CVE-2023-27000 to CVE-2023-27999
152 CVEs with public proof-of-concept exploits.
- CVE-2023-270082 PoCsA Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to…
- CVE-2023-270101 PoCWondershare Dr.Fone v12.9.6 was discovered to contain weak permissions for the service WsDrvInst. This vulnerability allows attackers to…
- CVE-2023-270121 PoCTenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the setSchedWifi function. This vulnerability…
- CVE-2023-270131 PoCTenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the get_parentControl_list_Info function. This…
- CVE-2023-270141 PoCTenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_46AC38 function. This vulnerability allows…
- CVE-2023-270151 PoCTenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_4A75C0 function. This vulnerability allows…
- CVE-2023-270161 PoCTenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the R7WebsSecurityHandler function. This…
- CVE-2023-270171 PoCTenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45DC58 function. This vulnerability allows…
- CVE-2023-270181 PoCTenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45EC1C function. This vulnerability allows…
- CVE-2023-270191 PoCTenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_458FBC function. This vulnerability allows…
- CVE-2023-270201 PoCTenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the saveParentControlInfo function. This…
- CVE-2023-270211 PoCTenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the formSetFirewallCfg function. This…
- CVE-2023-270321 PoCPrestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component…
- CVE-2023-270341 PoCPrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.
- CVE-2023-270351 PoCAn issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other…
- CVE-2023-270401 PoCSimple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter.
- CVE-2023-270421 PoCTenda AX3 V16.03.12.11 is vulnerable to Buffer Overflow via /goform/SetFirewallCfg.
- CVE-2023-270541 PoCA cross-site scripting (XSS) vulnerability in MiroTalk P2P before commit f535b35 allows attackers to execute arbitrary web scripts or HTML…
- CVE-2023-270591 PoCA cross-site scripting (XSS) vulnerability in the Edit Group function of ChurchCRM v4.5.3 allows attackers to execute arbitrary web…
- CVE-2023-270611 PoCTenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the wifiFilterListRemark parameter…
- CVE-2023-270621 PoCTenda V15V1.0 was discovered to contain a buffer overflow vulnerability via the gotoUrl parameter in the formPortalAuth function. This…
- CVE-2023-270631 PoCTenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the DNSDomainName parameter in the…
- CVE-2023-270641 PoCTenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the index parameter in the…
- CVE-2023-270651 PoCTenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the picName parameter in the…
- CVE-2023-270771 PoCStack Overflow vulnerability found in 360 D901 allows a remote attacker to cause a Distributed Denial of Service (DDOS) via a crafted HTTP…
- CVE-2023-270781 PoCA command injection issue was found in TP-Link MR3020 v.1_150921 that allows a remote attacker to execute arbitrary commands via a crafted…
- CVE-2023-270791 PoCCommand Injection vulnerability found in Tenda G103 v.1.0.05 allows an attacker to obtain sensitive information via a crafted package
- CVE-2023-270981 PoCTP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.
- CVE-2023-271002 PoCsImproper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense…
- CVE-2023-271021 PoCLibde265 v1.0.11 was discovered to contain a segmentation violation via the function decoder_context::process_slice_segment_header at…
- CVE-2023-271031 PoCLibde265 v1.0.11 was discovered to contain a heap buffer overflow via the function derive_collocated_motion_vectors at motion.cc.
- CVE-2023-271071 PoCIncorrect access control in the runReport function of MyQ Solution Print Server before 8.2 Patch 32 and Central Server before 8.2 Patch 22…
- CVE-2023-271121 PoCpearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the projectCode parameter at project.php.
- CVE-2023-271131 PoCpearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the organizationCode parameter at project.php.
- CVE-2023-271141 PoCradare2 v5.8.3 was discovered to contain a segmentation fault via the component wasm_dis at p/wasm/wasm.c.
- CVE-2023-271151 PoCWebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::cat_compute_size.
- CVE-2023-271161 PoCWebAssembly v1.0.29 discovered to contain an abort in CWriter::MangleType.
- CVE-2023-271171 PoCWebAssembly v1.0.29 was discovered to contain a heap overflow via the component component wabt::Node::operator.
- CVE-2023-271191 PoCWebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::Decompiler::WrapChild.
- CVE-2023-271211 PoCA cross-site scripting (XSS) vulnerability in the component /framework/cron/action/humanize of Pleasant Solutions Pleasant Password Server…
- CVE-2023-271301 PoCCross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via an arbitrarily supplied…
- CVE-2023-271321 PoCTSplus Remote Work 16.0.0.0 places a cleartext password on the "var pass" line of the HTML source code for the secure single sign-on web…
- CVE-2023-271331 PoCTSplus Remote Work 16.0.0.0 has weak permissions for .exe, .js, and .html files under the…
- CVE-2023-271351 PoCTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the enabled parameter at…
- CVE-2023-271501 PoCopenCRX 5.2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name field after creation of a Tracker in…
- CVE-2023-271511 PoCopenCRX 5.2.0 was discovered to contain an HTML injection vulnerability for Search Criteria-Activity Number (in the Saved Search Activity)…
- CVE-2023-271593 PoCsAppwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This…
- CVE-2023-2716331 PoCsrequest-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This…
- CVE-2023-271672 PoCsSuprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/absence?search_month=1.
- CVE-2023-271701 PoCXpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.
- CVE-2023-271792 PoCsGDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at…
- CVE-2023-271911 PoCAn issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the SharedPreference files.
- CVE-2023-271921 PoCAn issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the key_wifi_safe_net_check_url,…
- CVE-2023-271931 PoCAn issue found in DUALSPACE v.1.1.3 allows a local attacker to gain privileges via the key_ad_new_user_avoid_time field.
- CVE-2023-272162 PoCsAn issue found in D-Link DSL-3782 v.1.03 allows remote authenticated users to execute arbitrary code as root via the network settings page.
- CVE-2023-272291 PoCTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the upBw parameter at…
- CVE-2023-272311 PoCTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the downBw parameter at…
- CVE-2023-272321 PoCTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wanStrategy parameter at…
- CVE-2023-272331 PoCPiwigo before 13.6.0 was discovered to contain a SQL injection vulnerability via the order[0][dir] parameter at user_list_backend.php.
- CVE-2023-272341 PoCA Cross-Site Request Forgery (CSRF) in /Sys/index.html of Jizhicms v2.4.5 allows attackers to arbitrarily make configuration changes…
- CVE-2023-272351 PoCAn arbitrary file upload vulnerability in the \admin\c\CommonController.php component of Jizhicms v2.4.5 allows attackers to execute…
- CVE-2023-272492 PoCsswfdump v0.9.2 was discovered to contain a heap buffer overflow in the function swf_GetPlaceObject at swfobject.c.
- CVE-2023-272532 PoCsA command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute…
- CVE-2023-272901 PoCIBM Observability with Instana missing authentication
- CVE-2023-272922 PoCsAn open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters.
- CVE-2023-272931 PoCImproper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the…
- CVE-2023-272941 PoCImproper neutralization of input during web page generation allows an authenticated attacker with access to a restricted account to submit…
- CVE-2023-272951 PoCCross-site request forgery is facilitated by OpenCATS failure to require CSRF tokens in POST requests. An attacker can exploit this issue…
- CVE-2023-273262 PoCsParallels Desktop Toolgate Directory Traversal Local Privilege Escalation Vulnerability
- CVE-2023-2735029 PoCsKEVThis vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).…
- CVE-2023-273513 PoCsKEVThis vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914).…
- CVE-2023-273633 PoCsFoxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability
- CVE-2023-2737221 PoCsSPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions…
- CVE-2023-273791 PoCA use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 12.1.2.15332. By prematurely…
- CVE-2023-273801 PoCAn OS command injection vulnerability exists in the admin.cgi USSD_send functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A…
- CVE-2023-273901 PoCA heap-based buffer overflow vulnerability exists in the Sequence::DrawText functionality of Diagon v1.0.139. A specially crafted markdown…
- CVE-2023-273951 PoCA heap-based buffer overflow vulnerability exists in the vpnserver WpcParsePacket() functionality of SoftEther VPN 4.41-9782-beta,…
- CVE-2023-274701 PoCBASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at…
- CVE-2023-274791 PoCImproper Neutralization of Directives in Dynamically Evaluated Code in org.xwiki.platform:xwiki-platform-panels-ui
- CVE-2023-274821 PoChomeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the…
- CVE-2023-274871 PoCEnvoy client may fake the header `x-envoy-original-path`
- CVE-2023-274881 PoCEnvoy gRPC client produces invalid protobuf when an HTTP header with non-UTF8 value is received.
- CVE-2023-274911 PoCEnvoy forwards invalid Http2/Http3 downstream headers
- CVE-2023-274921 PoCEnvoy may crash when a large request body is processed in Lua filter
- CVE-2023-274931 PoCEnvoy doesn't escape HTTP header values
- CVE-2023-274961 PoCEnvoy may crash when a redirect url without a state param is received in the oauth filter
- CVE-2023-275161 PoCAn authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. A…
- CVE-2023-2752424 PoCsKEVApache Superset: Session validation vulnerability when using provided default SECRET_KEY
- CVE-2023-275325 PoCsKEVVulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained.…
- CVE-2023-275612 PoCsrunc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit…
- CVE-2023-275641 PoCThe n8n package 0.218.0 for Node.js allows Information Disclosure.
- CVE-2023-275661 PoCCubism Core in Live2D Cubism Editor 4.2.03 allows out-of-bounds write via a crafted Section Offset Table or Count Info Table in an MOC3…
- CVE-2023-275681 PoCSQL injection vulnerability inSpryker Commerce OS 0.9 that allows for access to sensitive data via…
- CVE-2023-275691 PoCThe eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header.
- CVE-2023-275711 PoCAn issue was discovered in DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. The troubleshooting_logs_download.php log file download…
- CVE-2023-275721 PoCAn issue was discovered in CommScope Arris DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. A reflected XSS vulnerability was…
- CVE-2023-275811 PoCgithub-slug-action vulnerable to arbitrary code execution
- CVE-2023-275843 PoCsDragonfly2 vulnerable to hard coded cyptographic key
- CVE-2023-275861 PoCCairoSVG improperly processes SVG files loaded from external resources
- CVE-2023-275873 PoCsReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an error message containing sensitive…
- CVE-2023-276241 PoCWordPress Redirect After Login Plugin <= 0.1.9 is vulnerable to Cross Site Scripting (XSS)
- CVE-2023-276361 PoCProgress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.
- CVE-2023-276372 PoCsAn issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged…
- CVE-2023-276382 PoCsAn issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged…
- CVE-2023-276392 PoCsAn issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged…
- CVE-2023-276402 PoCsAn issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged…
- CVE-2023-276412 PoCsThe REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XSS attacks via a…
- CVE-2023-276431 PoCAn issue found in POWERAMP 925-bundle-play and Poweramp 954-uni allows a remote attacker to cause a denial of service via the Rescan…
- CVE-2023-276451 PoCAn issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges via the reverb and…
- CVE-2023-276471 PoCAn issue found in DUALSPACE Lock Master v.2.2.4 allows a local attacker to cause a denial of service or gain sensitive information via the…
- CVE-2023-276481 PoCDirectory Traversal vulnerability found in T-ME Studios Change Color of Keypad v.1.275.1.277 allows a remote attacker to execute arbitrary…
- CVE-2023-276491 PoCSQL injection vulnerability found in Trusted Tools Free Music v.2.1.0.47, v.2.0.0.46, v.1.9.1.45, v.1.8.2.43 allows a remote attacker to…
- CVE-2023-276501 PoCAn issue found in APUS Group Launcher v.3.10.73 and v.3.10.88 allows a remote attacker to execute arbitrary code via the FONT_FILE…
- CVE-2023-276511 PoCAn issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges via the update_info field of the…
- CVE-2023-276521 PoCAn issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges cause a denial of service via the…
- CVE-2023-276531 PoCAn issue found in WHOv.1.0.28, v.1.0.30, v.1.0.32 allows an attacker to cause a denial of service via the SharedPreference files.
- CVE-2023-277031 PoCThe Android version of pikpak v1.29.2 was discovered to contain an information leak via the debug interface.
- CVE-2023-277041 PoCVoid Tools Everything lower than v1.4.1.1022 was discovered to contain a Regular Expression Denial of Service (ReDoS).
- CVE-2023-277061 PoCBitwarden Windows desktop application versions prior to v2023.4.0 store biometric keys in Windows Credential Manager, accessible to other…
- CVE-2023-277071 PoCSQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the…
- CVE-2023-277091 PoCSQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the…
- CVE-2023-277111 PoCCross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via the Comment Manager…
- CVE-2023-277181 PoCD-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_498308 function. This vulnerability allows attackers to cause…
- CVE-2023-277191 PoCD-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_478360 function. This vulnerability allows attackers to cause…
- CVE-2023-277201 PoCD-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_48d630 function. This vulnerability allows attackers to cause…
- CVE-2023-277272 PoCsNginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_function_frame at src/njs_function.h.
- CVE-2023-277282 PoCsNginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_dump_is_recursive at src/njs_vmcode.c.
- CVE-2023-277302 PoCsNginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_lvlhsh_find at src/njs_lvlhsh.c.
- CVE-2023-277421 PoCIDURAR ERP/CRM v1 was discovered to contain a SQL injection vulnerability via the component /api/login.
- CVE-2023-277541 PoCvox2mesh 1.0 has stack-overflow in main.cpp, this is stack-overflow caused by incorrect use of memcpy() funciton. The flow allows an…
- CVE-2023-277721 PoClibiec61850 v1.5.1 was discovered to contain a segmentation violation via the function ControlObjectClient_setOrigin() at…
- CVE-2023-277751 PoCA stored HTML injection vulnerability in LiveAction LiveSP v21.1.2 allows attackers to execute arbitrary code via a crafted payload.
- CVE-2023-277811 PoCjpegoptim v1.5.2 was discovered to contain a heap overflow in the optimize function at jpegoptim.c.
- CVE-2023-277831 PoCAn issue found in TCPreplay tcprewrite v.4.4.3 allows a remote attacker to cause a denial of service via the tcpedit_dlt_cleanup function…
- CVE-2023-277841 PoCAn issue found in TCPReplay v.4.4.3 allows a remote attacker to cause a denial of service via the read_hexstring function at the…
- CVE-2023-277961 PoCRG-EW1200G PRO Wireless Routers EW_3.0(1)B11P204, RG-EW1800GX PRO Wireless Routers EW_3.0(1)B11P204, and RG-EW3200GX PRO Wireless Routers…
- CVE-2023-278212 PoCsDatabasir v1.0.7 was discovered to contain a remote code execution (RCE) vulnerability via the mockDataScript parameter.
- CVE-2023-278231 PoCAn authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.
- CVE-2023-278261 PoCSeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Injection. which…
- CVE-2023-278301 PoCTightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate files with crafted…
- CVE-2023-278424 PoCsInsecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code…
- CVE-2023-278431 PoCSQL injection vulnerability found in PrestaShop askforaquote v.5.4.2 and before allow a remote attacker to gain privileges via the…
- CVE-2023-278472 PoCsSQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges via the…
- CVE-2023-278481 PoCbroccoli-compass v0.2.4 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.
- CVE-2023-278491 PoCrails-routes-to-json v1.0.0 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.
- CVE-2023-278551 PoCRockwell Automation ThinManager ThinServer Path Traversal Upload
- CVE-2023-278561 PoCRockwell Automation ThinManager ThinServer Path Traversal Download
- CVE-2023-278821 PoCA heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A…
- CVE-2023-278921 PoCInsufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.7.0 allow a global buffer overflow via crafted…
- CVE-2023-279221 PoCCross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary…
- CVE-2023-279741 PoCBitwarden through 2023.2.1 offers password auto-fill when the second-level domain matches, e.g., a password stored for an example.com…
- CVE-2023-279979 PoCsKEVA heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and…