina CMS media_folders cross-site request forgery
- CVE-2024-71141 PoCTianchoy Blog so.php sql injection
- CVE-2024-71151 PoCMD-MAFUJUL-HASAN Online-Payroll-Management-System designation_viewmore.php sql injection
- CVE-2024-71161 PoCMD-MAFUJUL-HASAN Online-Payroll-Management-System branch_viewmore.php sql injection
- CVE-2024-71171 PoCMD-MAFUJUL-HASAN Online-Payroll-Management-System shift_viewmore.php sql injection
- CVE-2024-71181 PoCMD-MAFUJUL-HASAN Online-Payroll-Management-System department_viewmore.php sql injection
- CVE-2024-71191 PoCMD-MAFUJUL-HASAN Online-Payroll-Management-System employee_viewmore.php sql injection
- CVE-2024-71205 PoCsRaisecom MSG1200/MSG2100E/MSG2200/MSG2300 Web Interface list_base_config.php os command injection
- CVE-2024-71241 PoCReflected XSS in DInGO dLibra
- CVE-2024-71291 PoCAppointment Booking Calendar < 1.6.7.43 - Admin+ Template Injection to RCE
- CVE-2024-71321 PoCCoBlocks < 3.1.13 - Editor+ Stored XSS
- CVE-2024-71331 PoCMy Sticky Bar < 2.7.3 - Admin+ Stored XSS
- CVE-2024-71352 PoCsTainacan <= 0.21.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read
- CVE-2024-71511 PoCTenda O3 setMacFilter fromMacFilterSet stack-based overflow
- CVE-2024-71521 PoCTenda O3 setMacFilterList fromSafeSetMacFilter stack-based overflow
- CVE-2024-71531 PoCNetgear WN604 siteSurvey.php direct request
- CVE-2024-71541 PoCTOTOLINK A3700R Password Reset wizard.html access control
- CVE-2024-71551 PoCTOTOLINK A3300R shadow.sample hard-coded password
- CVE-2024-71561 PoCTOTOLINK A3700R apmib Configuration ExportSettings.sh information disclosure
- CVE-2024-71571 PoCTOTOLINK A3100R getSaveConfig buffer overflow
- CVE-2024-71581 PoCTOTOLINK A3100R HTTP POST Request cstecgi.cgi setTelnetCfg command injection
- CVE-2024-71591 PoCTOTOLINK A3600R Telnet Service product.ini hard-coded password
- CVE-2024-71601 PoCTOTOLINK A3700R cstecgi.cgi setWanCfg command injection
- CVE-2024-71611 PoCSeaCMS Password Change cross-site request forgery
- CVE-2024-71621 PoCSeaCMS cross site scripting
- CVE-2024-71631 PoCSeaCMS index.php cross site scripting
- CVE-2024-71641 PoCSourceCodester School Fees Payment System sql injection
- CVE-2024-71651 PoCSourceCodester School Fees Payment System view_payment.php sql injection
- CVE-2024-71661 PoCSourceCodester School Fees Payment System receipt.php sql injection
- CVE-2024-71671 PoCSourceCodester School Fees Payment System manage_course.php sql injection
- CVE-2024-71681 PoCSourceCodester School Fees Payment System manage_user.php sql injection
- CVE-2024-71691 PoCSourceCodester School Fees Payment System ajax.php cross-site request forgery
- CVE-2024-71701 PoCTOTOLINK A3000RU product.ini hard-coded password
- CVE-2024-71711 PoCTOTOLINK A3600R cstecgi.cgi NTPSyncWithHost os command injection
- CVE-2024-71721 PoCTOTOLINK A3600R getSaveConfig buffer overflow
- CVE-2024-71731 PoCTOTOLINK A3600R cstecgi.cgi loginauth buffer overflow
- CVE-2024-71741 PoCTOTOLINK A3600R cstecgi.cgi setdeviceName buffer overflow
- CVE-2024-71751 PoCTOTOLINK A3600R cstecgi.cgi setDiagnosisCfg os command injection
- CVE-2024-71761 PoCTOTOLINK A3600R cstecgi.cgi setIpQosRules buffer overflow
- CVE-2024-71771 PoCTOTOLINK A3600R cstecgi.cgi setLanguageCfg buffer overflow
- CVE-2024-71781 PoCTOTOLINK A3600R cstecgi.cgi setMacQos buffer overflow
- CVE-2024-71791 PoCTOTOLINK A3600R cstecgi.cgi setParentalRules buffer overflow
- CVE-2024-71801 PoCTOTOLINK A3600R cstecgi.cgi setPortForwardRules buffer overflow
- CVE-2024-71811 PoCTOTOLINK A3600R cstecgi.cgi setTelnetCfg command injection
- CVE-2024-71821 PoCTOTOLINK A3600R cstecgi.cgi setUpgradeFW buffer overflow
- CVE-2024-71831 PoCTOTOLINK A3600R cstecgi.cgi setUploadSetting buffer overflow
- CVE-2024-71841 PoCTOTOLINK A3600R cstecgi.cgi setUrlFilterRules buffer overflow
- CVE-2024-71851 PoCTOTOLINK A3600R cstecgi.cgi setWebWlanIdx buffer overflow
- CVE-2024-71861 PoCTOTOLINK A3600R cstecgi.cgi setWiFiAclAddConfig buffer overflow
- CVE-2024-71871 PoCTOTOLINK A3600R cstecgi.cgi UploadCustomModule buffer overflow
- CVE-2024-71882 PoCsBylancer Quicklancer GET Parameter listing sql injection
- CVE-2024-71891 PoCitsourcecode Online Food Ordering System editproduct.php unrestricted upload
- CVE-2024-71901 PoCitsourcecode Society Management System get_price.php sql injection
- CVE-2024-71911 PoCitsourcecode Society Management System get_balance.php sql injection
- CVE-2024-71921 PoCitsourcecode Society Management System student.php unrestricted upload
- CVE-2024-71931 PoCMp3tag DLL tak_deco_lib.dll uncontrolled search path
- CVE-2024-71941 PoCitsourcecode Society Management System check_student.php sql injection
- CVE-2024-71951 PoCitsourcecode Society Management System check_admin.php sql injection
- CVE-2024-71961 PoCSourceCodester Complaints Report Management System sql injection
- CVE-2024-71971 PoCSourceCodester Complaints Report Management System manage_complaint.php sql injection
- CVE-2024-71981 PoCSourceCodester Complaints Report Management System manage_station.php sql injection
- CVE-2024-71991 PoCSourceCodester Complaints Report Management System manage_user.php sql injection
- CVE-2024-72001 PoCSourceCodester Complaints Report Management System cross site scripting
- CVE-2024-72121 PoCTOTOLINK A7000R cstecgi.cgi loginauth buffer overflow
- CVE-2024-72131 PoCTOTOLINK A7000R cstecgi.cgi setWizardCfg buffer overflow
- CVE-2024-72141 PoCTOTOLINK LR350 cstecgi.cgi setWanCfg command injection
- CVE-2024-72151 PoCTOTOLINK LR1200 cstecgi.cgi NTPSyncWithHost command injection
- CVE-2024-72161 PoCTOTOLINK LR1200 shadow.sample hard-coded password
- CVE-2024-72171 PoCTOTOLINK CA300-PoE cstecgi.cgi loginauth buffer overflow
- CVE-2024-72181 PoCSourceCodester/Campcodes School Log Management System ajax.php cross site scripting
- CVE-2024-72191 PoCSourceCodester/Campcodes School Log Management System ajax.php sql injection
- CVE-2024-72201 PoCSourceCodester/Campcodes School Log Management System print_barcode.php sql injection
- CVE-2024-72211 PoCSourceCodester/Campcodes School Log Management System manage_user.php sql injection
- CVE-2024-72221 PoCSourceCodester Lot Reservation Management System home.php sql injection
- CVE-2024-72231 PoCSourceCodester Lot Reservation Management System view_model.php sql injection
- CVE-2024-72241 PoCSourceCodester Lot Reservation Management System lot_details.php sql injection
- CVE-2024-72251 PoCSourceCodester Insurance Management System Edit Insurance Policy Page update_policy cross site scripting
- CVE-2024-72261 PoCSourceCodester Medicine Tracker System Password Change cross-site request forgery
- CVE-2024-72561 PoCInsufficient data validation in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to execute arbitrary…
- CVE-2024-72721 PoCFFmpeg swresample.c fill_audiodata heap-based overflow
- CVE-2024-72731 PoCitsourcecode Alton Management System search.php sql injection
- CVE-2024-72741 PoCitsourcecode Alton Management System reservation_status.php sql injection
- CVE-2024-72751 PoCitsourcecode Alton Management System category_save.php sql injection
- CVE-2024-72761 PoCitsourcecode Alton Management System member_save.php sql injection
- CVE-2024-72771 PoCitsourcecode Alton Management System Add a Menu menu.php unrestricted upload
- CVE-2024-72781 PoCitsourcecode Alton Management System team_save.php sql injection
- CVE-2024-72791 PoCSourceCodester Lot Reservation Management System sql injection
- CVE-2024-72801 PoCSourceCodester Lot Reservation Management System view_reserved.php sql injection
- CVE-2024-72811 PoCSourceCodester Lot Reservation Management System sql injection
- CVE-2024-72821 PoCSourceCodester Lot Reservation Management System manage_model.php sql injection
- CVE-2024-72831 PoCSourceCodester Lot Reservation Management System manage_user.php sql injection
- CVE-2024-72841 PoCSourceCodester Lot Reservation Management System cross site scripting
- CVE-2024-72851 PoCSourceCodester Establishment Billing Management System cross site scripting
- CVE-2024-72861 PoCSourceCodester Establishment Billing Management System Login sql injection
- CVE-2024-72871 PoCSourceCodester Establishment Billing Management System manage_user.php sql injection
- CVE-2024-72881 PoCSourceCodester Establishment Billing Management System sql injection
- CVE-2024-72891 PoCSourceCodester Establishment Billing Management System manage_payment.php sql injection
- CVE-2024-72901 PoCSourceCodester Establishment Billing Management System manage_tenant.php sql injection
- CVE-2024-72961 PoCIncorrect Authorization in GitLab
- CVE-2024-72971 PoCLangflow Privilege Escalation
- CVE-2024-73031 PoCitsourcecode Online Blood Bank Management System Send Blood Request Page request.php cross site scripting
- CVE-2024-73061 PoCSourceCodester Establishment Billing Management System manage_block.php sql injection
- CVE-2024-73071 PoCSourceCodester Establishment Billing Management System manage_billing.php sql injection
- CVE-2024-73081 PoCSourceCodester Establishment Billing Management System view_bill.php sql injection
- CVE-2024-73091 PoCSourceCodester Record Management System entry.php cross site scripting
- CVE-2024-73101 PoCSourceCodester Record Management System sort_user.php cross site scripting
- CVE-2024-73111 PoCcode-projects Online Bus Reservation Site register.php sql injection
- CVE-2024-73133 PoCsShield Security < 20.0.6 - Reflected XSS
- CVE-2024-73144 PoCsanji-plus AJ-Report Authentication Bypass
- CVE-2024-73151 PoCMigration, Backup, Staging – WPvivid < 0.9.106 - Unauthenticated Sensitive Data Exposure
- CVE-2024-73201 PoCitsourcecode Online Blood Bank Management System Admin Login index.php sql injection
- CVE-2024-73211 PoCitsourcecode Online Blood Bank Management System User Registration signup.php cross site scripting
- CVE-2024-73271 PoCXinhu RockOA openmodhetongAction.php dataAction sql injection
- CVE-2024-73281 PoCYouDianCMS information disclosure
- CVE-2024-73291 PoCYouDianCMS image_upload.php unrestricted upload
- CVE-2024-73301 PoCYouDianCMS ydLib.php curl_exec server-side request forgery
- CVE-2024-73311 PoCTOTOLINK A3300R cstecgi.cgi UploadCustomModule buffer overflow
- CVE-2024-73322 PoCsTOTOLINK CP450 Telnet Service product.ini hard-coded password
- CVE-2024-73331 PoCTOTOLINK N350RT cstecgi.cgi setParentalRules buffer overflow
- CVE-2024-73341 PoCTOTOLINK EX1200L cstecgi.cgi UploadCustomModule buffer overflow
- CVE-2024-73351 PoCTOTOLINK EX200 getSaveConfig buffer overflow
- CVE-2024-73361 PoCTOTOLINK EX200 cstecgi.cgi loginauth buffer overflow
- CVE-2024-73371 PoCTOTOLINK EX1200L cstecgi.cgi loginauth buffer overflow
- CVE-2024-73381 PoCTOTOLINK EX1200L cstecgi.cgi setParentalRules buffer overflow
- CVE-2024-73393 PoCsTVT DVR TD-2104TS-CL queryDevInfo information disclosure
- CVE-2024-73401 PoCW&B Weave server remote arbitrary file leak and privilege escalation
- CVE-2024-73421 PoCBaidu UEditor unrestricted upload
- CVE-2024-73431 PoCBaidu UEditor cross site scripting
- CVE-2024-73442 PoCsHowyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.
- CVE-2024-73542 PoCsNinja Forms 3.8.6-3.8.10 - Reflected XSS
- CVE-2024-73571 PoCD-Link DIR-600 soap.cgi soapcgi_main os command injection
- CVE-2024-73581 PoCPoint B Ltd Getscreen Agent Installation getscreen.msi temp file
- CVE-2024-73591 PoCSourceCodester Tracking Monitoring Management System ajax.php cross site scripting
- CVE-2024-73601 PoCSourceCodester Tracking Monitoring Management System ajax.php cross-site request forgery
- CVE-2024-73611 PoCSourceCodester Tracking Monitoring Management System ajax.php sql injection
- CVE-2024-73621 PoCSourceCodester Tracking Monitoring Management System manage_user.php sql injection
- CVE-2024-73631 PoCSourceCodester Tracking Monitoring Management System manage_person.php sql injection
- CVE-2024-73641 PoCSourceCodester Tracking Monitoring Management System manage_records.php sql injection
- CVE-2024-73651 PoCSourceCodester Tracking Monitoring Management System manage_establishment.php sql injection
- CVE-2024-73661 PoCSourceCodester Tracking Monitoring Management System Login ajax.php sql injection
- CVE-2024-73671 PoCSourceCodester Simple Realtime Quiz System ajax.php cross-site request forgery
- CVE-2024-73681 PoCSourceCodester Simple Realtime Quiz System ajax.php cross site scripting
- CVE-2024-73691 PoCSourceCodester Simple Realtime Quiz System Login ajax.php sql injection
- CVE-2024-73701 PoCSourceCodester Simple Realtime Quiz System manage_quiz.php sql injection
- CVE-2024-73711 PoCSourceCodester Simple Realtime Quiz System quiz_view.php sql injection
- CVE-2024-73721 PoCSourceCodester Simple Realtime Quiz System quiz_board.php sql injection
- CVE-2024-73731 PoCSourceCodester Simple Realtime Quiz System ajax.php sql injection
- CVE-2024-73741 PoCSourceCodester Simple Realtime Quiz System manage_user.php sql injection
- CVE-2024-73751 PoCSourceCodester Simple Realtime Quiz System my_quiz_result.php sql injection
- CVE-2024-73761 PoCSourceCodester Simple Realtime Quiz System print_quiz_records.php sql injection
- CVE-2024-73771 PoCSourceCodester Simple Realtime Quiz System view_result.php sql injection
- CVE-2024-73781 PoCSourceCodester Simple Realtime Quiz System manage_question.php sql injection
- CVE-2024-73891 PoCForminator <= 1.29.1 - HubSpot Developer API Key Sensitive Information Exposure
- CVE-2024-73994 PoCsKEVImproper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows…
- CVE-2024-74012 PoCsClient Enrollment Process Bypass
- CVE-2024-74041 PoCImproper Restriction of Rendered UI Layers or Frames in GitLab
- CVE-2024-74361 PoCD-Link DI-8100 msp_info.htm msp_info_htm command injection
- CVE-2024-74371 PoCSimpleMachines SMF Delete User index.php resource injection
- CVE-2024-74381 PoCSimpleMachines SMF User Alert Read Status index.php resource injection
- CVE-2024-74391 PoCVivotek CC8160 httpd read stack-based overflow
- CVE-2024-74411 PoCVivotek SD9364 httpd read stack-based overflow
- CVE-2024-74441 PoCitsourcecode Ticket Reservation System Login Page login.php sql injection
- CVE-2024-74451 PoCitsourcecode Ticket Reservation System checkout_ticket_save.php sql injection
- CVE-2024-74461 PoCitsourcecode Ticket Reservation System list_tickets.php sql injection
- CVE-2024-74491 PoCitsourcecode Placement Management System login.php sql injection
- CVE-2024-74501 PoCitsourcecode Placement Management System Image resume_upload.php unrestricted upload
- CVE-2024-74511 PoCitsourcecode Placement Management System apply_now.php sql injection
- CVE-2024-74521 PoCitsourcecode Placement Management System view_company.php sql injection
- CVE-2024-74531 PoCFastAdmin Attachment Management Section 4 cross site scripting
- CVE-2024-74541 PoCSourceCodester Clinics Patient Management System patients.php patient_name sql injection
- CVE-2024-74551 PoCitsourcecode Tailoring Management System partedit.php sql injection
- CVE-2024-74561 PoCSQL Injection in lunary-ai/lunary
- CVE-2024-74581 PoCelunez eladmin Database Management/Deployment Management upload path traversal
- CVE-2024-74591 PoCOSWAPP Warehouse Inventory System edit_account.php cross-site request forgery
- CVE-2024-74601 PoCOSWAPP Warehouse Inventory System change_password.php cross-site request forgery
- CVE-2024-74611 PoCForIP Tecnologia Administração PABX monitcallcenter authMonitCallcenter sql injection
- CVE-2024-74621 PoCTOTOLINK N350RT cstecgi.cgi setWizardCfg buffer overflow
- CVE-2024-74631 PoCTOTOLINK CP900 cstecgi.cgi UploadCustomModule buffer overflow
- CVE-2024-74641 PoCTOTOLINK CP900 Telnet Service setTelnetCfg command injection
- CVE-2024-74652 PoCsTOTOLINK CP450 cstecgi.cgi loginauth buffer overflow
- CVE-2024-74661 PoCPMWeb Web Application Firewall cross site scripting
- CVE-2024-74671 PoCRaisecom MSG1200/MSG2100E/MSG2200/MSG2300 Web Interface list_ip_network.php sslvpn_config_mod os command injection
- CVE-2024-74681 PoCRaisecom MSG1200/MSG2100E/MSG2200/MSG2300 Web Interface list_service_manage.php sslvpn_config_mod os command injection
- CVE-2024-74691 PoCRaisecom MSG1200/MSG2100E/MSG2200/MSG2300 Web Interface list_vpn_web_custom.php sslvpn_config_mod os command injection
- CVE-2024-74701 PoCRaisecom MSG1200/MSG2100E/MSG2200/MSG2300 Web Interface vpn_template_style.php sslvpn_config_mod os command injection
- CVE-2024-74792 PoCsImproper signature verification of VPN driver installation in TeamViewer Remote Clients
- CVE-2024-74811 PoCImproper signature verification of Printer driver installation in TeamViewer Remote Clients
- CVE-2024-74941 PoCSourceCodester Clinics Patient Management System new_prescription.php sql injection
- CVE-2024-74951 PoCitsourcecode Laravel Accounting System HomeController.php unrestricted upload
- CVE-2024-74961 PoCitsourcecode Airline Reservation System index.php file inclusion
- CVE-2024-74971 PoCitsourcecode Airline Reservation System index.php file inclusion
- CVE-2024-74981 PoCitsourcecode Airline Reservation System Admin Login Page login.php login2 sql injection
- CVE-2024-74991 PoCitsourcecode Airline Reservation System flights.php sql injection
- CVE-2024-75001 PoCitsourcecode Airline Reservation System admin_class.php save_settings unrestricted upload
- CVE-2024-75051 PoCitsourcecode Bike Delivery System contact_us_action.php sql injection
- CVE-2024-75061 PoCitsourcecode Tailoring Management System setlogo.php unrestricted upload
- CVE-2024-75141 PoCWordPress Comments Import & Export <= 2.3.7 - Authenticated (Author+) Arbitrary File Read via Directory Traversal
- CVE-2024-75511 PoCjuzaweb CMS Theme Editor default path traversal
- CVE-2024-75521 PoCDataGear Data Schema Page ConversionSqlParamValueMapper.java evaluateVariableExpression expression language injection
- CVE-2024-75561 PoCWordpress Simple Share Plugin <=0.5.3 - Admin+ XSS
- CVE-2024-75582 PoCsJUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an…
- CVE-2024-75781 PoCAlien Technology ALR-F800 cmd.php improper authorization
- CVE-2024-75791 PoCAlien Technology ALR-F800 File Name upgrade.cgi popen os command injection
- CVE-2024-75801 PoCAlien Technology ALR-F800 system.html os command injection
- CVE-2024-75811 PoCTenda A301 WifiBasicSet formWifiBasicSet stack-based overflow
- CVE-2024-75821 PoCTenda i22 apPortalAccessCodeAuth formApPortalAccessCodeAuth buffer overflow
- CVE-2024-75831 PoCTenda i22 apPortalOneKeyAuth formApPortalOneKeyAuth buffer overflow
- CVE-2024-75841 PoCTenda i22 apPortalPhoneAuth formApPortalPhoneAuth buffer overflow
- CVE-2024-75851 PoCTenda i22 apPortalAuth formApPortalWebAuth buffer overflow
- CVE-2024-75912 PoCsImproper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection
- CVE-2024-75938 PoCsKEVIncorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated…
- CVE-2024-76131 PoCTenda FH1206 GstDhcpSetSer fromGstDhcpSetSer buffer overflow
- CVE-2024-76141 PoCTenda FH1206 qossetting fromqossetting stack-based overflow
- CVE-2024-76151 PoCTenda FH1206 fromSafeUrlFilter stack-based overflow
- CVE-2024-76272 PoCsBit File Manager 6.0 - 6.5.5 - Unauthenticated Remote Code Execution via Race Condition
- CVE-2024-76351 PoCcode-projects Simple Ticket Booking Registration register_insert.php sql injection
- CVE-2024-76361 PoCcode-projects Simple Ticket Booking Login authenticate.php sql injection
- CVE-2024-76371 PoCcode-projects Online Polling Registration registeracc.php sql injection
- CVE-2024-76381 PoCSourceCodester Kortex Lite Advocate Office Management System delete_client.php sql injection
- CVE-2024-76391 PoCSourceCodester Kortex Lite Advocate Office Management System delete_act.php sql injection
- CVE-2024-76401 PoCSourceCodester Kortex Lite Advocate Office Management System delete_register.php sql injection
- CVE-2024-76411 PoCSourceCodester Kortex Lite Advocate Office Management System deactivate_act.php sql injection
- CVE-2024-76421 PoCSourceCodester Kortex Lite Advocate Office Management System activate_act.php sql injection
- CVE-2024-76431 PoCSourceCodester Leads Manager Tool Delete Leads delete-leads.php sql injection
- CVE-2024-76441 PoCSourceCodester Leads Manager Tool Add Leads add-leads.php cross site scripting
- CVE-2024-76451 PoCSourceCodester Clinics Patient Management System User Page users.php cross-site request forgery
- CVE-2024-76462 PoCsA security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or…
- CVE-2024-76601 PoCSourceCodester File Manager App Add File cross site scripting
- CVE-2024-76611 PoCSourceCodester Car Driving School Management System index.php save_users cross-site request forgery
- CVE-2024-76621 PoCSourceCodester Car Driving School Management System manag_package.php save_package cross-site request forgery
- CVE-2024-76631 PoCSourceCodester Car Driving School Management System manage_user.php sql injection
- CVE-2024-76641 PoCSourceCodester Car Driving School Management System view_details.php sql injection
- CVE-2024-76651 PoCSourceCodester Car Driving School Management System manage_package.php sql injection
- CVE-2024-76661 PoCSourceCodester Car Driving School Management System view_package.php sql injection
- CVE-2024-76671 PoCSourceCodester Car Driving School Management System User.php delete_users sql injection
- CVE-2024-76681 PoCSourceCodester Car Driving School Management System Master.php delete_package sql injection
- CVE-2024-76691 PoCSourceCodester Car Driving School Management System Master.php delete_enrollment sql injection
- CVE-2024-76761 PoCSourcecodester Car Driving School Management System Master.php save_package sql injection
- CVE-2024-76771 PoCSourceCodester Car Driving School Management System SystemSettings.php update_settings_info cross site scripting
- CVE-2024-76781 PoCSourceCodester Car Driving School Management System Master.php cross site scripting
- CVE-2024-76801 PoCitsourcecode Tailoring Management System incedit.php sql injection
- CVE-2024-76811 PoCcode-projects College Management System Login Page login.php sql injection
- CVE-2024-76821 PoCcode-projects Job Portal rw_i_nat.php sql injection
- CVE-2024-76831 PoCSourceCodester Kortex Lite Advocate Office Management System addcase_stage.php cross site scripting
- CVE-2024-76841 PoCSourceCodester Kortex Lite Advocate Office Management System add_act.php cross site scripting
- CVE-2024-76851 PoCSourceCodester Kortex Lite Advocate Office Management System adds.php cross site scripting
- CVE-2024-76861 PoCSourceCodester Kortex Lite Advocate Office Management System register_case.php cross site scripting
- CVE-2024-76871 PoCAZIndex <= 0.8.1 - Stored XSS via CSRF
- CVE-2024-76881 PoCAZIndex <= 0.8.1 - Index Deletion via CSRF
- CVE-2024-76891 PoCSnapshot Backup <= 2.1.1 - Stored XSS via CSRF
- CVE-2024-76901 PoCDN Popup <= 1.2.2 - Settings Update via CSRF
- CVE-2024-76911 PoCFlaming Forms <= 1.0.1 - Unauthenticated Stored XSS
- CVE-2024-76921 PoCFlaming Forms <= 1.0.1 - Reflected XSS
- CVE-2024-77031 PoCARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup <= 4.0.37 - Authenticated (Subscriber+)…
- CVE-2024-77041 PoCWeaver e-cology Source Code ecology_dev.zip information disclosure
- CVE-2024-77051 PoCFujian mwcms Image Upload uploadeditor.html uploadeditor unrestricted upload
- CVE-2024-77061 PoCFujian mwcms uploadfile.html uploadimage unrestricted upload
- CVE-2024-77071 PoCTenda FH1206 HTTP POST Request SafeEmailFilter formSafeEmailFilter stack-based overflow
- CVE-2024-77131 PoCAI Chatbot with ChatGPT by AYS <= 2.0.9 - Unauthenticated OpenAI Key Disclosure
- CVE-2024-77142 PoCsAI Assistant with ChatGPT by AYS <= 2.0.9 - Unauthenticated AJAX Calls
- CVE-2024-77151 PoCD-Link DNS-1550-04 photocenter_mgr.cgi sprintf command injection
- CVE-2024-77161 PoCGS Logo Slider Lite < 3.6.9 - Admin+ Stored XSS
- CVE-2024-77261 PoCArbitrary Code execution via exposed JTAG port in Kioxia CM6, PM6, PM7
- CVE-2024-77331 PoCFastCMS New Article Category Page cross site scripting
- CVE-2024-77381 PoCyzane vscode-markdown-pdf Markdown File pathname traversal
- CVE-2024-77391 PoCyzane vscode-markdown-pdf cross site scripting
- CVE-2024-77401 PoCwanglongcn ltcms API Endpoint download server-side request forgery
- CVE-2024-77411 PoCwanglongcn ltcms API Endpoint downloadfile downloadFile path traversal
- CVE-2024-77421 PoCwanglongcn ltcms API Endpoint multiDownload server-side request forgery
- CVE-2024-77431 PoCwanglongcn ltcms API Endpoint downloadUrl server-side request forgery
- CVE-2024-77481 PoCSourceCodester Accounts Manager App delete-account.php sql injection
- CVE-2024-77491 PoCSourceCodester Accounts Manager App add-account.php cross site scripting
- CVE-2024-77501 PoCSourceCodester Clinics Patient Management System medicines.php sql injection
- CVE-2024-77511 PoCSourceCodester Clinics Patient Management System update_medicine.php sql injection
- CVE-2024-77521 PoCSourceCodester Clinics Patient Management System update_medicine.php cross site scripting
- CVE-2024-77531 PoCSourceCodester Clinics Patient Management System user_images direct request
- CVE-2024-77541 PoCSourceCodester Clinics Patient Management System check_medicine_name.php sql injection
- CVE-2024-77581 PoCStylish Price List < 7.1.8 - Contributor+ Stored XSS
- CVE-2024-77591 PoCPWA For WP & AMP < 1.7.72 Administrator+ Stored XSS
- CVE-2024-77611 PoCSimple Job Board < 2.12.2 - Admin+ Stored XSS
- CVE-2024-77621 PoCSimple Job Board < 2.12.6 - Unauthenticated Resumes Download
- CVE-2024-77661 PoCAdicon Server <= 1.2 - Admin+ SQL Injection
- CVE-2024-77691 PoCWordpress Clicksold IDX Plugin <= 1.90 - Admin+ XSS
- CVE-2024-77862 PoCsSensei LMS < 4.24.2 - Unauthenticated Email Template Leak
- CVE-2024-77921 PoCSourceCodester Task Progress Tracker delete-task.php sql injection
- CVE-2024-77931 PoCSourceCodester Task Progress Tracker add-task.php cross site scripting
- CVE-2024-77941 PoCitsourcecode Vehicle Management System mybill.php sql injection
- CVE-2024-77971 PoCSourceCodester Simple Online Bidding System ajax.php sql injection
- CVE-2024-77981 PoCSourceCodester Simple Online Bidding System ajax.php sql injection
- CVE-2024-77991 PoCSourceCodester Simple Online Bidding System users.php improper authorization
- CVE-2024-78001 PoCSourceCodester Simple Online Bidding System ajax.php sql injection
- CVE-2024-78012 PoCsSQL injection in get_chart_data in TimeProvider 4100
- CVE-2024-78031 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2024-78082 PoCscode-projects Job Portal logindbc.php sql injection
- CVE-2024-78091 PoCSourceCodester Online Graduate Tracer System nbproject exposure of information through directory listing
- CVE-2024-78101 PoCSourceCodester Online Graduate Tracer System view_itprofile.php sql injection
- CVE-2024-78111 PoCSourceCodester Daily Expenses Monitoring App delete-expense.php sql injection
- CVE-2024-78121 PoCSourceCodester Best House Rental Management System POST Parameter ajax.php cross site scripting
- CVE-2024-78131 PoCSourceCodester Prison Management System Profile Image insufficiently protected credentials
- CVE-2024-78141 PoCCodeAstro Online Railway Reservation System Add Employee Page admin-add-employee.php cross site scripting
- CVE-2024-78152 PoCsCodeAstro Online Railway Reservation System Update Employee Page admin-update-employee.php cross site scripting
- CVE-2024-78161 PoCGixaw Chat <= 1.0 - Stored XSS via CSRF
- CVE-2024-78171 PoCMisiek Photo Album <= 1.4.3 - Album Deletion via CSRF
- CVE-2024-78181 PoCMisiek Photo Album <= 1.4.3 - Stored XSS via CSRF
- CVE-2024-78201 PoCILC Thickbox <= 1.0 - Settings update via CSRF
- CVE-2024-78221 PoCQuick Code <= 1.0 - Stored XSS via CSRF
- CVE-2024-78281 PoCD-Link DNS-1550-04 photocenter_mgr.cgi cgi_set_cover buffer overflow
- CVE-2024-78291 PoCD-Link DNS-1550-04 photocenter_mgr.cgi cgi_del_photo buffer overflow
- CVE-2024-78301 PoCD-Link DNS-1550-04 photocenter_mgr.cgi cgi_move_photo buffer overflow
- CVE-2024-78311 PoCD-Link DNS-1550-04 photocenter_mgr.cgi cgi_get_cooliris buffer overflow
- CVE-2024-78321 PoCD-Link DNS-1550-04 photocenter_mgr.cgi cgi_get_fullscreen_photos buffer overflow
- CVE-2024-78331 PoCD-Link DI-8100 upgrade_filter.asp upgrade_filter_asp command injection
- CVE-2024-78381 PoCitsourcecode Online Food Ordering System addcategory.php sql injection
- CVE-2024-78391 PoCitsourcecode Billing System addbill.php sql injection
- CVE-2024-78411 PoCSourceCodester Clinics Patient Management System check_user_name.php sql injection
- CVE-2024-78421 PoCSourceCodester Online Graduate Tracer System export_it.php information disclosure
- CVE-2024-78431 PoCSourceCodester Online Graduate Tracer System exportcs.php information disclosure
- CVE-2024-78441 PoCSourceCodester Online Graduate Tracer System add_acc.php cross site scripting
- CVE-2024-78451 PoCSourceCodester Online Graduate Tracer System fetch_it.php sql injection
- CVE-2024-78461 PoCYITH WooCommerce Ajax Search < 2.7.1 - Contributor+ Stored XSS
- CVE-2024-78491 PoCD-Link DNS-1550-04 photocenter_mgr.cgi cgi_create_album buffer overflow
- CVE-2024-78511 PoCSourceCodester Yoga Class Registration System Add User Users.php improper authorization
- CVE-2024-78521 PoCSourceCodester Yoga Class Registration System view_inquiry.php cross site scripting
- CVE-2024-78531 PoCSourceCodester Yoga Class Registration System sql injection
- CVE-2024-78542 PoCsWoo Inquiry <= 0.1 - Unauthenticated SQL Injection
- CVE-2024-78561 PoCMP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar <= 5.7.0.1 - Missing Authorization to Authenticated (Subscriber+)…
- CVE-2024-78591 PoCVisual Sound <= 1.03 - Settings Update via CSRF
- CVE-2024-78601 PoCSimple Headline Rotator <= 1.0 - Stored XSS via CSRF
- CVE-2024-78611 PoCMisiek Paypal <= 1.1.20090324 - Stored XSS via CSRF
- CVE-2024-78621 PoCBlog Introduction <= 0.3.0 - Settings Update via CSRF
- CVE-2024-78631 PoCFavicon Generator < 2.1 - Arbitrary File Upload via CSRF
- CVE-2024-78641 PoCFavicon Generator < 2.1 - Arbitrary File Deletion via CSRF
- CVE-2024-78761 PoCAppointment Booking Calendar < 1.6.7.55 - Admin+ Stored XSS
- CVE-2024-78771 PoCAppointment Booking Calendar < 1.6.7.55 - Admin+ Stored XSS
- CVE-2024-78781 PoCWP ULike < 4.7.4 - Admin+ Stored XSS
- CVE-2024-78791 PoCWP ULike < 4.7.5 - Admin+ Stored XSS via Widgets
- CVE-2024-78871 PoCLimeSurvey File Upload index.php denial of service
- CVE-2024-78911 PoCFloating Contact Button < 2.8 - Admin+ Stored XSS
- CVE-2024-78921 PoCadstxt Plugin <= 1.0.0 - Settings Update via CSRF
- CVE-2024-78961 PoCTosei Online Store Management System ネット店舗管理システム p1_ftpserver.php command injection
- CVE-2024-78971 PoCTosei Online Store Management System ネット店舗管理システム tosei_kikai.php command injection
- CVE-2024-78981 PoCTosei Online Store Management System ネット店舗管理システム Backend default credentials
- CVE-2024-78991 PoCInnoCMS Backend edit code injection
- CVE-2024-79001 PoCxiaohe4966 TpMeCMS Basic Configuration config cross site scripting
- CVE-2024-79031 PoCDedeBIZ File Extension media_add.php unrestricted upload
- CVE-2024-79041 PoCDedeBIZ File Extension file_manage_control.php unrestricted upload
- CVE-2024-79051 PoCDedeBIZ archives_do.php AdminUpload unrestricted upload
- CVE-2024-79061 PoCDedeBIZ Attachment Settings select_images_post.php get_mime_type unrestricted upload
- CVE-2024-79071 PoCTOTOLINK X6000R cstecgi.cgi setSyslogCfg command injection
- CVE-2024-79081 PoCTOTOLINK EX1200L cstecgi.cgi setDefResponse stack-based overflow
- CVE-2024-79091 PoCTOTOLINK EX1200L cstecgi.cgi setLanguageCfg stack-based overflow
- CVE-2024-79101 PoCCodeAstro Online Railway Reservation System Profile Photo Update emp-profile-avatar.php unrestricted upload
- CVE-2024-79111 PoCSourceCodester Simple Online Bidding System index.php file inclusion
- CVE-2024-79121 PoCCodeAstro Online Railway Reservation System assets exposure of information through directory listing
- CVE-2024-79131 PoCitsourcecode Billing System addclient1.php sql injection
- CVE-2024-79141 PoCSourceCodester Yoga Class Registration System SystemSettings.php cross site scripting
- CVE-2024-79161 PoCnafisulbari/itsourcecode Insurance Management System Add Nominee Page addNominee.php cross site scripting
- CVE-2024-79171 PoCDouPHP Favicon system.php unrestricted upload
- CVE-2024-79181 PoCPocket Widget <= 0.1.3 - Admin+ Stored XSS
- CVE-2024-79191 PoCAnhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 GetDataList access control
- CVE-2024-79201 PoCAnhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 GetParkInThroughDeivces access control
- CVE-2024-79211 PoCAnhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 GetDataList access control
- CVE-2024-79221 PoCD-Link DNS-1550-04 myMusic.cgi cgi_write_playlist command injection
- CVE-2024-79241 PoCZZCMS list.php path traversal
- CVE-2024-79251 PoCZZCMS eginfo.php information disclosure
- CVE-2024-79261 PoCZZCMS about_edit.php path traversal
- CVE-2024-79271 PoCZZCMS class.php path traversal
- CVE-2024-79289 PoCsFastAdmin lang path traversal
- CVE-2024-79291 PoCSourceCodester Simple Forum Website Signup Page registration.php cross site scripting
- CVE-2024-79301 PoCSourceCodester Clinics Patient Management System get_packings.php sql injection
- CVE-2024-79311 PoCSourceCodester Online Graduate Tracer System view_csprofile.php sql injection
- CVE-2024-79331 PoCitsourcecode Project Expense Monitoring System Backend Login login1.php sql injection
- CVE-2024-79341 PoCitsourcecode Project Expense Monitoring System execute.php sql injection
- CVE-2024-79351 PoCitsourcecode Project Expense Monitoring System print.php sql injection
- CVE-2024-79361 PoCitsourcecode Project Expense Monitoring System transferred_report.php sql injection
- CVE-2024-79371 PoCitsourcecode Project Expense Monitoring System printtransfer.php sql injection
- CVE-2024-79421 PoCSourceCodester Leads Manager Tool update-leads.php cross site scripting
- CVE-2024-79431 PoCitsourcecode Laravel Property Management System PropertiesController.php upload unrestricted upload
- CVE-2024-79441 PoCitsourcecode Laravel Property Management System DocumentsController.php UpdateDocumentsRequest unrestricted upload
- CVE-2024-79451 PoCitsourcecode Laravel Property Management System Notes Page create cross site scripting
- CVE-2024-79461 PoCitsourcecode Online Blood Bank Management System User Signup register.php sql injection
- CVE-2024-79471 PoCSourceCodester Point of Sales and Inventory Management System login.php sql injection
- CVE-2024-79481 PoCSourceCodester Accounts Manager App Update Account Page update-account.php cross site scripting
- CVE-2024-79491 PoCSourceCodester Online Graduate Tracer System fetch_genderit.php sql injection
- CVE-2024-795413 PoCsSPIP porte_plume Plugin Arbitrary PHP Execution
- CVE-2024-79551 PoCStarbox < 3.5.2 - Admin+ Stored XSS
- CVE-2024-79652 PoCsKEVInappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap…
- CVE-2024-79661 PoCOut of bounds memory access in Skia in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had compromised the renderer…
- CVE-2024-79712 PoCsKEVType confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page.…
- CVE-2024-79821 PoCRegistrations for The Events Calendar < 2.12.4 - Unauthenticated Stored XSS
- CVE-2024-79841 PoCJoy Of Text Lite – SMS messaging for WordPress <= 2.3.1 - Settings Update via CSRF
- CVE-2024-79851 PoCFileOrganizer <= 1.0.9 - Authenticated (Subscriber+) Arbitrary File Upload