CVE-2023-0 to CVE-2023-999
460 CVEs with public proof-of-concept exploits.
- CVE-2023-00281 PoCCross-site Scripting (XSS) - Stored in linagora/twake
- CVE-2023-00331 PoCPDF Viewer < 1.0.0 - Contributor+ Stored XSS via Shortcode
- CVE-2023-00341 PoCJetWidgets For Elementor < 1.0.14 - Contributor+ Stored XSS via Shortcode
- CVE-2023-00372 PoCs10WebMapBuilder < 1.0.73 - Unauthenticated SQLi
- CVE-2023-00431 PoCCustom Add User <= 2.0.2 - Reflected Cross-Site Scripting
- CVE-2023-00453 PoCsIncorrect indirect branch prediction barrier in the Linux Kernel
- CVE-2023-00461 PoCImproper Restriction of Names for Files and Other Resources in lirantal/daloradius
- CVE-2023-00481 PoCCode Injection in lirantal/daloradius
- CVE-2023-00491 PoCOut-of-bounds Read in vim/vim
- CVE-2023-00511 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2023-00541 PoCOut-of-bounds Write in vim/vim
- CVE-2023-00551 PoCSensitive Cookie in HTTPS Session Without 'Secure' Attribute in pyload/pyload
- CVE-2023-00581 PoCTiempo.com <= 0.1.2 - Stored XSS via CSRF
- CVE-2023-00591 PoCYouzify < 1.2.2 - Contributor+ Stored XSS
- CVE-2023-00601 PoCResponsive Gallery Grid < 2.3.9 - Contributor+ Stored XSS
- CVE-2023-00611 PoCJudge.me Product Reviews for WooCommerce < 1.3.21 - Contributor+ Stored XSS
- CVE-2023-00621 PoCEAN for WooCommerce < 4.4.3 - Contributor+ Stored XSS
- CVE-2023-00631 PoCSynved Shortcodes <= 1.6.36 - Contributor+ Stored XSS
- CVE-2023-00641 PoCeVision Responsive Column Layout Shortcodes <= 2.3 - Contributor+ Stored XSS
- CVE-2023-00651 PoCi2 Pros & Cons <= 1.3.1 - Contributor+ Stored XSS
- CVE-2023-00661 PoCCompanion Sitemap Generator <= 4.5.1.1 - Contributor+ Stored XSS
- CVE-2023-00671 PoCTimed Content < 2.73 - Contributor+ Stored XSS
- CVE-2023-00681 PoCProduct GTIN (EAN, UPC, ISBN) for WooCommerce <= 1.1.1 - Contributor+ Stored XSS
- CVE-2023-00691 PoCWPaudio MP3 Player <= 4.0.2 - Contributor+ Stored XSS
- CVE-2023-00701 PoCResponsiveVoice Text To Speech < 1.7.7 - Contributor+ Stored XSS
- CVE-2023-00711 PoCWP Tabs < 2.1.17 - Contributor+ Stored XSS
- CVE-2023-00721 PoCWC Vendors Marketplace < 2.4.5 - Contributor+ Stored XSS
- CVE-2023-00731 PoCClient Logo Carousel <= 3.0.0 - Contributor+ Stored XSS
- CVE-2023-00741 PoCWP Social Widget < 2.2.4 - Contributor+ Stored XSS
- CVE-2023-00751 PoCAmazon JS <= 0.10 - Contributor+ Stored XSS
- CVE-2023-00761 PoCDownload Attachments < 1.3 - Contributor+ Stored XSS
- CVE-2023-00781 PoCResume Builder <= 3.1.1 - Subscriber+ Stored XSS
- CVE-2023-00791 PoCCustomer Reviews for WooCommerce < 5.17.0 - Contributor+ Stored XSS
- CVE-2023-00801 PoCCustomer Reviews for WooCommerce < 5.16.0 - Contributor+ LFI
- CVE-2023-00811 PoCMonsterInsights < 8.12.1 - Contributor+ Stored XSS
- CVE-2023-00821 PoCExactMetrics < 7.12.1 - Contributor+ Stored XSS
- CVE-2023-00841 PoCMetform Elementor Contact Form Builder <= 3.1.2 - Unauthenticated Stored Cross-Site Scripting
- CVE-2023-00941 PoCUpQode Google Maps <= 1.0.5 - Contributor+ Stored XSS
- CVE-2023-00951 PoCPage View Count < 2.6.1 - Contributor+ Stored XSS
- CVE-2023-00961 PoCHappyforms < 1.22.0 - Contributor+ Stored XSS
- CVE-2023-00971 PoCPost Grid, Post Carousel, & List Category Posts < 2.4.19 - Contributor+ Stored XSS
- CVE-2023-00981 PoCSimple URLs < 115 - Subscriber+ SQLi
- CVE-2023-00993 PoCsSimple URLs < 115 - Multiple Reflected XSS
- CVE-2023-01061 PoCCross-site Scripting (XSS) - Stored in usememos/memos
- CVE-2023-01071 PoCCross-site Scripting (XSS) - Stored in usememos/memos
- CVE-2023-01081 PoCCross-site Scripting (XSS) - Stored in usememos/memos
- CVE-2023-01101 PoCCross-site Scripting (XSS) - Stored in usememos/memos
- CVE-2023-01111 PoCCross-site Scripting (XSS) - Stored in usememos/memos
- CVE-2023-01121 PoCCross-site Scripting (XSS) - Stored in usememos/memos
- CVE-2023-01201 PoCIncorrect Authorization in GitLab
- CVE-2023-01251 PoCControl iD Gerencia Web Web Interface cross site scripting
- CVE-2023-01262 PoCsPre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access…
- CVE-2023-01431 PoCSend PDF for Contact Form 7 < 0.9.9.2 - Contributor+ Stored XSS via Shortcode
- CVE-2023-01441 PoCEvent Manager and Tickets Selling Plugin for WooCommerce < 3.8.0 - Contributor+ Stored XSS
- CVE-2023-01451 PoCSaan World Clock <= 1.8 - Contributor+ Stored XSS
- CVE-2023-01461 PoCNaver Map <= 1.1.0 - Contributor+ Stored XSS
- CVE-2023-01471 PoCFlexible Captcha <= 4.1 - Contributor+ Stored XSS
- CVE-2023-01481 PoCGallery Factory Lite <= 2.0.0 - Contributor+ Stored XSS
- CVE-2023-01491 PoCWordPrezi < 0.9 - Contributor+ Strored XSS
- CVE-2023-01501 PoCCloak Front End Email < 1.9.2 - Contributor+ Stored XSS
- CVE-2023-01511 PoCuTubeVideo Gallery < 2.0.8 - Contributor+ Stored XSS
- CVE-2023-01521 PoCWP Multi Store Locator <= 2.4 - Contributor+ Stored XSS
- CVE-2023-01531 PoCVimeo Video Autoplay Automute <= 1.0 - Contributor+ Stored XSS
- CVE-2023-01541 PoCGamiPress – Vimeo integration < 1.0.9 - Contributor+ Stored XSS
- CVE-2023-01551 PoCAn issue has been discovered in GitLab CE/EE affecting all versions before 15.8.5, 15.9.4, 15.10.1. Open redirects was possible due to…
- CVE-2023-01562 PoCsAll-In-One Security (AIOS) < 5.1.5 - Admin+ Arbitrary File/Folder Access via Traversal
- CVE-2023-01572 PoCsAll-In-One Security (AIOS) < 5.1.5 - Admin+ Stored XSS
- CVE-2023-01593 PoCsExtensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE
- CVE-2023-01601 PoCPossibility of deadlock in libbpf function sock_hash_delete_elem
- CVE-2023-01631 PoCPrototype Pollution in convict
- CVE-2023-01641 PoCOrangeScrum version 2.0.11 allows an authenticated external attacker to execute arbitrary commands on the server. This is possible because…
- CVE-2023-01651 PoCCost Calculator <= 1.8 - Contributor+ Stored XSS
- CVE-2023-01661 PoCPickPlugins Product Slider for WooCommerce < 1.13.42 - Contributor+ Stored XSS
- CVE-2023-01671 PoCGetResponse for WordPress <= 5.5.31 - Contributor+ Stored XSS
- CVE-2023-01681 PoCOlevmedia Shortcodes <= 1.1.9 - Contributor+ Stored XSS
- CVE-2023-01691 PoCZoho Forms < 3.0.1 - Contributor+ Stored XSS
- CVE-2023-01701 PoCHtml5 Audio Player < 2.1.12 - Contributor+ Stored XSS
- CVE-2023-01711 PoCjQuery T(-) Countdown Widget < 2.3.24 - Contributor+ Stored XSS
- CVE-2023-01721 PoCJuicer < 1.11 - Contributor+ Stored XSS
- CVE-2023-01731 PoCWPFunnels < 2.6.9 - Contributor+ Stored XSS
- CVE-2023-01741 PoCWP VR < 8.2.7 - Contributor+ Stored XSS
- CVE-2023-01751 PoCSmart Logo Showcase Lite <= 1.1.9 - Contributor+ Stored XSS
- CVE-2023-01761 PoCGiveaways and Contests by RafflePress < 1.11.3 - Contributor+ Stored XSS
- CVE-2023-01771 PoCSocial Like Box and Page by WpDevArt < 0.8.41 - Contributor+ Stored XSS
- CVE-2023-01781 PoCAnnual Archive < 1.6.0 - Contributor+ Stored XSS
- CVE-2023-01795 PoCsA buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack…
- CVE-2023-02102 PoCsA bug affects the Linux kernel’s ksmbd NTLMv2 authentication and is known to crash the OS immediately in Linux-based systems.
- CVE-2023-02121 PoCAdvanced Recent Posts <= 0.6.14 - Contributor+ Stored XSS
- CVE-2023-02142 PoCsXSS in Skyhigh Security SWG
- CVE-2023-02191 PoCFluentSMTP < 2.2.3 - Stored XSS via Email Logs
- CVE-2023-02201 PoCPinpoint Booking System < 2.9.9.2.9 - Subscriber+ SQLi
- CVE-2023-02241 PoCGiveWP < 2.24.1 - Unauthenticated SQLi
- CVE-2023-02271 PoCInsufficient Session Expiration in pyload/pyload
- CVE-2023-02301 PoCVK All in One Expansion Unit < 9.86.0.0 - Contributor+ Stored XSS
- CVE-2023-02311 PoCShopLentor < 2.5.4 - Contributor+ Stored XSS
- CVE-2023-02321 PoCShopLentor < 2.5.4 - PHP Object Injection
- CVE-2023-02331 PoCActiveCampaign < 8.1.12 - Contributor+ Stored XSS
- CVE-2023-02341 PoCSiteGround Security < 1.3.1 - Admin+ SQLi
- CVE-2023-02362 PoCsTutor LMS < 2.0.10 - Reflected Cross-Site Scripting
- CVE-2023-02431 PoCTuziCMS Article Module ArticleController.class.php index sql injection
- CVE-2023-02441 PoCTuziCMS KefuController.class.php delall sql injection
- CVE-2023-02451 PoCSourceCodester Online Flight Booking Management System add_contestant.php sql injection
- CVE-2023-02461 PoCearclink ESPCMS Content cross site scripting
- CVE-2023-02471 PoCUncontrolled Search Path Element in bits-and-blooms/bloom
- CVE-2023-02521 PoCContextual Related Posts < 3.3.1 - Contributor+ Stored XSS
- CVE-2023-02551 PoCEnable Media Replace < 4.0.2 - Author+ Arbitrary File Upload
- CVE-2023-02591 PoCWP Google Review Slider < 11.8 - Subscriber+ SQLi
- CVE-2023-02601 PoCWP Review Slider < 12.2 - Subscriber+ SQLi
- CVE-2023-02612 PoCsWP TripAdvisor Review Slider < 10.8 - Subscriber+ SQLi
- CVE-2023-02621 PoCWP Airbnb Review Slider < 3.3 - Subscriber+ SQLi
- CVE-2023-02631 PoCWP Yelp Review Slider < 7.1 - Subscriber+ SQLi
- CVE-2023-02641 PoCA flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker…
- CVE-2023-02661 PoCKEVUse after free in SNDRV_CTL_IOCTL_ELEM in Linux Kernel
- CVE-2023-02671 PoCUltimate Carousel For WPBakery Page Builder <= 2.6 - Contributor+ Stored XSS
- CVE-2023-02681 PoCMega Addons For WPBakery Page Builder < 4.3.0 - Contributor+ Stored XSS
- CVE-2023-02701 PoCYaMaps for WordPress Plugin < 0.6.26 - Contributor+ Stored XSS
- CVE-2023-02711 PoCWP Font Awesome < 1.7.9 - Contributor+ Stored XSS
- CVE-2023-02721 PoCNEX-Forms < 8.3.3 - Contributor+ Stored XSS
- CVE-2023-02731 PoCCustom Content Shortcode <= 4.0.2 - Contributor+ Stored XSS
- CVE-2023-02741 PoCURL Params < 2.5 - Contributor+ Stored XSS
- CVE-2023-02751 PoCEasy Accept Payments for PayPal < 4.9.10 - Contributor+ Stored XSS
- CVE-2023-02761 PoCWeaver Xtreme Theme Support < 6.2.7 - Contributor+ Stored XSS
- CVE-2023-02771 PoCWC Fields Factory <= 4.1.5 - ShopManager+ SQLi
- CVE-2023-02781 PoCGeoDirectory < 2.2.24 - Admin+ SQLi
- CVE-2023-02791 PoCMedia Library Assistant < 3.06 - Admin+ SQLi
- CVE-2023-02801 PoCUltimate Carousel For Elementor <= 2.1.7 - Contributor+ Stored XSS
- CVE-2023-02811 PoCSourceCodester Online Flight Booking Management System judge_panel.php sql injection
- CVE-2023-02821 PoCYourChannel < 1.2.2 - Subscriber+ Stored XSS
- CVE-2023-02831 PoCSourceCodester Online Flight Booking Management System POST Parameter review_search.php sql injection
- CVE-2023-02851 PoCReal Media Library < 4.18.29 - Author+ Stored XSS
- CVE-2023-02871 PoCityouknow favorites-web Comment cross site scripting
- CVE-2023-02881 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2023-02891 PoCCross-site Scripting (XSS) - Stored in craigk5n/webcalendar
- CVE-2023-02921 PoCQuiz And Survey Master <= 8.0.8 - Cross-Site Request Forgery to Arbitrary Media Deletion
- CVE-2023-029711 PoCsCode Injection in pyload/pyload
- CVE-2023-02981 PoCIncorrect Authorization in firefly-iii/firefly-iii
- CVE-2023-02991 PoCImproper Input Validation in publify/publify
- CVE-2023-03001 PoCCross-site Scripting (XSS) - Reflected in alfio-event/alf.io
- CVE-2023-03011 PoCCross-site Scripting (XSS) - Stored in alfio-event/alf.io
- CVE-2023-03021 PoCFailure to Sanitize Special Elements into a Different Plane (Special Element Injection) in radareorg/radare2
- CVE-2023-03031 PoCSourceCodester Online Food Ordering System view_prod.php sql injection
- CVE-2023-03041 PoCSourceCodester Online Food Ordering System Signup Module admin_class.php sql injection
- CVE-2023-03051 PoCSourceCodester Online Food Ordering System Login Module admin_class.php sql injection
- CVE-2023-03154 PoCsCommand Injection in froxlor/froxlor
- CVE-2023-03161 PoCPath Traversal: '\..\filename' in froxlor/froxlor
- CVE-2023-03211 PoCDisclosure of Sensitive Information on Campbell Scientific Products
- CVE-2023-03231 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2023-03241 PoCSourceCodester Online Tours & Travels Management System page-login.php sql injection
- CVE-2023-03261 PoCAn issue has been discovered in GitLab DAST API scanner affecting all versions starting from 1.6.50 before 2.11.0, where Authorization…
- CVE-2023-03281 PoCWPCode < 2.0.7 - Contributor+ WPCode Library Auth Key Update/Deletion
- CVE-2023-03291 PoCElementor Website Builder < 3.12.2 - Admin+ SQLi
- CVE-2023-03311 PoCCorreos Oficial <= 1.2.0.2 - Unauthenticated Arbitrary File Download
- CVE-2023-03321 PoCSourceCodester Online Food Ordering System manage_user.php sql injection
- CVE-2023-03331 PoCTemplatesNext ToolKit < 3.2.9 - Contributor+ Stored XSS
- CVE-2023-03342 PoCsShortPixel Adaptive Images < 3.6.3 - Reflected XSS
- CVE-2023-03351 PoCWP Shamsi <= 4.3.3 - Subscriber+ Attachment Deletion
- CVE-2023-03361 PoCOoohBoi Steroids for Elementor < 2.1.5 - Subscriber+ Attachment Deletion
- CVE-2023-03401 PoCCustom Content Shortcode <= 4.0.2 - Contributor+ LFI
- CVE-2023-03411 PoCStack Buffer Overflow in editorconfig-core-c
- CVE-2023-03421 PoCMongoDB Ops Manager may disclose sensitive information in Diagnostic Archive
- CVE-2023-03581 PoCUse After Free in gpac/gpac
- CVE-2023-03601 PoCLocation Weather < 1.3.4 - Contributor+ Stored XSS
- CVE-2023-03621 PoCThemify Portfolio Post < 1.2.2 - Contributor+ Stored XSS
- CVE-2023-03631 PoCScheduled Announcements Widget < 1.0 - Contributor+ Stored XSS
- CVE-2023-03641 PoCreal.Kit < 5.1.1 - Contributor+ Stored XSS
- CVE-2023-03651 PoCReact Webcam <= 1.2.0 - Contributor+ Stored XSS
- CVE-2023-03661 PoCLoan Comparison < 1.5.3 - Contributor+ Stored XSS via shortcode
- CVE-2023-03671 PoCPricing Tables For WPBakery Page Builder < 3.0 - Contributor+ Stored XSS
- CVE-2023-03681 PoCResponsive Tabs For WPBakery Page Builder <= 1.1 - Contributor+ Stored XSS
- CVE-2023-03691 PoCGoToWP <= 5.1.1 - Contributor+ Stored XSS
- CVE-2023-03701 PoCWPB Advanced FAQ <= 1.0.6 - Contributor+ Stored XSS
- CVE-2023-03711 PoCEmbedSocial < 1.1.28 - Contributor+ Stored XSS
- CVE-2023-03721 PoCEmbedStories < 0.7.5 - Contributor+ Stored XSS
- CVE-2023-03731 PoCLightweight Accordion < 1.5.15 - Contributor+ Stored XSS
- CVE-2023-03741 PoCW4 Post List < 2.4.6 - Contributor+ Stored XSS
- CVE-2023-03751 PoCEasy Affiliate Links < 3.7.1 - Contributor+ Stored XSS
- CVE-2023-03761 PoCQubely < 1.8.5 - Contributor+ Stored XSS
- CVE-2023-03771 PoCScriptless Social Sharing < 3.2.2 - Contributor+ Stored XSS
- CVE-2023-03781 PoCGreenshift < 5.0 - Contributor+ Stored XSS
- CVE-2023-03791 PoCSpotlight Social Feeds < 1.4.3 - Contributor+ Stored XSS
- CVE-2023-03801 PoCEasy Digital Downloads < 3.1.0.5 - Contributor+ Stored XSS
- CVE-2023-03811 PoCGigPress <= 2.3.28 - Subscriber+ SQLi
- CVE-2023-038627 PoCsKEVA flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the…
- CVE-2023-03881 PoCRandom Text <= 0.3.0 - Subscriber+ SQLi
- CVE-2023-03891 PoCCalculated Fields Form < 1.1.151 - Admin+ Stored Cross-Site Scripting via Dropdown Fields
- CVE-2023-03911 PoCMGT-COMMERCE CloudPanel Shared Certificate
- CVE-2023-03951 PoCmenu shortcode <= 1.0 - Contributor+ Stored XSS via Shortcode
- CVE-2023-03981 PoCCross-Site Request Forgery (CSRF) in modoboa/modoboa
- CVE-2023-03991 PoCImage Over Image For WPBakery Page Builder < 3.0 - Contributor+ Stored XSS
- CVE-2023-04001 PoCThe protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP…
- CVE-2023-04051 PoCGPT3 AI Content Writer < 1.4.38 - Subscriber+ Arbitrary Post Content Update
- CVE-2023-04061 PoCCross-Site Request Forgery (CSRF) in modoboa/modoboa
- CVE-2023-04181 PoCVideo Central for WordPress <= 1.3.0 - Contributor+ Stored XSS
- CVE-2023-04191 PoCShortcode for Font Awesome < 1.4.1 - Contributor+ Stored XSS
- CVE-2023-04201 PoCCustom Post Type and Taxonomy GUI Manager <= 1.1 - Stored XSS via CSRF
- CVE-2023-04211 PoCCloud Manager <= 1.0 - Reflected XSS
- CVE-2023-04221 PoCArticle Directory <= 1.3 - Admin+ Stored XSS
- CVE-2023-04231 PoCWordPress Amazon S3 Plugin < 1.6 - Reflected XSS
- CVE-2023-04241 PoCMS-Reviews <= 1.5 - Subscriber+ Stored XSS
- CVE-2023-04281 PoCWatu Quiz < 3.3.8.2 - Reflected XSS
- CVE-2023-04291 PoCWatu Quiz < 3.3.8.3 - Admin+ Stored XSS
- CVE-2023-04311 PoCFile Away <= 3.9.9.0.1 - Contributor+ Stored XSS via Shortcode
- CVE-2023-04331 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2023-04341 PoCImproper Input Validation in pyload/pyload
- CVE-2023-04351 PoCExcessive Attack Surface in pyload/pyload
- CVE-2023-04381 PoCCross-Site Request Forgery (CSRF) in modoboa/modoboa
- CVE-2023-04391 PoCNEX-Forms < 8.4.4 - Authenticated Stored XSS
- CVE-2023-04401 PoCObservable Discrepancy in healthchecks/healthchecks
- CVE-2023-04411 PoCGallery Blocks with Lightbox < 3.0.8 - Subscriber+ Arbitrary Options Update
- CVE-2023-04421 PoCLoan Comparison < 1.5.2 - Reflected XSS via shortcode
- CVE-2023-04431 PoCAnyWhere Elementor < 1.2.8 - Freemius API Key Disclosure
- CVE-2023-04482 PoCsThe WP Helper Lite WordPress plugin, in versions < 4.3, returns all GET parameters unsanitized in the response, resulting in a reflected…
- CVE-2023-04531 PoCWP Private Message < 1.0.6 - Private Message Disclosure via IDOR
- CVE-2023-04552 PoCsUnrestricted Upload of File with Dangerous Type in unilogies/bumsys
- CVE-2023-04611 PoCUse-after-free vulnerability in the Linux Kernel
- CVE-2023-04641 PoCExcessive Resource Usage Verifying X.509 Policy Constraints
- CVE-2023-04671 PoCWP Dark Mode < 4.0.8 - Subscriber+ Local File Inclusion
- CVE-2023-04701 PoCCross-site Scripting (XSS) - Stored in modoboa/modoboa
- CVE-2023-04771 PoCAuto Featured Image < 3.9.16 - Author+ Arbitrary File Upload
- CVE-2023-04791 PoCPrint Invoice & Delivery Notes for WooCommerce < 4.7.2 - Reflected XSS
- CVE-2023-04841 PoCContact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks < 1.1.6 - Arbitrary Plugin Activation via CSRF
- CVE-2023-04871 PoCMy Sticky Elements < 2.0.9 - Admin+ SQLi
- CVE-2023-04881 PoCCross-site Scripting (XSS) - Stored in pyload/pyload
- CVE-2023-04891 PoCSlideOnline <= 1.2.1 - Contributor+ Stored XSS
- CVE-2023-04901 PoCf(x) TOC <= 1.1.0 - Contributor+ Stored XSS
- CVE-2023-04911 PoCSchedulicity - Easy Online Scheduling <= 2.21 - Contributor+ Stored XSS
- CVE-2023-04921 PoCGS Products Slider for WooCommerce < 1.5.9 - Contributor+ Stored XSS
- CVE-2023-04932 PoCsImproper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserver
- CVE-2023-04951 PoCHT Slider For Elementor < 1.4.0 - Arbitrary Plugin Activation via CSRF
- CVE-2023-04961 PoCHT Event < 1.4.6 - Arbitrary Plugin Activation via CSRF
- CVE-2023-04971 PoCHT Portfolio < 1.1.6 - Arbitrary Plugin Activation via CSRF
- CVE-2023-04981 PoCWP Education < 1.2.7 - Arbitrary Plugin Activation via CSRF
- CVE-2023-04991 PoCQuickSwish < 1.1.0 - Arbitrary Plugin Activation via CSRF
- CVE-2023-05001 PoCWP Film Studio < 1.3.5 - Arbitrary Plugin Activation via CSRF
- CVE-2023-05011 PoCWP Insurance < 2.1.4 - Arbitrary Plugin Activation via CSRF
- CVE-2023-05021 PoCWP News <= 1.1.9 - Arbitrary Plugin Activation via CSRF
- CVE-2023-05031 PoCFree WooCommerce Theme 99fy Extension < 1.2.8 - Arbitrary Plugin Activation via CSRF
- CVE-2023-05041 PoCHT Politic < 2.3.8 - Arbitrary Plugin Activation via CSRF
- CVE-2023-05051 PoCEver Compare <= 1.2.3 - Arbitrary Plugin Activation via CSRF
- CVE-2023-05091 PoCImproper Certificate Validation in pyload/pyload
- CVE-2023-05121 PoCDivide By Zero in vim/vim
- CVE-2023-05131 PoCisoftforce Dreamer CMS cross site scripting
- CVE-2023-05142 PoCsMembership Database <= 1.0 - Reflected XSS
- CVE-2023-05151 PoCSourceCodester Online Tours & Travels Management System Parameter forget_password.php sql injection
- CVE-2023-05161 PoCSourceCodester Online Tours & Travels Management System Parameter forget_password.php sql injection
- CVE-2023-05191 PoCCross-site Scripting (XSS) - Stored in modoboa/modoboa
- CVE-2023-05201 PoCRapidExpCart <= 1.0 - Stored XSS via CSRF
- CVE-2023-05221 PoCEnable/Disable Auto Login when Register <= 1.1.0 - Settings Update via CSRF
- CVE-2023-05261 PoCPost Shortcode <= 2.0.9 - Contributor+ Stored Cross-Site Scripting
- CVE-2023-05273 PoCsPHPGurukul Online Security Guards Hiring System search-request.php cross site scripting
- CVE-2023-05281 PoCSourceCodester Online Tours & Travels Management System abc.php sql injection
- CVE-2023-05291 PoCSourceCodester Online Tours & Travels Management System add_payment.php sql injection
- CVE-2023-05301 PoCSourceCodester Online Tours & Travels Management System approve_user.php sql injection
- CVE-2023-05311 PoCSourceCodester Online Tours & Travels Management System booking_report.php sql injection
- CVE-2023-05321 PoCSourceCodester Online Tours & Travels Management System disapprove_user.php sql injection
- CVE-2023-05331 PoCSourceCodester Online Tours & Travels Management System expense_report.php sql injection
- CVE-2023-05341 PoCSourceCodester Online Tours & Travels Management System expense_report.php sql injection
- CVE-2023-05351 PoCDonation Block For PayPal < 2.1.0 - Contributor+ Stored XSS
- CVE-2023-05361 PoCWp-D3 <= 2.4.1 - Contributor+ Stored XSS
- CVE-2023-05371 PoCProduct Slider For WooCommerce Lite <= 1.1.7 - Contributor+ Stored XSS
- CVE-2023-05381 PoCCampaign URL Builder < 1.8.2 - Contributor+ Stored XSS
- CVE-2023-05391 PoCGS Insever Portfolio < 1.4.5 - Contributor+ Stored XSS
- CVE-2023-05401 PoCGS Filterable Portfolio < 1.6.1 - Contributor+ Stored XSS
- CVE-2023-05411 PoCGS Books Showcase < 1.3.1 - Contributor+ Stored XSS
- CVE-2023-05421 PoCCustom Post Type List Shortcode <= 1.4.4 - Contributor+ Stored XSS
- CVE-2023-05431 PoCArigato Autoresponder and Newsletter < 2.1.7.2 - Admin+ Stored XSS
- CVE-2023-05441 PoCWP Login Box <= 2.0.2 - Admin+ Stored XSS
- CVE-2023-05451 PoCHostel < 1.1.5.2 - Admin+ Stored XSS
- CVE-2023-05461 PoCFluentForms < 4.3.25 - Contributor+ Stored XSS via Custom HTML Form Field
- CVE-2023-05481 PoCNamaste! LMS < 2.5.9.4 - Admin+ Stored XSS
- CVE-2023-05492 PoCsYAFNET Private Message PostPrivateMessage cross site scripting
- CVE-2023-05511 PoCREST API TO MiniProgram <= 4.6.1 - Subscriber+ Attachment Deletion
- CVE-2023-05522 PoCsPie Register < 3.8.2.3 - Open Redirect
- CVE-2023-05591 PoCGS Portfolio for Envato < 1.4.0 - Contributor+ Stored XSS
- CVE-2023-05601 PoCSourceCodester Online Tours & Travels Management System practice_pdf.php sql injection
- CVE-2023-05611 PoCSourceCodester Online Tours & Travels Management System s.php sql injection
- CVE-2023-05622 PoCsPHPGurukul Bank Locker Management System Login index.php sql injection
- CVE-2023-05632 PoCsPHPGurukul Bank Locker Management System Assign Locker add-locker-form.php cross site scripting
- CVE-2023-05671 PoCpassword_verify() always returns true for some invalid hashes
- CVE-2023-05701 PoCSourceCodester Online Tours & Travels Management System payment_operation.php sql injection
- CVE-2023-05711 PoCSourceCodester Canteen Management System Add Customer createcustomer.php cross site scripting
- CVE-2023-05791 PoCYARPP - Yet Another Related Posts Plugin < 5.30.3 - Subscriber+ SQLi
- CVE-2023-05881 PoCCatalyst Connect Zoho CRM Client Portal < 2.1.0 - Reflected XSS
- CVE-2023-05891 PoCWP Image Carousel <= 1.0.2 - Contributor+ Stored XSS
- CVE-2023-05911 PoCPath Traversal in ubi_reader
- CVE-2023-05921 PoCPath traversal in jefferson
- CVE-2023-05931 PoCPath traversal in yaffshiv
- CVE-2023-06002 PoCsWP Visitor Statistics (Real Time Traffic) < 6.9 - Unauthenticated SQLi
- CVE-2023-06022 PoCsTwittee Text Tweet <= 1.0.8 - Reflected XSS
- CVE-2023-06031 PoCSloth Logo Customizer <= 2.0.2 - Stored XSS via CSRF
- CVE-2023-06041 PoCWP Food Manager < 1.0.4 - Admin+ Stored XSS
- CVE-2023-06051 PoCAuto Rename Media On Upload < 1.1.0 - Admin+ Stored XSS
- CVE-2023-06061 PoCCross-site Scripting (XSS) - Reflected in ampache/ampache
- CVE-2023-06081 PoCCross-site Scripting (XSS) - DOM in microweber/microweber
- CVE-2023-06091 PoCImproper Authorization in wallabag/wallabag
- CVE-2023-06101 PoCImproper Authorization in wallabag/wallabag
- CVE-2023-06111 PoCTRENDnet TEW-652BRP Web Management Interface get_set.ccp command injection
- CVE-2023-06121 PoCTRENDnet TEW-811DRU httpd basic.asp buffer overflow
- CVE-2023-06131 PoCTRENDnet TEW-811DRU httpd security.asp memory corruption
- CVE-2023-06171 PoCTRENDNet TEW-811DRU httpd guestnetwork.asp buffer overflow
- CVE-2023-06181 PoCTRENDnet TEW-652BRP Web Service cfg_op.ccp memory corruption
- CVE-2023-06292 PoCsDocker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation restrictions via the raw Docker socket and…
- CVE-2023-06303 PoCsSlimstat Analytics < 4.9.3.3 - Subscriber+ SQL Injection
- CVE-2023-06311 PoCPaid Memberships Pro < 2.9.12 - Subscriber+ SQL Injection
- CVE-2023-06321 PoCInefficient Regular Expression Complexity in GitLab
- CVE-2023-06371 PoCTRENDnet TEW-811DRU Web Management Interface wan.asp memory corruption
- CVE-2023-06381 PoCTRENDnet TEW-811DRU Web Interface command injection
- CVE-2023-06401 PoCTRENDnet TEW-652BRP Web Interface ping.ccp command injection
- CVE-2023-06411 PoCPHPGurukul Employee Leaves Management System changepassword.php weak password
- CVE-2023-06421 PoCCross-Site Request Forgery (CSRF) in squidex/squidex
- CVE-2023-06431 PoCImproper Handling of Additional Special Element in squidex/squidex
- CVE-2023-06441 PoCPushAssist <= 3.0.8 - Reflected Cross-Site Scripting
- CVE-2023-06461 PoCdst-admin cavesConsole command injection
- CVE-2023-06471 PoCdst-admin kickPlayer command injection
- CVE-2023-06481 PoCdst-admin masterConsole command injection
- CVE-2023-06491 PoCdst-admin sendBroadcast command injection
- CVE-2023-06502 PoCsYAFNET Signature cross site scripting
- CVE-2023-06511 PoCFastCMS Template Management unrestricted upload
- CVE-2023-06561 PoCA Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS),…
- CVE-2023-06601 PoCSmart Slider 3 < 3.5.1.14 - Contributor+ Stored XSS
- CVE-2023-06631 PoCCalendar Event Management System Login Page sql injection
- CVE-2023-06661 PoCWireshark RTPS Parsing Buffer Overflow
- CVE-2023-06672 PoCsWireshark MSMMS parsing buffer overflow
- CVE-2023-06681 PoCWireshark IEEE-C37.118 parsing buffer overflow
- CVE-2023-066912 PoCsKEVFortra GoAnywhere MFT License Response Servlet Command Injection
- CVE-2023-06711 PoCCode Injection in froxlor/froxlor
- CVE-2023-06741 PoCXXL-JOB New Password updatePwd cross-site request forgery
- CVE-2023-06751 PoCCalendar Event Management System sql injection
- CVE-2023-06762 PoCsCross-site Scripting (XSS) - Reflected in phpipam/phpipam
- CVE-2023-06771 PoCCross-site Scripting (XSS) - Reflected in phpipam/phpipam
- CVE-2023-06781 PoCMissing Authorization in phpipam/phpipam
- CVE-2023-06791 PoCSourceCodester Canteen Management System removeUser.php sql injection
- CVE-2023-07331 PoCNewsletter Popup <= 1.2 - Unauthenticated Stored XSS
- CVE-2023-07341 PoCImproper Authorization in wallabag/wallabag
- CVE-2023-07361 PoCCross-site Scripting (XSS) - Stored in wallabag/wallabag
- CVE-2023-07381 PoCOrangeScrum version 2.0.11 allows an external attacker to obtain arbitrary user accounts from the application. This is possible because…
- CVE-2023-07391 PoCConcurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in answerdev/answer
- CVE-2023-07401 PoCCross-site Scripting (XSS) - Stored in answerdev/answer
- CVE-2023-07411 PoCCross-site Scripting (XSS) - DOM in answerdev/answer
- CVE-2023-07421 PoCCross-site Scripting (XSS) - Stored in answerdev/answer
- CVE-2023-07431 PoCCross-site Scripting (XSS) - Generic in answerdev/answer
- CVE-2023-07442 PoCsImproper Access Control in answerdev/answer
- CVE-2023-07471 PoCCross-site Scripting (XSS) - Stored in btcpayserver/btcpayserver
- CVE-2023-07482 PoCsOpen Redirect in btcpayserver/btcpayserver
- CVE-2023-07491 PoCOcean Extra < 2.1.3 - Subscriber+ Arbitrary Post Content Disclosure
- CVE-2023-07581 PoCglorylion JFinalOA SysOrg.java sql injection
- CVE-2023-07591 PoCPrivilege Chaining in cockpit-hq/cockpit
- CVE-2023-07601 PoCHeap-based Buffer Overflow in gpac/gpac
- CVE-2023-07611 PoCClock In Portal <= 2.1 - Staff Deletion via CSRF
- CVE-2023-07621 PoCClock In Portal <= 2.1 - Designation Deletion via CSRF
- CVE-2023-07631 PoCClock In Portal <= 2.1 - Holidays Deletion via CSRF
- CVE-2023-07641 PoCGallery by BestWebSoft < 4.7.0 - Author+ Stored Cross-Site Scripting
- CVE-2023-07651 PoCGallery by BestWebSoft < 4.7.0 - Author+ SQL Injection
- CVE-2023-07661 PoCNewsletter Popup <= 1.2 - Record Deletion via CSRF
- CVE-2023-07681 PoCAvirato hotels online booking engine <= 5.0.5 - Subscriber+ SQLi
- CVE-2023-07691 PoChiWeb Migration Simple <= 2.0.0.1 Reflected Cross-Site Scripting
- CVE-2023-07701 PoCStack-based Buffer Overflow in gpac/gpac
- CVE-2023-07711 PoCSQL Injection in ampache/ampache
- CVE-2023-07721 PoCPopup Builder by OptinMonster < 2.12.2 - Subscriber+ Arbitrary Post Content Disclosure
- CVE-2023-07741 PoCSourceCodester Medical Certificate Generator App action.php sql injection
- CVE-2023-07773 PoCsAuthentication Bypass by Primary Weakness in modoboa/modoboa
- CVE-2023-07801 PoCImproper Restriction of Rendered UI Layers or Frames in cockpit-hq/cockpit
- CVE-2023-07811 PoCSourceCodester Canteen Management System removeOrder.php query sql injection
- CVE-2023-07821 PoCTenda AC23 httpd formGetSysToolDDNS out-of-bounds write
- CVE-2023-07831 PoCEcShop PHP File template.php unrestricted upload
- CVE-2023-07871 PoCCross-site Scripting (XSS) - Generic in thorsten/phpmyfaq
- CVE-2023-07901 PoCUncaught Exception in thorsten/phpmyfaq
- CVE-2023-07931 PoCWeak Password Requirements in thorsten/phpmyfaq
- CVE-2023-07951 PoCLibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3488, allowing attackers to cause a denial-of-service via a…
- CVE-2023-07961 PoCLibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3592, allowing attackers to cause a denial-of-service via a…
- CVE-2023-07971 PoCLibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tools/tiffcrop.c:6921,…
- CVE-2023-07981 PoCLibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3400, allowing attackers to cause a denial-of-service via a…
- CVE-2023-07991 PoCLibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3701, allowing attackers to cause a denial-of-service via a…
- CVE-2023-08001 PoCLibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3502, allowing attackers to cause a denial-of-service via a…
- CVE-2023-08011 PoCLibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and…
- CVE-2023-08021 PoCLibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3724, allowing attackers to cause a denial-of-service via a…
- CVE-2023-08031 PoCLibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3516, allowing attackers to cause a denial-of-service via a…
- CVE-2023-08041 PoCLibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3609, allowing attackers to cause a denial-of-service via a…
- CVE-2023-08081 PoCDeye/Revolt/Bosswerk Inverter Access Point Setting hard-coded password
- CVE-2023-08101 PoCCross-site Scripting (XSS) - Stored in btcpayserver/btcpayserver
- CVE-2023-08121 PoCActive Directory Integration / LDAP Integration < 4.1.1 - Unauthenticated Data Disclosure
- CVE-2023-08161 PoCFormidable Forms < 6.1 - IP Spoofing
- CVE-2023-08171 PoCBuffer Over-read in gpac/gpac
- CVE-2023-08181 PoCOff-by-one Error in gpac/gpac
- CVE-2023-08191 PoCHeap-based Buffer Overflow in gpac/gpac
- CVE-2023-08201 PoCUser Role by BestWebSoft < 1.6.7 - Privilege Escalation via CSRF
- CVE-2023-08231 PoCCookie Notice & Compliance for GDPR / CCPA < 2.4.7 - Contributor+ Stored XSS
- CVE-2023-08241 PoCUserPlus <= 2.0 - Stored XSS via CSRF
- CVE-2023-08271 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2023-08302 PoCsEasyNAS backup.pl system os command injection
- CVE-2023-08401 PoCPHPCrazy cross site scripting
- CVE-2023-08411 PoCGPAC reframe_mp3.c mp3_dmx_process heap-based overflow
- CVE-2023-08441 PoCNamaste! LMS < 2.6 - Admin+ Stored XSS
- CVE-2023-08491 PoCNetgear WNDR3700v2 Web Interface command injection
- CVE-2023-08501 PoCNetgear WNDR3700v2 Web Interface denial of service
- CVE-2023-08602 PoCsImproper Restriction of Excessive Authentication Attempts in modoboa/modoboa-installer
- CVE-2023-08611 PoCAuthenticated Command Injection in NetModule NSRW
- CVE-2023-08651 PoCWooCommerce Multiple Customer Addresses & Shipping < 21.7 - Arbitrary Address Creation/Deletion/Access/Update via IDOR
- CVE-2023-08661 PoCHeap-based Buffer Overflow in gpac/gpac
- CVE-2023-08721 PoCROLE_REST can be used to escalate to ROLE_ADMIN via /rest/users
- CVE-2023-08731 PoCKanban Boards for WordPress < 2.5.21 - Admin+ Stored XSS
- CVE-2023-08741 PoCKlaviyo <= 3.0.10 - Admin+ Stored XSS
- CVE-2023-08751 PoCWP Meta SEO < 4.5.3 - Subscriber+ SQLi
- CVE-2023-08762 PoCsWP Meta SEO < 4.5.3 - Subscriber+ Improper Authorization causing Arbitrary Redirect
- CVE-2023-08771 PoCCode Injection in froxlor/froxlor
- CVE-2023-08781 PoCCross-site Scripting (XSS) - Generic in nuxt/framework
- CVE-2023-08791 PoCCross-site Scripting (XSS) - Stored in btcpayserver/btcpayserver
- CVE-2023-08801 PoCMisinterpretation of Input in thorsten/phpmyfaq
- CVE-2023-08831 PoCSourceCodester Online Pizza Ordering System index.php sql injection
- CVE-2023-08891 PoCTF Random Numbers < 2.0.1 - Subscriber+ Arbitrary Option Update
- CVE-2023-08901 PoCShortcodes Ultimate < 5.12.8 - Subscriber+ Arbitrary Post Access
- CVE-2023-08911 PoCStagtools < 2.3.7 - Contributor+ Stored XSS
- CVE-2023-08921 PoCBizLibrary <= 1.1 - Admin+ Stored XSS
- CVE-2023-08931 PoCTime Sheets < 1.29.3 - Admin+ Stored XSS
- CVE-2023-08941 PoCPickup | Delivery | Dine-in date time <= 1.0.9 - Admin+ Stored XSS
- CVE-2023-08991 PoCSteveas WP Live Chat Shoutbox <= 1.4.2 - Unauthenticated Stored XSS
- CVE-2023-09002 PoCsAP Pricing Tables Lite <= 1.1.6 - Admin+ SQLi
- CVE-2023-09011 PoCExposure of Sensitive Information to an Unauthorized Actor in pixelfed/pixelfed
- CVE-2023-09023 PoCsSourceCodester Simple Food Ordering System process_order.php cross site scripting
- CVE-2023-09031 PoCSourceCodester Employee Task Management System edit-task.php sql injection
- CVE-2023-09042 PoCsSourceCodester Employee Task Management System task-details.php sql injection
- CVE-2023-09053 PoCsSourceCodester Employee Task Management System changePasswordForEmployee.php improper authentication
- CVE-2023-09071 PoCFilseclab Twister Antivirus IoControlCode ffsmon.sys 0x220017 denial of service
- CVE-2023-09081 PoCXoslab Easy File Locker xlkfs.sys MessageNotifyCallback denial of service
- CVE-2023-09111 PoCShortcodes Ultimate < 5.12.8 - Subscriber+ User Meta Disclosure
- CVE-2023-09122 PoCsSourceCodester Auto Dealer Management System sql injection
- CVE-2023-09132 PoCsSourceCodester Auto Dealer Management System sql injection
- CVE-2023-09141 PoCImproper Authorization in pixelfed/pixelfed
- CVE-2023-09152 PoCsSourceCodester Auto Dealer Management System sql injection
- CVE-2023-09162 PoCsSourceCodester Auto Dealer Management System Users.php access control
- CVE-2023-09171 PoCSourceCodester Simple Customer Relationship Management System login.php sql injection
- CVE-2023-09181 PoCcodeprojects Pharmacy Management System Avatar Image add.php unrestricted upload
- CVE-2023-09191 PoCMissing Authentication for Critical Function in kareadita/kavita
- CVE-2023-09241 PoCZyrex Popup <= 1.0 - Admin+ Arbitrary File Upload
- CVE-2023-09351 PoCDolphinPHP Incomplete Fix CVE-2021-46097 common.php os command injection
- CVE-2023-09361 PoCTP-Link Archer C50 Web Management Interface denial of service
- CVE-2023-09371 PoCVK All in One Expansion Unit < 9.87.1.0 - Reflected XSS
- CVE-2023-09382 PoCsSourceCodester Music Gallery Site GET Request music_list.php sql injection
- CVE-2023-09401 PoCProfileGrid < 5.3.1 - Subscriber+ Arbitrary Password Reset
- CVE-2023-09421 PoCJapanized For WooCommerce <= 2.5.4 - Reflected Cross-Site Scripting
- CVE-2023-09431 PoCSourceCodester Best POS Management System Image save_settings unrestricted upload
- CVE-2023-09472 PoCsPath Traversal in flatpressblog/flatpress
- CVE-2023-09482 PoCsJapanized For WooCommerce < 2.5.8 - Reflected XSS
- CVE-2023-09491 PoCCross-site Scripting (XSS) - Reflected in modoboa/modoboa
- CVE-2023-09551 PoCWP Statistics < 14.0 - Authenticated SQLi
- CVE-2023-09601 PoCSeaCMS Picture Management config.ftp.php deserialization
- CVE-2023-09612 PoCsSourceCodester Music Gallery Site GET Request view_music_details.php sql injection
- CVE-2023-09622 PoCsSourceCodester Music Gallery Site GET Request Master.php sql injection
- CVE-2023-09632 PoCsSourceCodester Music Gallery Site POST Request Users.php access control
- CVE-2023-09661 PoCSourceCodester Online Eyewear Shop cross site scripting
- CVE-2023-09681 PoCWatu Quiz <= 3.3.9 - Reflected Cross-Site Scripting
- CVE-2023-09831 PoCStylish Cost Calculator Premium < 7.9.0 - Unauthenticated Stored XSS
- CVE-2023-09871 PoCSourceCodester Online Pizza Ordering System cross site scripting
- CVE-2023-09881 PoCSourceCodester Online Pizza Ordering System cross-site request forgery
- CVE-2023-09891 PoCImproper Ownership Management in GitLab
- CVE-2023-09941 PoCExposure of Sensitive Information to an Unauthorized Actor in francoisjacquet/rosariosis
- CVE-2023-09951 PoCCross-site Scripting (XSS) - Stored in unilogies/bumsys
- CVE-2023-09971 PoCSourceCodester Moosikay E-Commerce System POST Parameter order.php sql injection
- CVE-2023-09981 PoCSourceCodester Alphaware Simple E-Commerce System Payment summary.php access control
- CVE-2023-09991 PoCSourceCodester Sales Tracker Management System cross-site request forgery