Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | jsonpath-plus | 0 ~ * | - | |
| - | org.webjars.npm:jsonpath-plus | 0 ~ * | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Proof-of-concept (PoC) exploit for JSONPath-plus vulnerability | https://github.com/pabloopez/CVE-2024-21534 | POC Details |
| 2 | None | https://github.com/XiaomingX/CVE-2024-21534-poc | POC Details |
| 3 | jsonpath-plus 包(版本 <=10.0.7)存在严重的远程代码执行(RCE)漏洞,允许攻击者通过 Node.js 的 VM 模块执行任意代码。该漏洞由于输入验证不严格导致,影响版本为 10.0.7 以下,CVSS 分数为 9.8(极其严重)。漏洞首次公开于 2024 年 10 月 11 日。 | https://github.com/XiaomingX/cve-2024-21534-poc | POC Details |
| 4 | POC - CVE-2024-21534 Jsonpath-plus vulnerable to Remote Code Execution (RCE) due to improper input sanitization | https://github.com/verylazytech/cve-2024-21534 | POC Details |
| 5 | None | https://github.com/BohemianHacks/CVE-2024-21534-poc | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-35517 | 8.4 HIGH | NETGEAR XR1000 安全漏洞 |
| CVE-2024-35522 | 8.4 HIGH | NETGEAR EX3700 安全漏洞 |
| CVE-2024-9855 | 4.7 MEDIUM | 07FLYCMS/07FLY-CMS/07FlyCRM Module Plug-In sysmodule_1 uploadFile unrestricted upload |
| CVE-2024-9856 | 2.4 LOW | 07FLYCMS/07FLY-CMS/07FlyCRM System Settings Page cross site scripting |
| CVE-2024-48788 | Messe Frankfurt com.yescam.YesCam.zwave 安全漏洞 | |
| CVE-2024-42018 | Atos Eviden SMC xScale 安全漏洞 | |
| CVE-2024-48778 | Giant Bicycles RideLink 安全漏洞 | |
| CVE-2024-48937 | Znuny 安全漏洞 | |
| CVE-2024-48776 | Shelly com.home.shelly 安全漏洞 | |
| CVE-2024-48787 | Revic Optics Revic Ops 安全漏洞 | |
| CVE-2024-48769 | BURG-WCHTER KG de.burgwachter.keyapp.app 安全漏洞 | |
| CVE-2024-48771 | Almando Play 安全漏洞 | |
| CVE-2024-48775 | Plug n Play Camera com.ezset.delaney 安全漏洞 | |
| CVE-2024-48774 | Fermax com.fermax.vida 安全漏洞 | |
| CVE-2024-48786 | SwitchBot 安全漏洞 | |
| CVE-2024-48784 | SAMPMAX com.sampmax.homemax 安全漏洞 | |
| CVE-2024-48938 | Znuny 安全漏洞 | |
| CVE-2024-48772 | C-CHIP 安全漏洞 | |
| CVE-2024-48773 | Wo-smart WoFit 安全漏洞 | |
| CVE-2024-46468 | Jpress 安全漏洞 |
Showing top 20 of 41 CVEs. View all on vendor page → →
No comments yet