CVE-2023-24000 to CVE-2023-24999
131 CVEs with public proof-of-concept exploits.
- CVE-2023-240001 PoCWordPress GamiPress Plugin <= 2.5.7 is vulnerable to SQL Injection
- CVE-2023-240121 PoCData Distribution Service (DDS) Chain of Trust (CoT) violation vulnerability in Open DDS
- CVE-2023-240181 PoCA stack-based buffer overflow vulnerability exists in the libzebra.so.0.0.0 security_decrypt_password functionality of Milesight UR32L…
- CVE-2023-240191 PoCA stack-based buffer overflow vulnerability exists in the urvpn_client http_connection_readcb functionality of Milesight UR32L v32.3.0.5.…
- CVE-2023-240391 PoCA stack-based buffer overflow in ParseColors in libXm in Common Desktop Environment 1.6 can be exploited by local low-privileged users via…
- CVE-2023-240402 PoCsdtprintinfo in Common Desktop Environment 1.6 has a bug in the parser of lpstat (an invoked external command) during listing of the names…
- CVE-2023-240443 PoCsA Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites…
- CVE-2023-240451 PoCIn Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target…
- CVE-2023-240461 PoCAn issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary commands via use of a crafted string in…
- CVE-2023-240556 PoCsKeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the…
- CVE-2023-240591 PoCGrand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in…
- CVE-2023-240681 PoCSignal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to modify conversation attachments within the…
- CVE-2023-240691 PoCSignal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to obtain potentially sensitive attachments sent in messages…
- CVE-2023-240787 PoCsReal Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component…
- CVE-2023-240951 PoCTrendNet Wireless AC Easy-Upgrader TEW-820AP v1.0R, firmware version 1.01.B01 was discovered to contain a stack overflow via the…
- CVE-2023-240961 PoCTrendNet Wireless AC Easy-Upgrader TEW-820AP v1.0R, firmware version 1.01.B01 was discovered to contain a stack overflow via the newpass…
- CVE-2023-240971 PoCTrendNet Wireless AC Easy-Upgrader TEW-820AP v1.0R, firmware version 1.01.B01 was discovered to contain a stack overflow via the…
- CVE-2023-240981 PoCTrendNet Wireless AC Easy-Upgrader TEW-820AP v1.0R, firmware version 1.01.B01 was discovered to contain a stack overflow via the…
- CVE-2023-240991 PoCTrendNet Wireless AC Easy-Upgrader TEW-820AP v1.0R, firmware version 1.01.B01 was discovered to contain a stack overflow via the username…
- CVE-2023-241141 PoCtypecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.
- CVE-2023-241381 PoCTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the host_time parameter in the…
- CVE-2023-241501 PoCA command injection vulnerability in the serverIp parameter in the function meshSlaveDlfw of TOTOLINK T8 V4.1.5cu allows attackers to…
- CVE-2023-241511 PoCA command injection vulnerability in the ip parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers…
- CVE-2023-241521 PoCA command injection vulnerability in the serverIp parameter in the function meshSlaveUpdate of TOTOLINK T8 V4.1.5cu allows attackers to…
- CVE-2023-241531 PoCA command injection vulnerability in the version parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows…
- CVE-2023-241541 PoCTOTOLINK T8 V4.1.5cu was discovered to contain a command injection vulnerability via the slaveIpList parameter in the function setUpgradeFW.
- CVE-2023-241561 PoCA command injection vulnerability in the ip parameter in the function recvSlaveUpgstatus of TOTOLINK T8 V4.1.5cu allows attackers to…
- CVE-2023-241571 PoCA command injection vulnerability in the serverIp parameter in the function updateWifiInfo of TOTOLINK T8 V4.1.5cu allows attackers to…
- CVE-2023-241591 PoCTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admpass parameter in the setPasswordCfg…
- CVE-2023-241601 PoCTOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg…
- CVE-2023-241661 PoCTenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/formWifiBasicSet.
- CVE-2023-241811 PoCLuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the…
- CVE-2023-241821 PoCLuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the…
- CVE-2023-242031 PoCCross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute…
- CVE-2023-242041 PoCSQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitrary…
- CVE-2023-242051 PoCClash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the…
- CVE-2023-242121 PoCTenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the timeType function at /goform/SetSysTimeCfg.
- CVE-2023-242171 PoCAgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability.
- CVE-2023-242291 PoCDrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to inject operating system…
- CVE-2023-242361 PoCTOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the province parameter at…
- CVE-2023-242381 PoCTOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the city parameter at…
- CVE-2023-242431 PoCCData RSB Connect v22.0.8336 was discovered to contain a Server-Side Request Forgery (SSRF).
- CVE-2023-242493 PoCsAn arbitrary file upload vulnerability in laravel-admin v1.8.19 allows attackers to execute arbitrary code via a crafted PHP file.
- CVE-2023-242511 PoCWangEditor v5 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /dist/index.js.
- CVE-2023-242611 PoCA vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code via a crafted POST…
- CVE-2023-242691 PoCAn arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via…
- CVE-2023-242761 PoCTOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the country parameter at…
- CVE-2023-242782 PoCsSquidex before 7.4.0 was discovered to contain a squid.svg cross-site scripting (XSS) vulnerability.
- CVE-2023-242791 PoCA cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers to execute…
- CVE-2023-242821 PoCAn arbitrary file upload vulnerability in Poly Trio 8800 7.2.2.1094 allows attackers to execute arbitrary code via a crafted ringtone file.
- CVE-2023-243171 PoCJudging Management System 1.0 was discovered to contain an arbitrary file upload vulnerability via the component edit_organizer.php.
- CVE-2023-243222 PoCsA reflected cross-site scripting (XSS) vulnerability in the FileDialog.aspx component of mojoPortal v2.7.0.0 allows attackers to execute…
- CVE-2023-243231 PoCMojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability.
- CVE-2023-243293 PoCsAn issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that…
- CVE-2023-243301 PoCCommand Injection vulnerability in D-Link Dir 882 with firmware version DIR882A1_FW130B06 allows attackers to run arbitrary commands via…
- CVE-2023-243311 PoCCommand Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands…
- CVE-2023-243321 PoCA stack overflow vulnerability in Tenda AC6 with firmware version US_AC6V5.0re_V03.03.02.01_cn_TDC01 allows attackers to run arbitrary…
- CVE-2023-243331 PoCA stack overflow vulnerability in Tenda AC21 with firmware version US_AC21V1.0re_V16.03.08.15_cn_TDC01 allows attackers to run arbitrary…
- CVE-2023-243341 PoCA stack overflow vulnerability in Tenda AC23 with firmware version US_AC23V1.0re_V16.03.07.45_cn_TDC01 allows attackers to run arbitrary…
- CVE-2023-243441 PoCD-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at…
- CVE-2023-243451 PoCD-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at…
- CVE-2023-243461 PoCD-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the wan_connected parameter at…
- CVE-2023-243471 PoCD-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at…
- CVE-2023-243481 PoCD-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetACLFilter.
- CVE-2023-243491 PoCD-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetRoute.
- CVE-2023-243501 PoCD-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the config.smtp_email_subject parameter at…
- CVE-2023-243511 PoCD-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the FILECODE parameter at /goform/formLogin.
- CVE-2023-243521 PoCD-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWPS.
- CVE-2023-243661 PoCAn arbitrary file download vulnerability in rConfig v6.8.0 allows attackers to download sensitive files via a crafted HTTP request.
- CVE-2023-244221 PoCA sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and earlier allows…
- CVE-2023-244721 PoCA denial of service vulnerability exists in the FitsOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially…
- CVE-2023-244731 PoCAn information disclosure vulnerability exists in the TGAInput::read_tga2_header functionality of OpenImageIO Project OpenImageIO…
- CVE-2023-244871 PoCArbitrary file read
- CVE-2023-244887 PoCsCross site scripting
- CVE-2023-244893 PoCsKEVA vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an…
- CVE-2023-244961 PoCCross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN v2.0.2. A…
- CVE-2023-244971 PoCCross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN v2.0.2. A…
- CVE-2023-245171 PoCRemote Code Execution via Unrestricted File Upload
- CVE-2023-245191 PoCTwo OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A…
- CVE-2023-245201 PoCTwo OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A…
- CVE-2023-245821 PoCTwo OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially…
- CVE-2023-245831 PoCTwo OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially…
- CVE-2023-245851 PoCAn out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted…
- CVE-2023-245951 PoCAn OS command injection vulnerability exists in the ys_thirdparty system_user_script functionality of Milesight UR32L v32.3.0.5. A…
- CVE-2023-246091 PoCMatrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension…
- CVE-2023-246101 PoCNOSH 4a5cfdb allows remote authenticated users to execute PHP arbitrary code via the "practice logo" upload feature. The client-side…
- CVE-2023-246201 PoCAn issue was discovered in Esoteric YamlBeans through 1.15. A crafted YAML document is able perform am XML Entity Expansion attack against…
- CVE-2023-246211 PoCAn issue was discovered in Esoteric YamlBeans through 1.15. It allows untrusted deserialisation to Java classes by default, where the data…
- CVE-2023-246261 PoCsocket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows…
- CVE-2023-246572 PoCsphpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at…
- CVE-2023-246741 PoCPermissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter.
- CVE-2023-246751 PoCCross Site Scripting Vulnerability in BluditCMS v.3.14.1 allows attackers to execute arbitrary code via the Categories Friendly URL.
- CVE-2023-246841 PoCChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the EID parameter at GetText.php.
- CVE-2023-246851 PoCChurchCRM v4.5.3 and below was discovered to contain a SQL injection vulnerability via the Event parameter under the Event Attendance…
- CVE-2023-246861 PoCAn issue in the CSV Import function of ChurchCRM v4.5.3 and below allows attackers to execute arbitrary code via importing a crafted CSV…
- CVE-2023-246871 PoCMojoportal v2.7.0.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Company Info Settings component.…
- CVE-2023-246881 PoCAn issue in Mojoportal v2.7.0.0 allows an unauthenticated attacker to register a new user even if the Allow User Registrations feature is…
- CVE-2023-246891 PoCAn issue in Mojoportal v2.7.0.0 and below allows an authenticated attacker to list all css files inside the root path of the webserver via…
- CVE-2023-246901 PoCChurchCRM 4.5.3 and below was discovered to contain a stored cross-site scripting (XSS) vulnerability at /api/public/register/family.
- CVE-2023-247094 PoCsAn issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and login.xml parameters.
- CVE-2023-247211 PoCA cross-site scripting (XSS) vulnerability in LiveAction LiveSP v21.1.2 allows attackers to execute arbitrary web scripts or HTML.
- CVE-2023-247331 PoCPMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at…
- CVE-2023-247351 PoCPMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerability allows…
- CVE-2023-247371 PoCPMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at…
- CVE-2023-247511 PoClibde265 v1.0.10 was discovered to contain a NULL pointer dereference in the mc_chroma function at motion.cc. This vulnerability allows…
- CVE-2023-247521 PoClibde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_hevc_epel_pixels_8_sse function at sse-motion.cc.…
- CVE-2023-247541 PoClibde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at…
- CVE-2023-247551 PoClibde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_weighted_pred_8_fallback function at fallback-motion.cc.…
- CVE-2023-247561 PoClibde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_unweighted_pred_8_sse function at sse-motion.cc.…
- CVE-2023-247571 PoClibde265 v1.0.10 was discovered to contain a NULL pointer dereference in the put_unweighted_pred_16_fallback function at…
- CVE-2023-247581 PoClibde265 v1.0.10 was discovered to contain a NULL pointer dereference in the ff_hevc_put_weighted_pred_avg_8_sse function at…
- CVE-2023-247631 PoCIn the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2.13.0.
- CVE-2023-247731 PoCFunadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list.
- CVE-2023-247742 PoCsFunadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php.
- CVE-2023-247752 PoCsFunadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php.
- CVE-2023-247802 PoCsFunadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns.
- CVE-2023-247811 PoCFunadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\MemberLevel.php.
- CVE-2023-247821 PoCFunadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit.
- CVE-2023-247882 PoCsNotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at…
- CVE-2023-247971 PoCD-Link DIR882 DIR882A1_FW110B02 was discovered to contain a stack overflow in the sub_48AC20 function. This vulnerability allows attackers…
- CVE-2023-248041 PoCownCloud Android app vulnerable to Path Traversal
- CVE-2023-248051 PoCCommand injection in cups-filters
- CVE-2023-248081 PoCDenial Of Service when opening a corrupt PDF file in pdfio
- CVE-2023-248151 PoCDisclosure of classpath resources on Windows when mounted on a wildcard route in vertx-web
- CVE-2023-248161 PoCset_term_title command injection in ipython
- CVE-2023-248241 PoCQuadratic complexity may lead to a denial of service in cmark-gfm
- CVE-2023-248711 PoCWindows Bluetooth Service Remote Code Execution Vulnerability
- CVE-2023-248921 PoCMicrosoft Edge (Chromium-based) Webview2 Spoofing Vulnerability
- CVE-2023-249323 PoCsSecure Boot Security Feature Bypass Vulnerability
- CVE-2023-249553 PoCsKEVMicrosoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2023-249981 PoCApache Commons FileUpload, Apache Tomcat: FileUpload DoS with excessive parts