CVE-2024-8000 to CVE-2024-8999
290 CVEs with public proof-of-concept exploits.
- CVE-2024-80031 PoCGo-Tribe gotribe-admin Log routes.go InitRoutes deserialization
- CVE-2024-80051 PoCdemozx gf_cms JWT Authentication auth.go init hard-coded credentials
- CVE-2024-80091 PoCSensei LMS < 4.20.0 - Teacher+ Users Email Address Disclosure
- CVE-2024-80211 PoCOpen Redirect in gradio-app/gradio
- CVE-2024-80231 PoCchillzhuang SpringBlade list sql injection
- CVE-2024-80311 PoCSecure Downloads < 1.2.3 - Admin+ Arbitrary File Download
- CVE-2024-80321 PoCSmooth Gallery Replacement <= 1.0 - CSRF to Stored XSS
- CVE-2024-80411 PoCUncontrolled Resource Consumption in GitLab
- CVE-2024-80431 PoCVikinghammer Tweet <= 0.2.4 - Stored XSS via CSRF
- CVE-2024-80441 PoCinfolinks Ad Wrap <= 1.0.2 - Settings Update via CSRF
- CVE-2024-80471 PoCVisual Sound (old) <= 1.06 - Settings Update via CSRF
- CVE-2024-80501 PoCCustom Author Base <= 1.1.1 - Settings Update via CSRF
- CVE-2024-80511 PoCSpecial Feed Items <= 1.0.1 - Stored XSS via CSRF
- CVE-2024-80521 PoCReview Ratings <= 1.6 - Stored XSS via CSRF
- CVE-2024-80541 PoCMM-Breaking News <= 0.7.9 - Stored XSS via CSRF
- CVE-2024-80561 PoCMM-Breaking News <= 0.7.9 - Reflected XSS
- CVE-2024-80682 PoCsKEVPrivilege escalation to NetworkService Account access
- CVE-2024-80692 PoCsKEVLimited remote code execution with privilege of a NetworkService Account access
- CVE-2024-80721 PoCMage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users
- CVE-2024-80801 PoCSourceCodester Online Health Care System search.php sql injection
- CVE-2024-80811 PoCitsourcecode Payroll Management System login.php sql injection
- CVE-2024-80821 PoCWidgets Reset <= 0.1 - Settings Update via CSRF
- CVE-2024-80831 PoCSourceCodester Online Computer and Laptop Store Master.php sql injection
- CVE-2024-80841 PoCSourceCodester Online Computer and Laptop Store Setting SystemSettings.php cross site scripting
- CVE-2024-80851 PoCPeoplePond <= 1.1.9 - CSRF to Stored XSS
- CVE-2024-80861 PoCSourceCodester E-Commerce System Admin Login login.php sql injection
- CVE-2024-80871 PoCSourceCodester E-Commerce System popup_Item.php sql injection
- CVE-2024-80891 PoCSourceCodester E-Commerce System controller.php unrestricted upload
- CVE-2024-80901 PoCJavaScript Logic <= 0.1 - CSRF to Stored XSS
- CVE-2024-80911 PoCEnhanced Search Box <= 0.6.1 - Settings Update via CSRF
- CVE-2024-80921 PoCAccordion Image Menu <= 3.1.3 - Stored XSS via CSRF
- CVE-2024-80931 PoCPosts reminder <= 0.20 - Settings Update via CSRF
- CVE-2024-80941 PoCNtz Antispam <= 2.0e - Settings Update via CSRF
- CVE-2024-80951 PoCBabelZ – Google Translate Widget <= 1.1.5 - CSRF to Stored XSS
- CVE-2024-81121 PoCthinkgem JeeSite Cookie login cross site scripting
- CVE-2024-81141 PoCMissing Authorization in GitLab
- CVE-2024-81161 PoCIncorrect Authorization in GitLab
- CVE-2024-81181 PoCGrafana alerting wrong permission on datasource rule write endpoint
- CVE-2024-81241 PoCInefficient Regular Expression Complexity in GitLab
- CVE-2024-81271 PoCD-Link DNS-1550-04 HTTP POST Request webfile_mgr.cgi cgi_unzip command injection
- CVE-2024-81281 PoCD-Link DNS-1550-04 HTTP POST Request webfile_mgr.cgi cgi_add_zip command injection
- CVE-2024-81291 PoCD-Link DNS-1550-04 HTTP POST Request s3.cgi cgi_s3_modify command injection
- CVE-2024-81301 PoCD-Link DNS-1550-04 HTTP POST Request s3.cgi cgi_s3 command injection
- CVE-2024-81311 PoCD-Link DNS-1550-04 HTTP POST Request apkg_mgr.cgi module_enable_disable command injection
- CVE-2024-81321 PoCD-Link DNS-1550-04 HTTP POST Request webdav_mgr.cgi webdav_mgr command injection
- CVE-2024-81331 PoCD-Link DNS-1550-04 HTTP POST Request hd_config.cgi cgi_FMT_R5_SpareDsk_DiskMGR command injection
- CVE-2024-81341 PoCD-Link DNS-1550-04 HTTP POST Request hd_config.cgi cgi_FMT_Std2R5_1st_DiskMGR command injection
- CVE-2024-81361 PoCSourceCodester Record Management System sort1_user.php cross site scripting
- CVE-2024-81371 PoCSourceCodester Record Management System search_user.php cross site scripting
- CVE-2024-81381 PoCcode-projects Pharmacy Management System Parameter index.php editManager sql injection
- CVE-2024-81391 PoCitsourcecode E-Commerce Website search_list.php sql injection
- CVE-2024-81401 PoCSourceCodester Task Progress Tracker update-task.php cross site scripting
- CVE-2024-81411 PoCSourceCodester Daily Calories Monitoring Tool add-calorie.php cross site scripting
- CVE-2024-81421 PoCSourceCodester Daily Calories Monitoring Tool delete-calorie.php cross site scripting
- CVE-2024-81441 PoCClassCMS Logo admin cross site scripting
- CVE-2024-81451 PoCClassCMS Article admin cross site scripting
- CVE-2024-81461 PoCcode-projects Pharmacy Management System index.php sql injection
- CVE-2024-81471 PoCcode-projects Pharmacy Management System index.php sql injection
- CVE-2024-81501 PoCContiNew Admin user sql injection
- CVE-2024-81511 PoCSourceCodester Interactive Map with Marker delete-mark.php cross site scripting
- CVE-2024-81521 PoCSourceCodester QR Code Bookmark System Parameter add-bookmark.php cross site scripting
- CVE-2024-81531 PoCSourceCodester QR Code Bookmark System delete-bookmark.php cross site scripting
- CVE-2024-81541 PoCSourceCodester QR Code Bookmark System Parameter update-bookmark.php cross site scripting
- CVE-2024-81551 PoCContiNew Admin tree sql injection
- CVE-2024-81571 PoCAlphabetical List <= 1.0.3 - Settings Update via CSRF
- CVE-2024-81621 PoCTOTOLINK T10 AC1200 Telnet Service product.ini hard-coded credentials
- CVE-2024-81631 PoCChengdu Everbrite Network Technology BeikeShop files destroyFiles path traversal
- CVE-2024-81641 PoCChengdu Everbrite Network Technology BeikeShop FileManagerController.php rename unrestricted upload
- CVE-2024-81651 PoCChengdu Everbrite Network Technology BeikeShop export exportZip path traversal
- CVE-2024-81661 PoCRuijie EG2000K index.php unrestricted upload
- CVE-2024-81671 PoCcode-projects Job Portal forget.php sql injection
- CVE-2024-81681 PoCcode-projects Online Bus Reservation Site login.php sql injection
- CVE-2024-81691 PoCcode-projects Online Quiz Site signupuser.php sql injection
- CVE-2024-81701 PoCSourceCodester Zipped Folder Manager App add-folder.php unrestricted upload
- CVE-2024-81711 PoCitsourcecode Tailoring Management System staffcatedit.php sql injection
- CVE-2024-81721 PoCSourceCodester QR Code Attendance System delete-student.php cross site scripting
- CVE-2024-81731 PoCcode-projects Blood Bank System Login Page login.php sql injection
- CVE-2024-81741 PoCcode-projects Blood Bank System Login Page login.php cross site scripting
- CVE-2024-81761 PoCLibexpat: expat: improper restriction of xml entity expansion depth in libexpat
- CVE-2024-81771 PoCInefficient Algorithmic Complexity in GitLab
- CVE-2024-81791 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2024-81801 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2024-81811 PoCFlowise Authentication Bypass
- CVE-2024-81861 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2024-81871 PoCSmart Post Show <= 3.0.0 - Editor+ Stored XSS
- CVE-2024-81904 PoCsKEVAn OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated…
- CVE-2024-81931 PoCHeap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process…
- CVE-2024-81981 PoCHeap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process…
- CVE-2024-82101 PoCD-Link DNS-1550-04 hd_config.cgi sprintf command injection
- CVE-2024-82111 PoCD-Link DNS-1550-04 hd_config.cgi cgi_FMT_Std2R1_DiskMGR command injection
- CVE-2024-82121 PoCD-Link DNS-1550-04 hd_config.cgi cgi_FMT_R12R5_2nd_DiskMGR command injection
- CVE-2024-82131 PoCD-Link DNS-1550-04 hd_config.cgi cgi_FMT_R12R5_1st_DiskMGR command injection
- CVE-2024-82141 PoCD-Link DNS-1550-04 hd_config.cgi cgi_FMT_Std2R5_2nd_DiskMGR command injection
- CVE-2024-82171 PoCSourceCodester E-Commerce Website registration.php sql injection
- CVE-2024-82181 PoCcode-projects Online Quiz Site index.php sql injection
- CVE-2024-82191 PoCcode-projects Responsive Hotel Site index.php sql injection
- CVE-2024-82201 PoCitsourcecode Tailoring Management System staffedit.php sql injection
- CVE-2024-82211 PoCSourceCodester Music Gallery Site manage_category.php sql injection
- CVE-2024-82221 PoCSourceCodester Music Gallery Site sql injection
- CVE-2024-82231 PoCSourceCodester Music Gallery Site Master.php sql injection
- CVE-2024-82241 PoCTenda G3 setDebugCfg formSetDebugCfg stack-based overflow
- CVE-2024-82251 PoCTenda G3 SetSysTimeCfg formSetSysTime stack-based overflow
- CVE-2024-82261 PoCTenda O1 setcfm formSetCfm stack-based overflow
- CVE-2024-82271 PoCTenda O1 DhcpSetSer fromDhcpSetSer stack-based overflow
- CVE-2024-82281 PoCTenda O5 setMacFilterList fromSafeSetMacFilter stack-based overflow
- CVE-2024-82291 PoCTenda O6 operateMacFilter frommacFilterModify stack-based overflow
- CVE-2024-82301 PoCTenda O6 setMacFilterList fromSafeSetMacFilter stack-based overflow
- CVE-2024-82311 PoCTenda O6 setPortForward fromVirtualSet stack-based overflow
- CVE-2024-82321 PoCiniNet Solutions SpiderControl SCADA Web Server Unrestricted Upload of File with Dangerous Type
- CVE-2024-82332 PoCsInefficient Algorithmic Complexity in GitLab
- CVE-2024-82371 PoCInefficient Algorithmic Complexity in GitLab
- CVE-2024-82391 PoCStarbox < 3.5.3 - Contributor+ Stored XSS
- CVE-2024-82431 PoCPlugin Upgrade Time Out <= 1.0 - Stored XSS via CSRF
- CVE-2024-82451 PoCGamiPress - Reset User <= 1.0.0 - GamiPress User Data Removal via CSRF
- CVE-2024-82521 PoCClean Login <= 1.14.5 - Authenticated (Contributor+) Local File Inclusion
- CVE-2024-82662 PoCsExecution with Unnecessary Privileges in GitLab
- CVE-2024-82751 PoCThe Events Calendar <= 6.6.4 - Unauthenticated SQL Injection
- CVE-2024-82831 PoCSlider by 10Web < 1.2.59 - Admin+ Stored XSS
- CVE-2024-82841 PoCDownload Manager <= 3.2.98 - Admin+ Stored XSS
- CVE-2024-82861 PoCGDPR Cookie Consent <= 2.6.0 - Bulk Delete via CSRF
- CVE-2024-82891 PoCMultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.0 - Missing Authorization to Limited Vendor Privilege…
- CVE-2024-82941 PoCFeehiCMS index.php update unrestricted upload
- CVE-2024-82951 PoCFeehiCMS index.php createBanner unrestricted upload
- CVE-2024-82961 PoCFeehiCMS index.php insert unrestricted upload
- CVE-2024-83011 PoCdingfanzu CMS checkin.php sql injection
- CVE-2024-83021 PoCdingfanzu CMS chpwd.php sql injection
- CVE-2024-83031 PoCdingfanzu CMS getBasicInfo.php sql injection
- CVE-2024-83041 PoCjpress Template Module edit path traversal
- CVE-2024-83091 PoCSQL Injection in langchain-ai/langchain
- CVE-2024-83121 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2024-83311 PoCOpenRapid RapidCMS user-move-run.php sql injection
- CVE-2024-83351 PoCOpenRapid RapidCMS runlogon.php sql injection
- CVE-2024-83361 PoCSourceCodester Music Gallery Site Master.php sql injection
- CVE-2024-83371 PoCSourceCodester Contact Manager with Export to VCF index.html cross site scripting
- CVE-2024-83381 PoCHFO4 shudong-share File Extension fileReceive.php unrestricted upload
- CVE-2024-83391 PoCSourceCodester Electric Billing Management System Connection Code ?page=tracks sql injection
- CVE-2024-83401 PoCSourceCodester Electric Billing Management System Actions.php sql injection
- CVE-2024-83411 PoCSourceCodester Petshop Management System add_user.php unrestricted upload
- CVE-2024-83421 PoCSourceCodester Petshop Management System add_client.php unrestricted upload
- CVE-2024-83431 PoCSourceCodester Sentiment Based Movie Rating System User Registration Users.php sql injection
- CVE-2024-83441 PoCCampcodes Supplier Management System edit_area.php sql injection
- CVE-2024-83451 PoCSourceCodester Music Gallery Site Users.php sql injection
- CVE-2024-83461 PoCSourceCodester Computer Laboratory Management System SystemSettings.php update_settings_info sql injection
- CVE-2024-83471 PoCSourceCodester Computer Laboratory Management System Master.php delete_record sql injection
- CVE-2024-83481 PoCSourceCodester Computer Laboratory Management System Master.php delete_category sql injection
- CVE-2024-83491 PoCUncanny Groups for LearnDash <= 6.1.0.1 - Authenticated (Group Leader+) Privilege Escalation
- CVE-2024-83501 PoCUncanny Groups for LearnDash <= 6.1.0.1 - Missing Authorization to Authenticated (Group Leader+) User Group Add
- CVE-2024-83535 PoCsGiveWP – Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection
- CVE-2024-83621 PoCUse after free in WebAudio in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2024-83681 PoCcode-projects Hospital Management System Login index.php sql injection
- CVE-2024-83701 PoCGrocy SVG File Upload recipepictures cross site scripting
- CVE-2024-83722 PoCsAngularJS improper sanitization in 'srcset' attribute
- CVE-2024-83732 PoCsAngularJS improper sanitization in '<source>' element
- CVE-2024-83781 PoCSafe SVG < 2.2.6 - Author+ SVG Sanitisation Bypass
- CVE-2024-83791 PoCCost Calculator Builder < 3.2.29 - Admin+ SQL Injection
- CVE-2024-83801 PoCSourceCodester Contact Manager with Export to VCF Delete Contact delete-account.php sql injection
- CVE-2024-83811 PoCA potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with`…
- CVE-2024-83971 PoCGDPR Cookie Consent <= 2.6.0 - Unauthenticated Stored XSS
- CVE-2024-83981 PoCSimple Nav Archives <= 2.1.3 - Settings Update via CSRF
- CVE-2024-84021 PoCImproper Neutralization of Special Elements used in a Command ('Command Injection') in GitLab
- CVE-2024-84071 PoCalwindoss akademy handlers.go cross site scripting
- CVE-2024-84081 PoCLinksys WRT54G POST Parameter apply.cgi validate_services_port stack-based overflow
- CVE-2024-84091 PoCABCD ABCD2 show_image.php path traversal
- CVE-2024-84101 PoCABCD ABCD2 otros_sitios.php path traversal
- CVE-2024-84111 PoCABCD ABCD2 buscar_integrada.php cross site scripting
- CVE-2024-84141 PoCSourceCodester Insurance Management System cross-site request forgery
- CVE-2024-84151 PoCSourceCodester Food Ordering Management System add-ticket.php sql injection
- CVE-2024-84161 PoCSourceCodester Food Ordering Management System ticket-status.php sql injection
- CVE-2024-84171 PoC云课网络科技有限公司 Yunke Online School System videobind.html sensitive information in source
- CVE-2024-84252 PoCsWooCommerce Ultimate Gift Card <= 2.9.2 - Unauthenticated Arbitrary File Upload
- CVE-2024-84261 PoCPagelayer < 1.8.8 - Admin+ Stored XSS
- CVE-2024-84441 PoCDownload Manager < 3.3.00 - Contributor+ Stored XSS
- CVE-2024-84511 PoCPLANET Technology switch devices - SSH server DoS attack
- CVE-2024-84601 PoCD-Link DNS-320 Web Management Interface widget_api.cgi information disclosure
- CVE-2024-84611 PoCD-Link DNS-320 Web Management Interface discovery.cgi information disclosure
- CVE-2024-84652 PoCsSQL injection vulnerability in Job Portal
- CVE-2024-84842 PoCsREST API TO MiniProgram <= 4.7.1 - Unauthenticated SQL Injection
- CVE-2024-84921 PoCHustle < 7.8.5 - Admin+ Stored XSS
- CVE-2024-84931 PoCThe Events Calendar < 6.6.4 - Admin+ Stored XSS
- CVE-2024-85034 PoCsVICIdial Unauthenticated SQL Injection
- CVE-2024-85042 PoCsVICIdial Authenticated Remote Code Execution
- CVE-2024-85176 PoCsSPIP Bigup Multipart File Upload OS Command Injection
- CVE-2024-85211 PoCWavelog Live QSO qso index cross site scripting
- CVE-2024-85223 PoCsLearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
- CVE-2024-85231 PoClmxcms SQL Command Execution Module admin.php formatData code injection
- CVE-2024-85292 PoCsLearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'
- CVE-2024-85361 PoCUltimate Blocks < 3.2.2 - Contributor+ Stored XSS
- CVE-2024-85421 PoCEverest Forms < 3.0.3.1 - Admin+ Stored XSS
- CVE-2024-85541 PoCSourceCodester Clinics Patient Management System users.php cross site scripting
- CVE-2024-85551 PoCSourceCodester Clinics Patient Management System congratulations.php redirect
- CVE-2024-85571 PoCSourceCodester Food Ordering Management System cancel-order.php sql injection
- CVE-2024-85581 PoCSourceCodester Food Ordering Management System Price place-order.php improper validation of specified quantity in input
- CVE-2024-85652 PoCsSourceCodesters Clinics Patient Management System print_diseases.php sql injection
- CVE-2024-85661 PoCcode-projects Online Shop Store settings.php cross site scripting
- CVE-2024-85671 PoCitsourcecode Payroll Management System ajax.php sql injection
- CVE-2024-85681 PoCMini-Tmall 1 rewardMapper.select sql injection
- CVE-2024-85691 PoCcode-projects Hospital Management System user-login.php sql injection
- CVE-2024-85701 PoCitsourcecode Tailoring Management System inccatadd.php sql injection
- CVE-2024-85731 PoCTOTOLINK AC1200 T8/AC1200 T10 cstecgi.cgi setParentalRules buffer overflow
- CVE-2024-85741 PoCTOTOLINK AC1200 T8 cstecgi.cgi setParentalRules os command injection
- CVE-2024-85751 PoCTOTOLINK AC1200 T8 cstecgi.cgi setWiFiScheduleCfg buffer overflow
- CVE-2024-85761 PoCTOTOLINK AC1200 T8/AC1200 T10 cstecgi.cgi setIpPortFilterRules buffer overflow
- CVE-2024-85771 PoCTOTOLINK AC1200 T8/AC1200 T10 cstecgi.cgi setStaticDhcpRules buffer overflow
- CVE-2024-85781 PoCTOTOLINK AC1200 T8 cstecgi.cgi setWiFiMeshName buffer overflow
- CVE-2024-85791 PoCTOTOLINK AC1200 T8 cstecgi.cgi setWiFiRepeaterCfg buffer overflow
- CVE-2024-85801 PoCTOTOLINK AC1200 T8 shadow.sample hard-coded password
- CVE-2024-85821 PoCSourceCodester Food Ordering Management System index.php cross site scripting
- CVE-2024-85831 PoCSourceCodester Online Bank Management System Feedback mfeedback.php cross site scripting
- CVE-2024-86051 PoCcode-projects Inventory Management Registration Form registration.php cross site scripting
- CVE-2024-86101 PoCSourceCodester Best House Rental Management System New Tenant Page index.php cross site scripting
- CVE-2024-86111 PoCitsourcecode Tailoring Management System ssms.php sql injection
- CVE-2024-86171 PoCQuiz Maker <= 6.5.9.8 - Admin+ Stored XSS
- CVE-2024-86181 PoCPage Builder: Pagelayer < 1.9.0- Admin+ Stored XSS
- CVE-2024-86191 PoCAjax Search Lite <= 4.12.2 - Admin+ Stored XSS
- CVE-2024-86201 PoCMapPress Maps for WordPress < 2.93 - Admin+ Stored XSS via Map Settings
- CVE-2024-86252 PoCsTS Poll – Survey, Versus Poll, Image Poll, Video Poll < 2.4.0 - Admin+ SQL Injection
- CVE-2024-86311 PoCPrivilege Defined With Unsafe Actions in GitLab
- CVE-2024-86361 PoCHeap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via…
- CVE-2024-86401 PoCImproper Neutralization of Special Elements used in a Command ('Command Injection') in GitLab
- CVE-2024-86411 PoCPrivilege Context Switching Error in GitLab
- CVE-2024-86472 PoCsImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
- CVE-2024-86481 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2024-86502 PoCsIncorrect Authorization in GitLab
- CVE-2024-86701 PoCPhoto Gallery by 10Web < 1.8.29 - Admin+ Stored XSS
- CVE-2024-86721 PoCWidget Options – The #1 WordPress Widget & Block Control Plugin <= 4.0.7 - Authenticated (Contributor+) Remote Code Execution
- CVE-2024-86732 PoCsZ-Downloads < 1.11.7 - Admin+ Stored XSS via SVG Upload
- CVE-2024-86821 PoCJNews - WordPress Newspaper Magazine Blog AMP Theme <= 11.6.6 - Unauthorized User Registration
- CVE-2024-86921 PoCTDuckCloud TDuckPro password recovery
- CVE-2024-86931 PoCKaon CG3000 dhcpcd Command cross site scripting
- CVE-2024-86941 PoCJFinalCMS com.cms.controller.admin.TemplateController update path traversal
- CVE-2024-86982 PoCsKeycloak-saml-core: improper verification of saml responses leading to privilege escalation in keycloak
- CVE-2024-86991 PoCZ-Downloads < 1.11.5 - Admin+ Arbitrary File Upload
- CVE-2024-87001 PoCEvent Calendar <= 1.0.4 - Unauthenticated Arbitrary Calendar Deletion
- CVE-2024-87011 PoCEvent Calendar <= 1.0.4 - Admin+ Stored XSS
- CVE-2024-87021 PoCBackup Database <= 4.9 - Admin+ Stored XSS
- CVE-2024-87031 PoCZ-Downloads < 1.11.6 - Unauthenticated Stored XSS
- CVE-2024-87051 PoCShandong Star Measurement and Control Equipment Heating Network Wireless Monitoring System UCCGSrv.asmx GetDataKindByType sql injection
- CVE-2024-87061 PoCJFinalCMS com.cms.util.TemplateUtils update path traversal
- CVE-2024-87071 PoC云课网络科技有限公司 Yunke Online School System Appadmin.php downfile path traversal
- CVE-2024-87091 PoCSourceCodester Best House Rental Management System admin_class.php save_user sql injection
- CVE-2024-87101 PoCcode-projects Inventory Management Products Table Page viewProduct.php sql injection
- CVE-2024-87111 PoCSourceCodester Food Ordering Management System includes exposure of information through directory listing
- CVE-2024-87431 PoCBit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress <= 6.5.7 - Authenticated (Subscriber+) Limited…
- CVE-2024-87522 PoCsWebIQ 2.15.9 Runtime on Windows - Directory Traversal Vulnerability
- CVE-2024-87581 PoCQuiz and Survey Master (QSM) < 9.1.3 - Author+ Stored XSS
- CVE-2024-87591 PoCNested Pages <= 3.2.8 - Editor+ Stored XSS
- CVE-2024-87621 PoCcode-projects Crud Operation System updatedata.php sql injection
- CVE-2024-87821 PoCJFinalCMS edit delete path traversal
- CVE-2024-87831 PoCOpenTibiaBR MyAAC Post Reply new_post.php cross site scripting
- CVE-2024-87841 PoCQDocs Smart School Management System Chat mynewuser sql injection
- CVE-2024-88511 PoCPolls CP <= 1.0.75 - Admin+ Stored Cross-Site Scripting
- CVE-2024-88521 PoCAll-in-One WP Migration and Backup <= 7.86 - Unauthenticated Information Disclosure via Error Logs
- CVE-2024-88541 PoCPolls CP <= 1.0.75 - Admin+ Stored XSS via Custom Styles
- CVE-2024-88551 PoCWordPress Auction <= 3.7 - Editor+ SQL Injection
- CVE-2024-88567 PoCsBackup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
- CVE-2024-88571 PoCWordPress Auction <= 3.7 - Editor+ Stored XSS
- CVE-2024-88591 PoCPath Traversal in mlflow/mlflow
- CVE-2024-88621 PoCh2oai h2o-3 JDBC Connection 1 getConnectionSafe deserialization
- CVE-2024-88631 PoCaimhubio aim Text Explorer textbox.tsx dangerouslySetInnerHTML cross site scripting
- CVE-2024-88641 PoCcomposiohq composio calculator.py Calculator code injection
- CVE-2024-88651 PoCcomposiohq composio api.py path path traversal
- CVE-2024-88661 PoCAutoCMS robot.php cross site scripting
- CVE-2024-88672 PoCsPerfex CRM Parameter Clients.php cross site scripting
- CVE-2024-88681 PoCcode-projects Crud Operation System savedata.php sql injection
- CVE-2024-88751 PoCvedees wcms finder.php path traversal
- CVE-2024-88761 PoCxiaohe4966 TpMeCMS lang path traversal
- CVE-2024-88772 PoCsSQL Injection
- CVE-2024-88781 PoCUnauthenticated Password Reset
- CVE-2024-88831 PoCKeycloak: vulnerable redirect uri validation results in open redirec
- CVE-2024-89021 PoCElementor Addon Elements <= 1.13.8 - Authenticated (Contributor+) Sensitive Information Exposure via table_saved_sections
- CVE-2024-89041 PoCType Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2024-89051 PoCInappropriate implementation in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit stack…
- CVE-2024-89111 PoCLatePoint <= 5.0.11 - Unauthenticated Arbitrary User Password Change via SQL Injection
- CVE-2024-89251 PoCErroneous parsing of multipart form data
- CVE-2024-89262 PoCsPHP CGI Parameter Injection Vulnerability (CVE-2024-4577 bypass)
- CVE-2024-89291 PoCLeak partial content of the heap through heap buffer over-read in mysqlnd
- CVE-2024-89431 PoCLatePoint <= 5.0.12 - Authentication Bypass
- CVE-2024-89441 PoCcode-projects Hospital Management System check_availability.php sql injection
- CVE-2024-89452 PoCsCodeCanyon RISE Ultimate Project Manager save sql injection
- CVE-2024-89461 PoCMicroPython VFS Unmount vfs.c mp_vfs_umount heap-based overflow
- CVE-2024-89471 PoCMicroPython objarray.c use after free
- CVE-2024-89481 PoCMicroPython objint.c mpz_as_bytes heap-based overflow
- CVE-2024-89493 PoCsSourceCodester Online Eyewear Shop Cart Content Master.php improper ownership management
- CVE-2024-89511 PoCSourceCodester Resort Reservation System manage_fee.php cross site scripting
- CVE-2024-89634 PoCsKEVPath Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
- CVE-2024-89681 PoCMaxButtons < 9.8.1 - Admin+ Stored XSS via Text Color
- CVE-2024-89701 PoCIncorrect Authorization in GitLab
- CVE-2024-89731 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2024-89771 PoCServer-Side Request Forgery (SSRF) in GitLab
- CVE-2024-89831 PoCCustom Twitter Feeds < 2.2.3 - Admin+ Stored XSS