CVE-2024-9000 to CVE-2024-9999
263 CVEs with public proof-of-concept exploits.
- CVE-2024-90011 PoCTOTOLINK T10 cstecgi.cgi setTracerouteCfg os command injection
- CVE-2024-90031 PoCJinan Chicheng Company JFlow Attachment EntityMutliFile_Load.do AttachmentUploadController access control
- CVE-2024-90041 PoCD-Link DAR-7000 Backup_Server_commit.php os command injection
- CVE-2024-90061 PoCjeanmarc77 123solar config_invt1.php code injection
- CVE-2024-90072 PoCsjeanmarc77 123solar detailed.php cross site scripting
- CVE-2024-90081 PoCSourceCodester Best Online News Portal Comment Section news-details.php sql injection
- CVE-2024-90091 PoCcode-projects Online Quiz Site showtest.php sql injection
- CVE-2024-90111 PoCcode-projects Crud Operation System updata.php sql injection
- CVE-2024-90143 PoCsOAuth2 client id and secret exposed through the web browser in pgAdmin 4
- CVE-2024-90201 PoCList category posts < 0.90.3 - Author+ Stored XSS
- CVE-2024-90211 PoCRelevanssi < 4.23.1 - Contributor+ Stored XSS
- CVE-2024-90221 PoCTS Poll – Survey, Versus Poll, Image Poll, Video Poll <= 2.4.0 - Authenticated (Administrator+) SQL Injection via orderby Parameter
- CVE-2024-90261 PoCPHP-FPM logs from children may be altered
- CVE-2024-90301 PoCCodeCanyon CRMGo SaaS note cross site scripting
- CVE-2024-90311 PoCCodeCanyon CRMGo SaaS show cross site scripting
- CVE-2024-90321 PoCSourceCodester Simple Forum-Discussion System index.php path traversal
- CVE-2024-90331 PoCSourceCodester Best House Rental Management System ajax.php cross site scripting
- CVE-2024-90341 PoCcode-projects Patient Record Management System login.php sql injection
- CVE-2024-90351 PoCcode-projects Blood Bank Management System Admin Login login.php sql injection
- CVE-2024-90361 PoCitsourcecode Online Bookstore admin_add.php unrestricted upload
- CVE-2024-90371 PoCCodezips Internal Marks Calculation index.php sql injection
- CVE-2024-90381 PoCCodezips Online Shopping Portal insert-product.php unrestricted upload
- CVE-2024-90391 PoCSourceCodester Best House Rental Management System ajax.php sql injection
- CVE-2024-90411 PoCSourceCodester Best House Rental Management System ajax.php sql injection
- CVE-2024-90477 PoCsWordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php
- CVE-2024-90481 PoCy_project RuoYi Backend User Import SysUserServiceImpl.java SysUserServiceImpl cross site scripting
- CVE-2024-90542 PoCsRemote code Execution inTimeProvider® 4100
- CVE-2024-90612 PoCsWP Popup Builder – Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via…
- CVE-2024-90761 PoCDedeCMS article_string_mix.php os command injection
- CVE-2024-90771 PoCdingfangzu Order Checkout order.js cross site scripting
- CVE-2024-90781 PoCcode-projects Student Record System course.php sql injection
- CVE-2024-90791 PoCcode-projects Student Record System marks.php sql injection
- CVE-2024-90801 PoCcode-projects Student Record System pincode-verification.php sql injection
- CVE-2024-90811 PoCSourceCodester Online Eyewear Shop view_category.php sql injection
- CVE-2024-90821 PoCSourceCodester Online Eyewear Shop User Creation Users.php improper authorization
- CVE-2024-90831 PoCSourceCodester Employee Management System add-admin.php cross site scripting
- CVE-2024-90841 PoCcode-projects Blood Bank System bbms.php cross site scripting
- CVE-2024-90851 PoCcode-projects Restaurant Reservation System index.php sql injection
- CVE-2024-90861 PoCcode-projects Restaurant Reservation System filter.php sql injection
- CVE-2024-90871 PoCcode-projects Vehicle Management edit1.php sql injection
- CVE-2024-90881 PoCSourceCodester Telecom Billing Management System login buffer overflow
- CVE-2024-90891 PoCSourceCodester Modern Loan Management System update_loan_record.php cross site scripting
- CVE-2024-90901 PoCSourceCodester Modern Loan Management System search_member.php sql injection
- CVE-2024-90911 PoCcode-projects Student Record System index.php sql injection
- CVE-2024-90921 PoCSourceCodester Profile Registration without Reload Refresh Registration Form add.php cross site scripting
- CVE-2024-90931 PoCSourceCodester Profile Registration without Reload Refresh GET Parameter del.php sql injection
- CVE-2024-90941 PoCcode-projects Blood Bank System o-.php sql injection
- CVE-2024-91061 PoCWechat Social login <= 1.3.0 - Authentication Bypass
- CVE-2024-91221 PoCType Confusion in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform out of bounds memory access via a…
- CVE-2024-91481 PoCFlowise Stored Cross-Site Scripting
- CVE-2024-91561 PoCTI WooCommerce Wishlist <= 2.8.2 - Unauthenticated SQL Injection via lang parameters
- CVE-2024-91611 PoCRank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Missing Authorization to Unauthenticated User and Term Metadata Insert,…
- CVE-2024-91621 PoCAll-in-One WP Migration and Backup <= 7.86 - Authenticated (Administrator+) Arbitrary PHP Code Injection
- CVE-2024-91631 PoCUser Interface (UI) Misrepresentation of Critical Information in GitLab
- CVE-2024-91641 PoCMissing Authentication for Critical Function in GitLab
- CVE-2024-91662 PoCsOS Command Injection in Atelmo Atemio AM 520 HD Full HD Satellite Receiver
- CVE-2024-91821 PoCMaspik - Advanced Spam protection < 2.1.3 - Admin+ Stored XSS
- CVE-2024-91831 PoCTime-of-check Time-of-use (TOCTOU) Race Condition in GitLab
- CVE-2024-91862 PoCsAutomation By Autonami < 3.3.0 - Unauthenticated SQLi
- CVE-2024-91931 PoCWHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update
- CVE-2024-92241 PoCHello World <= 2.1.1 - Authenticated (Subscriber+) Arbitrary File Read
- CVE-2024-92271 PoCPowerPress Podcasting < 11.9.18 - Author+ XSS
- CVE-2024-92301 PoCPowerPress Podcasting < 11.9.18 - Author+ XSS via Podcast URL
- CVE-2024-92331 PoCGS Logo Slider < 3.7.1 - Settings Update via Cross-Site Request Forgery
- CVE-2024-92343 PoCsGutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload
- CVE-2024-92361 PoCTeam Members Showcase < 4.4.2 - Editor+ Stored XSS
- CVE-2024-92381 PoCAVIF & SVG Uploader <= 1.1.0 - Author+ Stored XSS via SVG Uplaod
- CVE-2024-926416 PoCsGrafana SQL Expressions allow for remote code execution
- CVE-2024-92751 PoCjeanmarc77 123solar admin_invt2.php file inclusion
- CVE-2024-92771 PoCLangflow HTTP POST Request utils.py redos
- CVE-2024-92781 PoCHuankeMao SCRM Administrator Backend WxkConfig.php upload_domain_verification_file unrestricted upload
- CVE-2024-92791 PoCfunnyzpc Mee-Admin User Center index cross site scripting
- CVE-2024-92801 PoCkalvinGit kvf-admin FileUploadKit.java fileUpload unrestricted upload
- CVE-2024-92811 PoCbg5sbk MiniCMS post-edit.php cross-site request forgery
- CVE-2024-92821 PoCbg5sbk MiniCMS page-edit.php cross-site request forgery
- CVE-2024-92831 PoCRelaxedJS ReLaXed Pug to PDF Converter cross site scripting
- CVE-2024-92841 PoCTP-LINK TL-WR841ND popupSiteSurveyRpm.htm stack-based overflow
- CVE-2024-92852 PoCsTu Yafeng Via Browser Javascript Bridge cross site scripting
- CVE-2024-92902 PoCsSuper Backup & Clone - Migrate for WordPress <= 2.3.3 - Unauthenticated Arbitrary File Upload
- CVE-2024-92911 PoCkalvinGit kvf-admin XML File cross site scripting
- CVE-2024-92931 PoCskyselang yylAdmin Backend File.php list sql injection
- CVE-2024-92941 PoCdingfanzu CMS saveNewPwd.php sql injection
- CVE-2024-92951 PoCSourceCodester Advocate Office Management System login.php sql injection
- CVE-2024-92961 PoCSourceCodester Advocate Office Management System forgot_pass.php sql injection
- CVE-2024-92971 PoCSourceCodester Online Railway Reservation System admin improper authorization
- CVE-2024-92981 PoCSourceCodester Online Railway Reservation System Ticket ?page=tickets access control
- CVE-2024-92991 PoCSourceCodester Online Railway Reservation System ?page=reserve cross site scripting
- CVE-2024-93001 PoCSourceCodester Online Railway Reservation System Message Us Form contact_us.php cross site scripting
- CVE-2024-93151 PoCSourceCodester Employee and Visitor Gate Pass Logging System manage_department.php sql injection
- CVE-2024-93161 PoCcode-projects Blood Bank Management System B+.php sql injection
- CVE-2024-93171 PoCSourceCodester Online Eyewear Shop Master.php delete_category sql injection
- CVE-2024-93181 PoCSourceCodester Advocate Office Management System activate.php sql injection
- CVE-2024-93191 PoCSourceCodester Online Timesheet App delete-timesheet.php sql injection
- CVE-2024-93201 PoCSourceCodester Online Timesheet App Add Timesheet Form add-timesheet.php cross site scripting
- CVE-2024-93211 PoCSourceCodester Online Railway Reservation System view_details.php access control
- CVE-2024-93221 PoCcode-projects Supply Chain Management edit_manufacturer.php sql injection
- CVE-2024-93231 PoCSourceCodester Inventory Management System add_staff.php cross site scripting
- CVE-2024-93241 PoCIntelbras InControl Relatório de Operadores Page operador code injection
- CVE-2024-93262 PoCsPHPGurukul Online Shopping Portal Admin Panel index.php sql injection
- CVE-2024-93271 PoCcode-projects Blood Bank System forgot.php sql injection
- CVE-2024-93281 PoCSourceCodester Advocate Office Management System edit_client.php sql injection
- CVE-2024-93291 PoCGlassfish redirect to untrusted site
- CVE-2024-93581 PoCThingsBoard HTTP RPC API resource consumption
- CVE-2024-93591 PoCcode-projects Restaurant Reservation System addcompany.php sql injection
- CVE-2024-93601 PoCcode-projects Restaurant Reservation System updatebal.php sql injection
- CVE-2024-93621 PoCDirectory Traversal in polyaxon/polyaxon
- CVE-2024-93672 PoCsAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2024-93791 PoCKEVSQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to…
- CVE-2024-93872 PoCsURL Redirection to Untrusted Site ('Open Redirect') in GitLab
- CVE-2024-93901 PoCRegistrationMagic < 6.0.2.1 - Stored XSS
- CVE-2024-94111 PoCOFCMS add.json add cross site scripting
- CVE-2024-94221 PoCGEO My WordPress < 4.5 - Admin+ Arbitrary File Upload
- CVE-2024-94281 PoCPopup Builder < 4.3.5 - Admin+ Stored XSS
- CVE-2024-94291 PoCcode-projects Restaurant Reservation System filter2.php sql injection
- CVE-2024-94401 PoCSlim Select 2.0 createOption "text" XSS
- CVE-2024-94413 PoCsLinear eMerge e3-Series Forgot Password Command Injection
- CVE-2024-94501 PoCFree Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking < 1.3.15 - Subscriber+ PayPal Settings Update
- CVE-2024-94582 PoCsReservit Hotel < 3.0 - Admin+ Stored XSS
- CVE-2024-94601 PoCCodezips Online Shopping Portal index.php sql injection
- CVE-2024-94633 PoCsKEVExpedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
- CVE-2024-94644 PoCsExpedition: Authenticated OS Command Injection Vulnerability Leads to Firewall Admin Credential Disclosure
- CVE-2024-94655 PoCsKEVExpedition: SQL Injection Leads to Firewall Admin Credential Disclosure
- CVE-2024-94663 PoCsExpedition: Cleartext Storage of Information Leads to Firewall Admin Credential Disclosure
- CVE-2024-94731 PoCGlobalProtect App: Local Privilege Escalation (PE) Vulnerability
- CVE-2024-947413 PoCsKEVPAN-OS: Privilege Escalation (PE) Vulnerability in the Web Management Interface
- CVE-2024-94871 PoCAn Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO…
- CVE-2024-95121 PoCTime-of-check Time-of-use (TOCTOU) Race Condition in GitLab
- CVE-2024-95131 PoCNetadmin Software NetAdmin IAM HTTP POST Request ReturnUserQuestionsFilled information exposure
- CVE-2024-95141 PoCD-Link DIR-605L formSetDomainFilter buffer overflow
- CVE-2024-95151 PoCD-Link DIR-605L formSetQoS buffer overflow
- CVE-2024-95291 PoCSecure Custom Fields < 6.3.6.3 - Admin+ Remote Code Execution
- CVE-2024-95321 PoCD-Link DIR-605L formAdvanceSetup buffer overflow
- CVE-2024-95331 PoCD-Link DIR-605L formDeviceReboot buffer overflow
- CVE-2024-95341 PoCD-Link DIR-605L formEasySetPassword buffer overflow
- CVE-2024-95351 PoCD-Link DIR-605L formEasySetupWWConfig buffer overflow
- CVE-2024-95361 PoCESAFENET CDG MultiServerBackService sql injection
- CVE-2024-95491 PoCD-Link DIR-605L formEasySetupWizard formEasySetupWizard2 buffer overflow
- CVE-2024-95501 PoCD-Link DIR-605L formLogDnsquery buffer overflow
- CVE-2024-95511 PoCD-Link DIR-605L formSetWanL2TP buffer overflow
- CVE-2024-95521 PoCD-Link DIR-605L formSetWanNonLogin buffer overflow
- CVE-2024-95531 PoCD-Link DIR-605L formdumpeasysetup buffer overflow
- CVE-2024-95551 PoCD-Link DIR-605L formSetEasy_Wizard buffer overflow
- CVE-2024-95561 PoCD-Link DIR-605L formSetEnableWizard buffer overflow
- CVE-2024-95571 PoCD-Link DIR-605L formSetWanPPPoE buffer overflow
- CVE-2024-95581 PoCD-Link DIR-605L formSetWanPPTP buffer overflow
- CVE-2024-95591 PoCD-Link DIR-605L formWlanSetup buffer overflow
- CVE-2024-95601 PoCESAFENET CDG Catelogs;logindojojs delCatelogs sql injection
- CVE-2024-95611 PoCD-Link DIR-605L formSetWAN_Wizard52 buffer overflow
- CVE-2024-95621 PoCD-Link DIR-605L formSetWizard2 buffer overflow
- CVE-2024-95631 PoCD-Link DIR-605L formWlanSetup_Wizard buffer overflow
- CVE-2024-95641 PoCD-Link DIR-605L formWlanWizardSetup buffer overflow
- CVE-2024-95651 PoCD-Link DIR-605L formSetPassword buffer overflow
- CVE-2024-95661 PoCD-Link DIR-619L B1 formDeviceReboot buffer overflow
- CVE-2024-95671 PoCD-Link DIR-619L B1 formAdvFirewall buffer overflow
- CVE-2024-95681 PoCD-Link DIR-619L B1 formAdvNetwork buffer overflow
- CVE-2024-95691 PoCD-Link DIR-619L B1 formEasySetPassword buffer overflow
- CVE-2024-95702 PoCsD-Link DIR-619L B1 formEasySetTimezone buffer overflow
- CVE-2024-95933 PoCsTime Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution
- CVE-2024-95991 PoCPopup Box < 4.7.8 - Admin+ Stored XSS
- CVE-2024-96001 PoCDitty < 3.1.47 - Author+ Stored XSS
- CVE-2024-96021 PoCType Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to perform an out of bounds memory write via a…
- CVE-2024-96171 PoCIDOR in danswer-ai/danswer
- CVE-2024-96312 PoCsInefficient Algorithmic Complexity in GitLab
- CVE-2024-96331 PoCIncorrect Ownership Assignment in GitLab
- CVE-2024-96381 PoCCategory Posts Widget < 4.9.18 - Admin+ Stored XSS
- CVE-2024-96411 PoCLuckyWP Table of Contents < 2.1.7 - Admin+ Stored XSS
- CVE-2024-96431 PoCFour-Faith F3x36 Hidden Debug Credentials
- CVE-2024-96451 PoCPost Grid and Gutenberg Blocks < 2.2.93 - Contributor+ Stored XSS
- CVE-2024-96511 PoCContact Form Plugin by Fluent Forms < 5.2.1 - Admin+ Stored XSS
- CVE-2024-96621 PoCCYAN Backup < 2.5.3 - Admin+ Stored XSS via General Settings
- CVE-2024-96631 PoCCYAN Backup < 2.5.3 - Admin+ Stored XSS via Remote Storage Settings
- CVE-2024-96802 PoCsKEVAn attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had…
- CVE-2024-96891 PoCPost From Frontend <= 1.0.0 - Post Deletion via CSRF
- CVE-2024-96981 PoCCrafthemes Demo Import <= 3.3 - Authenticated (Admin+) Arbitrary File Upload in process_uploaded_files
- CVE-2024-97073 PoCsHunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
- CVE-2024-97091 PoCEKC Tournament Manager < 2.2.2 - Create Tournaments/Teams via CSRF
- CVE-2024-97111 PoCEKC Tournament Manager < 2.2.2 - Delete Tournaments via CSRF
- CVE-2024-97561 PoCOrder Attachments for WooCommerce 2.0 - 2.4.1 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary File Upload
- CVE-2024-97652 PoCsEKC Tournament Manager < 2.2.2 - Local File Download Vulnerability
- CVE-2024-97681 PoCFormidable Forms < 6.14.1 - Admin+ Stored XSS
- CVE-2024-97691 PoCVideo Gallery <= 2.4.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
- CVE-2024-97701 PoCWP-Recall < 16.26.12 - Admin+ SQL Injection
- CVE-2024-97711 PoCWP-Recall < 16.26.12 - Admin+ Stored XSS
- CVE-2024-97721 PoCUix Shortcodes – Compatible with Gutenberg <= 1.9.9 - Unauthenticated Arbitrary Shortcode Execution
- CVE-2024-97731 PoCImproper Neutralization of Special Elements used in a Command ('Command Injection') in GitLab
- CVE-2024-97821 PoCD-Link DIR-619L B1 formEasySetupWWConfig buffer overflow
- CVE-2024-97831 PoCD-Link DIR-619L B1 formLogDnsquery buffer overflow
- CVE-2024-97841 PoCD-Link DIR-619L B1 formResetStatistic buffer overflow
- CVE-2024-97851 PoCD-Link DIR-619L B1 formSetDDNS buffer overflow
- CVE-2024-97861 PoCD-Link DIR-619L B1 formSetLog buffer overflow
- CVE-2024-97871 PoCContemporary Control System BASrouter BACnet BASRT-B UDP Packet denial of service
- CVE-2024-97881 PoCLyLme_spage tag.php sql injection
- CVE-2024-97891 PoCLyLme_spage apply.php sql injection
- CVE-2024-97901 PoCLyLme_spage sou.php sql injection
- CVE-2024-97931 PoCTenda AC1206 ate ate_ifconfig_set command injection
- CVE-2024-97941 PoCCodezips Online Shopping Portal update-image1.php unrestricted upload
- CVE-2024-97966 PoCsWP-Advanced-Search < 3.3.9.2 - Unauthenticated SQL Injection
- CVE-2024-97971 PoCcode-projects Blood Bank System register.php sql injection
- CVE-2024-97991 PoCSourceCodester Profile Registration without Reload Refresh add.php cross site scripting
- CVE-2024-98031 PoCcode-projects Blood Bank Management System blooddetails.php cross site scripting
- CVE-2024-98041 PoCcode-projects Blood Bank System campsdetails.php sql injection
- CVE-2024-98051 PoCcode-projects Blood Bank System campsdetails.php cross site scripting
- CVE-2024-98061 PoCCraig Rodway Classroombookings Room Page fields cross site scripting
- CVE-2024-98081 PoCSourceCodester Online Eyewear Shop sql injection
- CVE-2024-98091 PoCSourceCodester Online Eyewear Shop Master.php delete_product sql injection
- CVE-2024-98101 PoCSourceCodester Record Management System sort2_user.php cross site scripting
- CVE-2024-98111 PoCcode-projects Restaurant Reservation System filter3.php sql injection
- CVE-2024-98121 PoCcode-projects Crud Operation System delete.php sql injection
- CVE-2024-98131 PoCCodezips Pharmacy Management System register.php sql injection
- CVE-2024-98141 PoCCodezips Pharmacy Management System update.php sql injection
- CVE-2024-98151 PoCCodezips Tourist Management System create-package.php unrestricted upload
- CVE-2024-98161 PoCCodezips Tourist Management System change-image.php unrestricted upload
- CVE-2024-98171 PoCcode-projects Blood Bank System update.php sql injection
- CVE-2024-98181 PoCSourceCodester Online Veterinary Appointment System manage_category.php sql injection
- CVE-2024-98211 PoCBot for Telegram on WooCommerce <= 1.2.7 - Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication Bypass
- CVE-2024-98221 PoCPedalo Connector <= 2.0.5 - Authentication Bypass to Administrator
- CVE-2024-98281 PoCTaskbuilder < 3.0.5 - Admin+ SQL Injection
- CVE-2024-98311 PoCTaskbuilder < 3.0.9 - Admin+ SQL Injection
- CVE-2024-98351 PoCRSS Feed Widget < 3.0.1 - Reflected XSS
- CVE-2024-98361 PoCRSS Feed Widget < 3.0.0 - Contributor+ Stored XSS
- CVE-2024-98381 PoCAuto Affiliate Links < 6.4.7 - Admin+ SQL Injection
- CVE-2024-98551 PoC07FLYCMS/07FLY-CMS/07FlyCRM Module Plug-In sysmodule_1 uploadFile unrestricted upload
- CVE-2024-98561 PoC07FLYCMS/07FLY-CMS/07FlyCRM System Settings Page cross site scripting
- CVE-2024-98591 PoCType confusion in WebAssembly in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to execute arbitrary code via a crafted…
- CVE-2024-98701 PoCUnintended Proxy or Intermediary ('Confused Deputy') in GitLab
- CVE-2024-98741 PoCWordPress Poll Maker Plugin <= 5.4.6 - Authenticated (Administrator+) Time-Based SQL Injection
- CVE-2024-98781 PoCPhoto Gallery by 10Web <= 1.8.30 - Authenticated (Administrator+) Stored Cross-Site Scripting
- CVE-2024-98791 PoCWebsite File Changes < 2.1.1 - Authenticated SQL Injection
- CVE-2024-98811 PoCLearnPress < 4.2.7.2 - Admin+ Stored XSS
- CVE-2024-98821 PoCSalon Booking System < 10.9.4 - Admin+ Stored XSS
- CVE-2024-98831 PoCPods < 3.2.7.1 - Admin+ Stored XSS
- CVE-2024-98901 PoCUser Toolkit <= 1.2.3 - Authenticated (Subscriber+) Authentication Bypass
- CVE-2024-98941 PoCcode-projects Blood Bank System reset.php sql injection
- CVE-2024-99031 PoC07FLYCMS/07FLY-CMS/07FlyCRM fileUpload unrestricted upload
- CVE-2024-99041 PoC07FLYCMS/07FLY-CMS/07FlyCRM pictureUpload unrestricted upload
- CVE-2024-99051 PoCSourceCodester Online Eyewear Shop sql injection
- CVE-2024-99061 PoCSourceCodester Online Eyewear Shop cross site scripting
- CVE-2024-99071 PoCQileCMS Verification Code Forget.php sendEmail password recovery
- CVE-2024-99081 PoCD-Link DIR-619L B1 formSetMACFilter buffer overflow
- CVE-2024-99091 PoCD-Link DIR-619L B1 formSetMuti buffer overflow
- CVE-2024-99101 PoCD-Link DIR-619L B1 formSetPassword buffer overflow
- CVE-2024-99111 PoCD-Link DIR-619L B1 formSetPortTr buffer overflow
- CVE-2024-99121 PoCD-Link DIR-619L B1 formSetQoS buffer overflow
- CVE-2024-99131 PoCD-Link DIR-619L B1 formSetRoute buffer overflow
- CVE-2024-99141 PoCD-Link DIR-619L B1 formSetWizardSelectMode buffer overflow
- CVE-2024-99151 PoCD-Link DIR-619L B1 formVirtualServ buffer overflow
- CVE-2024-99162 PoCsHuangDou UTCMS cli.php os command injection
- CVE-2024-99171 PoCHuangDou UTCMS template_creat.php deserialization
- CVE-2024-99181 PoCHuangDou UTCMS sql.php RunSql sql injection
- CVE-2024-99263 PoCsJetpack < 13.9.1 - Subscriber+ Arbitrary Feedback Access
- CVE-2024-99323 PoCsWux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
- CVE-2024-99332 PoCsWatchTowerHQ <= 3.10.1 - Authentication Bypass to Administrator due to Missing Empty Value Check
- CVE-2024-99341 PoCWp-ImageZoom <= 1.1.0 - Reflected XSS
- CVE-2024-99354 PoCsPDF Generator Addon for Elementor Page Builder <= 2.0.0 - Unauthenticated Arbitrary File Download
- CVE-2024-99501 PoCAbuse of Unauthenticated Compliance Recheck in SecureConnector
- CVE-2024-99521 PoCSourceCodester Online Eyewear Shop Contact Information Page contact_info cross site scripting
- CVE-2024-99731 PoCSourceCodester Online Eyewear Shop Report Viewing Page page sql injection
- CVE-2024-99741 PoCSourceCodester Online Eyewear Shop POST Request Master.php sql injection
- CVE-2024-99751 PoCSourceCodester Drag and Drop Image Upload upload.php unrestricted upload
- CVE-2024-99761 PoCcode-projects Pharmacy Management System manage_customer.php sql injection
- CVE-2024-99771 PoCMitraStar GPT-2541GNAC Firewall Settings Page settings-firewall.cgi os command injection
- CVE-2024-99861 PoCcode-projects Blood Bank Management System member_register.php sql injection
- CVE-2024-99891 PoCCrypto <= 2.18 - Authentication Bypass via log_in