CVE-2023-28000 to CVE-2023-28999
88 CVEs with public proof-of-concept exploits.
- CVE-2023-281021 PoCCommand injection in discordrb
- CVE-2023-281061 PoCPimcore vulnerable to Cross-site Scripting in UrlSlug Data type
- CVE-2023-281152 PoCsSnappy vulnerable to PHAR deserialization, allowing remote code execution
- CVE-2023-2812111 PoCsAn issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on…
- CVE-2023-281281 PoCAn unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker…
- CVE-2023-281531 PoCAn issue was discovered in the Kiddoware Kids Place Parental Control application before 3.8.50 for Android. The child can remove all…
- CVE-2023-281971 PoCAn access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.3, macOS Big Sur 11.7.5, macOS…
- CVE-2023-282052 PoCsKEVA use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 and iPadOS 15.7.5,…
- CVE-2023-282061 PoCKEVAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and…
- CVE-2023-282181 PoCWindows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- CVE-2023-282291 PoCKEVWindows CNG Key Isolation Service Elevation of Privilege Vulnerability
- CVE-2023-282312 PoCsDHCP Server Service Remote Code Execution Vulnerability
- CVE-2023-282441 PoCWindows Kerberos Elevation of Privilege Vulnerability
- CVE-2023-282529 PoCsKEVWindows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2023-282851 PoCMicrosoft Office Remote Code Execution Vulnerability
- CVE-2023-282881 PoCMicrosoft SharePoint Server Spoofing Vulnerability
- CVE-2023-282931 PoCWindows Kernel Elevation of Privilege Vulnerability
- CVE-2023-283111 PoCMicrosoft Word Remote Code Execution Vulnerability
- CVE-2023-283242 PoCsA improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote…
- CVE-2023-283436 PoCsOS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone…
- CVE-2023-283441 PoCAn issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated…
- CVE-2023-283451 PoCAn issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application exposes the teacher's Console…
- CVE-2023-283461 PoCAn issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate with the private…
- CVE-2023-283471 PoCAn issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a proof-of-concept script that…
- CVE-2023-283481 PoCAn issue was discovered in Faronics Insight 10.0.19045 on Windows. A suitably positioned attacker could perform a man-in-the-middle attack…
- CVE-2023-283491 PoCAn issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a crafted program that…
- CVE-2023-283511 PoCAn issue was discovered in Faronics Insight 10.0.19045 on Windows. Every keystroke made by any user on a computer with the Student…
- CVE-2023-283521 PoCAn issue was discovered in Faronics Insight 10.0.19045 on Windows. By abusing the Insight UDP broadcast discovery system, an…
- CVE-2023-283531 PoCAn issue was discovered in Faronics Insight 10.0.19045 on Windows. An unauthenticated attacker is able to upload any type of file to any…
- CVE-2023-283541 PoCAn issue was discovered in Opsview Monitor Agent 6.8. An unauthenticated remote attacker can call check_nrpe against affected targets,…
- CVE-2023-283751 PoCCVE-2023-28375
- CVE-2023-283791 PoCA memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially…
- CVE-2023-283811 PoCAn OS command injection vulnerability exists in the admin.cgi MVPN_trial_init functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A…
- CVE-2023-283841 PoCCVE-2023-28384
- CVE-2023-283911 PoCA memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially…
- CVE-2023-283931 PoCA stack-based buffer overflow vulnerability exists in the tif_processing_dng_channel_count functionality of Accusoft ImageGear 20.1. A…
- CVE-2023-284301 PoCOneSignal repository github action command injection
- CVE-2023-2843224 PoCsKEVMinio Information Disclosure in Cluster Deployment
- CVE-2023-284341 PoCKEVMinIO is vulnerable to privilege escalation on Linux/MacOS
- CVE-2023-284351 PoCDataease file upload interface does not verify permission or file type
- CVE-2023-284432 PoCsdirectus vulnerable to Insertion of Sensitive Information into Log File
- CVE-2023-284462 PoCsDeno is vulnerable to interactive `run` permission prompt spoofing via improper ANSI neutralization
- CVE-2023-284471 PoCCross site scripting vulnerability in Javascript escaping in smarty/smarty
- CVE-2023-284521 PoCAn issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a resolver to ignore…
- CVE-2023-284581 PoCpretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Organizers can trigger the overwriting (with the…
- CVE-2023-284611 PoCKEVArray Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the…
- CVE-2023-284652 PoCsThe package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to…
- CVE-2023-284671 PoCIn MyBB before 1.8.34, there is XSS in the User CP module via the user email field.
- CVE-2023-284851 PoCA stored cross-site scripting (Stored XSS) vulnerability in file preview in WeKan before 6.75 allows remote authenticated users to inject…
- CVE-2023-284881 PoCclient.c in gdhcp in ConnMan through 1.41 could be used by network-adjacent attackers (operating a crafted DHCP server) to cause a…
- CVE-2023-285021 PoCStack buffer overflow in UniRPC's udadmin_server service
- CVE-2023-285031 PoCAuthentication bypass in UniRPC's udadmin service
- CVE-2023-285281 PoCIBM AIX command execution
- CVE-2023-285885 PoCsInteger Overflow or Wraparound in Bluetooth Host
- CVE-2023-286271 PoCOS Command Injection via GIT_PATH in pymedusa
- CVE-2023-286281 PoC`authority-regex` returns the wrong authority in lambdaisland/uri
- CVE-2023-286371 PoCDataEase AWS redshift data source exists for remote code execution vulnerability
- CVE-2023-286481 PoCCVE-2023-28648
- CVE-2023-286591 PoCThe Waiting: One-click Countdowns WordPress Plugin, version <= 0.6.2, is affected by an authenticated SQL injection vulnerability in the…
- CVE-2023-286601 PoCThe Events Made Easy WordPress Plugin, version <= 2.3.14 is affected by an authenticated SQL injection vulnerability in the 'search_name'…
- CVE-2023-286611 PoCThe WP Popup Banners WordPress Plugin, version <= 1.2.5, is affected by an authenticated SQL injection vulnerability in the 'value'…
- CVE-2023-286622 PoCsThe Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection…
- CVE-2023-286631 PoCThe Formidable PRO2PDF WordPress Plugin, version < 3.11, is affected by an authenticated SQL injection vulnerability in the ‘fieldmap’…
- CVE-2023-286641 PoCThe Meta Data and Taxonomies Filter WordPress plugin, in versions < 1.3.1, is affected by a reflected cross-site scripting vulnerability…
- CVE-2023-286652 PoCsThe Woo Bulk Price Update WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the…
- CVE-2023-286661 PoCThe InPost Gallery WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'imgurl'…
- CVE-2023-286671 PoCThe Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels…
- CVE-2023-287251 PoCGeneral Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute…
- CVE-2023-287441 PoCA use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.1.1.15289. A specially crafted…
- CVE-2023-287531 PoCnetconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function. A malicious individual could leverage this…
- CVE-2023-287691 PoCThe buffer overflow vulnerability in the library “libclinkc.so” of the web server “zhttpd” in Zyxel DX5401-B0 firmware versions prior to…
- CVE-2023-287701 PoCThe sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmware versions prior…
- CVE-2023-287717 PoCsKEVImproper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through…
- CVE-2023-287722 PoCsAn issue was discovered in the Linux kernel before 5.13.3. lib/seq_buf.c has a seq_buf_putmem_hex buffer overflow.
- CVE-2023-287771 PoCWordPress LearnDash LMS Plugin <= 4.5.3 is vulnerable to SQL Injection
- CVE-2023-287871 PoCWordPress Quiz And Survey Master plugin <= 8.1.4 - Unauthenticated SQL Injection vulnerability
- CVE-2023-288101 PoCSome access control/intercom products have unauthorized modification of device network configuration vulnerabilities. Attackers can modify…
- CVE-2023-288501 PoCPimcore Perspective Editor vulnerable to Cross-site Scripting in perspective name
- CVE-2023-288531 PoCMastodon's blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP database
- CVE-2023-288681 PoCSupport Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operating system by…
- CVE-2023-288691 PoCSupport Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents of arbitrary files on the operating…
- CVE-2023-288701 PoCInsecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to configuration…
- CVE-2023-288711 PoCSupport Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry information of the operating system by…
- CVE-2023-288731 PoCAn XSS issue in wiki and discussion pages in Seafile 9.0.6 allows attackers to inject JavaScript into the Markdown editor.
- CVE-2023-288741 PoCThe next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary sites.
- CVE-2023-288751 PoCA Stored XSS issue in shared files download terms in Filerun Update 20220202 allows attackers to inject JavaScript code that is executed…
- CVE-2023-288761 PoCA Broken Access Control issue in comments to uploaded files in Filerun through Update 20220202 allows attackers to delete comments on…
- CVE-2023-288791 PoCIn Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript…