CVE-2023-2000 to CVE-2023-2999
475 CVEs with public proof-of-concept exploits.
- CVE-2023-20022 PoCsA vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux…
- CVE-2023-20082 PoCsKernel: udmabuf: improper validation of array index leading to local privilege escalation
- CVE-2023-20092 PoCsPretty Url <= 1.5.4 - Admin+ Stored XSS in plugin settings
- CVE-2023-20101 PoCForminator < 1.24.1 - Unauthenticated Race Condition on poll vote
- CVE-2023-20141 PoCCross-site Scripting (XSS) - Generic in microweber/microweber
- CVE-2023-20171 PoCImproper Control of Generation of Code in Twig Rendered Views in Shopware
- CVE-2023-20211 PoCCross-site Scripting (XSS) - Stored in nilsteampassnet/teampass
- CVE-2023-20221 PoCMissing Authorization in GitLab
- CVE-2023-20234 PoCsCustom 404 Pro < 3.7.3 - Reflected Cross-Site Scripting
- CVE-2023-20241 PoCImproper Authentication for OpenBlue Enterprise Manager Data Collector
- CVE-2023-20261 PoCImage Protector <= 1.1 - Admin+ Stored Cross-Site Scripting
- CVE-2023-20281 PoCCall Now Accessibility Button < 1.1 - Admin+ Stored Cross Site Scripting
- CVE-2023-20292 PoCsPrePost SEO <= 3.0 - Admin+ Stored Cross-Site Scripting
- CVE-2023-20301 PoCImproper Verification of Cryptographic Signature in GitLab
- CVE-2023-20321 PoCCustom 404 Pro < 3.8.1 - Multiple SQL Injection
- CVE-2023-20334 PoCsKEVType confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2023-20341 PoCUnrestricted Upload of File with Dangerous Type in froxlor/froxlor
- CVE-2023-20351 PoCCampcodes Video Sharing Website signup.php sql injection
- CVE-2023-20361 PoCCampcodes Video Sharing Website upload.php sql injection
- CVE-2023-20371 PoCCampcodes Video Sharing Website watch.php sql injection
- CVE-2023-20381 PoCCampcodes Video Sharing Website admin_class.php sql injection
- CVE-2023-20391 PoCnovel-plus sql injection
- CVE-2023-20401 PoCnovel-plus sql injection
- CVE-2023-20411 PoCnovel-plus sql injection
- CVE-2023-20421 PoCDataGear JDBC Server deserialization
- CVE-2023-20471 PoCCampcodes Advanced Online Voting System login.php sql injection
- CVE-2023-20481 PoCCampcodes Advanced Online Voting System voters_row.php sql injection
- CVE-2023-20491 PoCCampcodes Advanced Online Voting System ballot_up.php sql injection
- CVE-2023-20501 PoCCampcodes Advanced Online Voting System positions_add.php sql injection
- CVE-2023-20511 PoCCampcodes Advanced Online Voting System positions_row.php sql injection
- CVE-2023-20521 PoCCampcodes Advanced Online Voting System ballot_down.php sql injection
- CVE-2023-20531 PoCCampcodes Advanced Online Voting System candidates_row.php sql injection
- CVE-2023-20541 PoCCampcodes Advanced Online Voting System positions_delete.php sql injection
- CVE-2023-20551 PoCCampcodes Advanced Online Voting System config_save.php cross site scripting
- CVE-2023-20561 PoCDedeCMS module_main.php GetSystemFile code injection
- CVE-2023-20571 PoCEyouCms New Picture cross site scripting
- CVE-2023-20581 PoCEyouCms HTTP POST Request cross site scripting
- CVE-2023-20592 PoCsDedeCMS select_templets.php path traversal
- CVE-2023-20684 PoCsFile Manager Advanced Shortcode <= 2.3.2 - Unauthenticated Remote Code Execution through shortcode
- CVE-2023-20731 PoCCampcodes Online Traffic Offense Management System Login.php sql injection
- CVE-2023-20741 PoCCampcodes Online Traffic Offense Management System Master.php sql injection
- CVE-2023-20751 PoCCampcodes Online Traffic Offense Management System view_details.php sql injection
- CVE-2023-20761 PoCCampcodes Online Traffic Offense Management System Users.phpp cross site scripting
- CVE-2023-20771 PoCCampcodes Online Traffic Offense Management System view_details.php cross site scripting
- CVE-2023-20891 PoCSourceCodester Complaint Management System GET Parameter userprofile.php sql injection
- CVE-2023-20901 PoCSourceCodester Employee and Visitor Gate Pass Logging System GET Parameter view_designation.php sql injection
- CVE-2023-20911 PoCKylinSoft youker-assistant adjust_cpufreq_scaling_governer os command injection
- CVE-2023-20921 PoCSourceCodester Vehicle Service Management System view_service.php sql injection
- CVE-2023-20931 PoCSourceCodester Vehicle Service Management System Login.php sql injection
- CVE-2023-20941 PoCSourceCodester Vehicle Service Management System manage_mechanic.php sql injection
- CVE-2023-20951 PoCSourceCodester Vehicle Service Management System manage_category.php sql injection
- CVE-2023-20961 PoCSourceCodester Vehicle Service Management System manage_inventory.php sql injection
- CVE-2023-20971 PoCSourceCodester Vehicle Service Management System Master.php sql injection
- CVE-2023-20981 PoCSourceCodester Vehicle Service Management System topBarNav.php cross site scripting
- CVE-2023-20991 PoCSourceCodester Vehicle Service Management System Users.php cross site scripting
- CVE-2023-21001 PoCSourceCodester Vehicle Service Management System index.php cross site scripting
- CVE-2023-21011 PoCmoxi624 Mogu Blog v2 uploadPicsByUrl uploadPictureByUrl absolute path traversal
- CVE-2023-21021 PoCCross-site Scripting (XSS) - Stored in alextselegidis/easyappointments
- CVE-2023-21031 PoCCross-site Scripting (XSS) - Stored in alextselegidis/easyappointments
- CVE-2023-21051 PoCSession Fixation in alextselegidis/easyappointments
- CVE-2023-21071 PoCIBOS del&op=recycle sql injection
- CVE-2023-21081 PoCSourceCodester Judging Management System edit_contestant.php sql injection
- CVE-2023-21101 PoCObsidian Local File Disclosure
- CVE-2023-21111 PoCHollerBox < 2.1.4 - Admin+ SQL Injection
- CVE-2023-21131 PoCAutoptimize < 3.1.7 - Admin+ Stored Cross-Site Scripting via Settings Import
- CVE-2023-21143 PoCsNEX-Forms < 8.4 - Admin+ SQL Injection
- CVE-2023-21171 PoCImage Optimizer by 10web < 1.0.27 - Admin+ Path Traversal
- CVE-2023-21222 PoCsImage Optimizer by 10web < 1.0.27 - Reflected Cross-Site Scripting
- CVE-2023-21233 PoCsWP Inventory Manager < 2.1.0.13 - Reflected Cross-Site Scripting
- CVE-2023-21302 PoCsSourceCodester Purchase Order Management System GET Parameter view_details.php sql injection
- CVE-2023-21431 PoCEnable SVG, WebP & ICO Upload <= 1.0.3 - Author+ Stored XSS
- CVE-2023-21441 PoCCampcodes Online Thesis Archiving System view_department.php sql injection
- CVE-2023-21451 PoCCampcodes Online Thesis Archiving System projects_per_curriculum.php sql injection
- CVE-2023-21461 PoCCampcodes Online Thesis Archiving System Master.php sql injection
- CVE-2023-21471 PoCCampcodes Online Thesis Archiving System view_details.php sql injection
- CVE-2023-21481 PoCCampcodes Online Thesis Archiving System view_curriculum.php sql injection
- CVE-2023-21491 PoCCampcodes Online Thesis Archiving System manage_user.php sql injection
- CVE-2023-21501 PoCSourceCodester Task Reminder System Master.php sql injection
- CVE-2023-21511 PoCSourceCodester Student Study Center Desk Management System manage_student.php sql injection
- CVE-2023-21521 PoCSourceCodester Student Study Center Desk Management System index.php file inclusion
- CVE-2023-21531 PoCSourceCodester Complaint Management System POST Parameter editable_ajax.php cross site scripting
- CVE-2023-21541 PoCSourceCodester Task Reminder System sql injection
- CVE-2023-21551 PoCSourceCodester Air Cargo Management System cross site scripting
- CVE-2023-21601 PoCWeak Password Requirements in modoboa/modoboa
- CVE-2023-21631 PoCIncorrect Verifier Branch Pruning Logic Leads To Arbitrary Read/Write In Linux Kernel and Lateral Privilege Escalation
- CVE-2023-21641 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2023-21782 PoCsAajoda Testimonials < 2.2.2 - Admin+ Stored XSS
- CVE-2023-21791 PoCWooCommerce Order Status Change Notifier <= 1.1.0 - Subscriber+ Arbitrary Order Status Update
- CVE-2023-21801 PoCKIWIZ Invoices Certification & PDF System <= 2.1.3 - Unauthenticated Arbitrary File Download
- CVE-2023-21832 PoCsGrafana is an open-source platform for monitoring and observability. The option to send a test alert is not available from the user panel…
- CVE-2023-21901 PoCAuthorization Bypass Through User-Controlled Key in GitLab
- CVE-2023-21911 PoCCross-site Scripting (XSS) - Stored in azuracast/azuracast
- CVE-2023-22001 PoCImproper Encoding or Escaping of Output in GitLab
- CVE-2023-22041 PoCCampcodes Retro Basketball Shoes Online Store faqs.php sql injection
- CVE-2023-22051 PoCCampcodes Retro Basketball Shoes Online Store login.php sql injection
- CVE-2023-22061 PoCCampcodes Retro Basketball Shoes Online Store contactus.php sql injection
- CVE-2023-22071 PoCCampcodes Retro Basketball Shoes Online Store contactus1.php sql injection
- CVE-2023-22081 PoCCampcodes Retro Basketball Shoes Online Store details.php sql injection
- CVE-2023-22091 PoCCampcodes Coffee Shop POS System view_details.php sql injection
- CVE-2023-22101 PoCCampcodes Coffee Shop POS System view_category.php sql injection
- CVE-2023-22111 PoCCampcodes Coffee Shop POS System manage_category.php sql injection
- CVE-2023-22121 PoCCampcodes Coffee Shop POS System view_product.php sql injection
- CVE-2023-22131 PoCCampcodes Coffee Shop POS System manage_product.php sql injection
- CVE-2023-22141 PoCCampcodes Coffee Shop POS System manage_sale.php sql injection
- CVE-2023-22152 PoCsCampcodes Coffee Shop POS System manage_user.php sql injection
- CVE-2023-22161 PoCCampcodes Coffee Shop POS System Users.php cross site scripting
- CVE-2023-22171 PoCSourceCodester Task Reminder System manage_reminder.php sql injection
- CVE-2023-22181 PoCSourceCodester Task Reminder System manage_user.php sql injection
- CVE-2023-22191 PoCSourceCodester Task Reminder System Users.php cross site scripting
- CVE-2023-22211 PoCWP Custom Cursors < 3.2 - Admin+ SQLi
- CVE-2023-22232 PoCsLogin Rebuilder < 2.8.1 - Admin+ Stored XSS
- CVE-2023-22243 PoCsSeo By 10Web < 1.2.7 - Admin+ Stored XSS
- CVE-2023-22251 PoCSEO ALert <= 1.59 - Admin+ Stored XSS
- CVE-2023-22272 PoCsImproper Authorization in modoboa/modoboa
- CVE-2023-22281 PoCCross-Site Request Forgery (CSRF) in modoboa/modoboa
- CVE-2023-22331 PoCMissing Authorization in GitLab
- CVE-2023-22351 PoCUse-after-free in Linux kernel's Performance Events subsystem
- CVE-2023-22361 PoCUse-after-free in Linux kernel's Performance Events subsystem
- CVE-2023-22411 PoCPoDoFo PdfXRefStreamParserObject.cpp readXRefStreamEntry heap-based overflow
- CVE-2023-22421 PoCSourceCodester Online Computer and Laptop Store GET Parameter sql injection
- CVE-2023-22431 PoCSourceCodester Complaint Management System POST Parameter registration.php sql injection
- CVE-2023-22441 PoCSourceCodester Online Eyewear Shop GET Parameter update_status.php sql injection
- CVE-2023-22451 PoChansunCMS unrestricted upload
- CVE-2023-22462 PoCsSourceCodester Online Pizza Ordering System unrestricted upload
- CVE-2023-22511 PoCUncaught Exception in eemeli/yaml
- CVE-2023-22522 PoCsDirectorist < 7.5.4 - Admin+ LFI
- CVE-2023-22541 PoCKo-fi Button < 1.3.3 - Admin+ Stored XSS
- CVE-2023-22553 PoCsRemote documents loaded without prompt via IFrame
- CVE-2023-22562 PoCsProduct Addons & Fields for WooCommerce < 32.0.7 - Reflected Cross-Site Scripting
- CVE-2023-22591 PoCImproper Neutralization of Special Elements Used in a Template Engine in alfio-event/alf.io
- CVE-2023-22711 PoCTiempo.com <= 0.1.2 - Shortcode Deletion via CSRF
- CVE-2023-22722 PoCsTiempo.com <= 0.1.2 - Reflected XSS
- CVE-2023-22871 PoCOrbit Fox < 2.10.24 - Author+ Server-Side Request Forgery
- CVE-2023-22881 PoCOtter - Gutenberg Blocks < 2.2.6 - Author+ PHAR Deserialization
- CVE-2023-22911 PoCStatic credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager…
- CVE-2023-22931 PoCSourceCodester Purchase Order Management System cross site scripting
- CVE-2023-22941 PoCUCMS Column Configuration saddpost.php cross site scripting
- CVE-2023-22961 PoCLoginizer 1.7.8 - Reflected XSS
- CVE-2023-22971 PoCProfile Builder – User Profile & User Registration Forms <= 3.9.0 - Insecure Password Reset Mechanism
- CVE-2023-23071 PoCCross-Site Request Forgery (CSRF) in builderio/qwik
- CVE-2023-23092 PoCswpForo Forum < 2.1.9 - Reflected Cross-Site Scripting
- CVE-2023-23151 PoCPath Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2
- CVE-2023-23161 PoCTypora Local File Disclosure
- CVE-2023-23171 PoCTypora DOM-Based Cross-site Scripting leading to Remote Code Execution
- CVE-2023-23182 PoCsMarkText DOM-Based Cross-site Scripting leading to Remote Code Execution
- CVE-2023-23201 PoCCF7 Google Sheets Connector < 5.0.2 - Reflected XSS
- CVE-2023-23211 PoCWPForms Google Sheet Connector < 3.4.6 - Reflected XSS
- CVE-2023-23221 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2023-23231 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2023-23241 PoCElementor Forms Google Sheet Connector < 1.0.7 - Reflected XSS
- CVE-2023-23261 PoCGravity Forms Google Sheet Connector < 1.3.5 - Access Code Update via CSRF
- CVE-2023-23271 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2023-23281 PoCCross-site Scripting (XSS) - Generic in pimcore/pimcore
- CVE-2023-23291 PoCWooCommerce Google Sheet Connector < 1.3.6 - Access Code Update via CSRF
- CVE-2023-23301 PoCCaldera Forms Google Sheets Connector < 1.3 - Access Code Update via CSRF
- CVE-2023-23331 PoCNinja Forms Google Sheet Connector < 1.2.7 - Reflected XSS
- CVE-2023-23341 PoCEasy Digital Downloads Google Sheet Connector < 1.6.6 - Access Code Update via CSRF
- CVE-2023-23361 PoCPath Traversal in pimcore/pimcore
- CVE-2023-23371 PoCConvertKit < 2.2.1 - Reflected XSS
- CVE-2023-23381 PoCSQL Injection in pimcore/pimcore
- CVE-2023-23391 PoCCross-site Scripting (XSS) - Reflected in pimcore/pimcore
- CVE-2023-23401 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2023-23411 PoCCross-site Scripting (XSS) - Generic in pimcore/pimcore
- CVE-2023-23421 PoCCross-site Scripting (XSS) - Reflected in pimcore/pimcore
- CVE-2023-23431 PoCCross-site Scripting (XSS) - DOM in pimcore/pimcore
- CVE-2023-23441 PoCSourceCodester Service Provider Management System HTTP POST Request sql injection
- CVE-2023-23461 PoCSourceCodester Service Provider Management System view_inquiry.php sql injection
- CVE-2023-23471 PoCSourceCodester Service Provider Management System manage_service.php sql injection
- CVE-2023-23481 PoCSourceCodester Service Provider Management System manage_user.php sql injection
- CVE-2023-23491 PoCSourceCodester Service Provider Management System index.php cross site scripting
- CVE-2023-23501 PoCSourceCodester Service Provider Management System Users.php cross site scripting
- CVE-2023-23562 PoCsRelative Path Traversal in mlflow/mlflow
- CVE-2023-23591 PoCRevolution Slider <= 6.6.12 - Author+ Remote Code Execution
- CVE-2023-23611 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2023-23621 PoCMultiple Plugins from Wow-Company - Reflected XSS
- CVE-2023-23631 PoCSourceCodester Resort Reservation System view_room.php sql injection
- CVE-2023-23641 PoCSourceCodester Resort Reservation System registration.php cross site scripting
- CVE-2023-23651 PoCSourceCodester Faculty Evaluation System sql injection
- CVE-2023-23661 PoCSourceCodester Faculty Evaluation System sql injection
- CVE-2023-23671 PoCSourceCodester Faculty Evaluation System manage_academic.php sql injection
- CVE-2023-23681 PoCSourceCodester Faculty Evaluation System sql injection
- CVE-2023-23691 PoCSourceCodester Faculty Evaluation System manage_restriction.php sql injection
- CVE-2023-23701 PoCSourceCodester Online DJ Management System GET Parameter manage_event.php sql injection
- CVE-2023-23711 PoCSourceCodester Online DJ Management System GET Parameter view_details.php sql injection
- CVE-2023-23721 PoCSourceCodester Online DJ Management System cross site scripting
- CVE-2023-23731 PoCUbiquiti EdgeRouter X Web Management command injection
- CVE-2023-23741 PoCUbiquiti EdgeRouter X Web Management command injection
- CVE-2023-23752 PoCsUbiquiti EdgeRouter X Web Management command injection
- CVE-2023-23761 PoCUbiquiti EdgeRouter X Web Management command injection
- CVE-2023-23771 PoCUbiquiti EdgeRouter X Web Management command injection
- CVE-2023-23781 PoCUbiquiti EdgeRouter X Web Management command injection
- CVE-2023-23791 PoCUbiquiti EdgeRouter X Web Service denial of service
- CVE-2023-23801 PoCNetgear SRX5308 denial of service
- CVE-2023-23811 PoCNetgear SRX5308 Web Management Interface cross site scripting
- CVE-2023-23821 PoCNetgear SRX5308 Web Management Interface cross site scripting
- CVE-2023-23831 PoCNetgear SRX5308 Web Management Interface cross site scripting
- CVE-2023-23841 PoCNetgear SRX5308 Web Management Interface cross site scripting
- CVE-2023-23851 PoCNetgear SRX5308 Web Management Interface cross site scripting
- CVE-2023-23861 PoCNetgear SRX5308 Web Management Interface cross site scripting
- CVE-2023-23871 PoCNetgear SRX5308 Web Management Interface cross site scripting
- CVE-2023-23881 PoCNetgear SRX5308 Web Management Interface cross site scripting
- CVE-2023-23891 PoCNetgear SRX5308 Web Management Interface cross site scripting
- CVE-2023-23901 PoCNetgear SRX5308 Web Management Interface cross site scripting
- CVE-2023-23911 PoCNetgear SRX5308 Web Management Interface cross site scripting
- CVE-2023-23921 PoCNetgear SRX5308 Web Management Interface cross site scripting
- CVE-2023-23931 PoCNetgear SRX5308 Web Management Interface cross site scripting
- CVE-2023-23941 PoCNetgear SRX5308 Web Management Interface cross site scripting
- CVE-2023-23951 PoCNetgear SRX5308 Web Management Interface cross site scripting
- CVE-2023-23961 PoCNetgear SRX5308 Web Management Interface cross site scripting
- CVE-2023-23971 PoCSourceCodester Simple Mobile Comparison Website cross site scripting
- CVE-2023-23981 PoCIcegram Engage < 3.1.12 - Reflected XSS
- CVE-2023-23991 PoCqubotchat < 1.1.6 - Unauthenticated Stored XSS
- CVE-2023-24011 PoCQubotchat < 1.1.6 – Admin+ Stored XSS
- CVE-2023-24041 PoCCRM and Lead Management by vcita <= 2.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
- CVE-2023-24051 PoCCRM and Lead Management by vcita <= 2.7.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting
- CVE-2023-24061 PoCEvent Registration Calendar By vcita <= 1.3.1 & Online Payments – Get Paid with PayPal, Square & Stripe <= 3.9.1 - Authenticated…
- CVE-2023-24071 PoCEvent Registration Calendar By vcita <= 1.3.1 & Online Payments – Get Paid with PayPal, Square & Stripe <= 3.10.0 - Cross-Site Request…
- CVE-2023-24081 PoCSourceCodester AC Repair and Services System view.php sql injection
- CVE-2023-24091 PoCSourceCodester AC Repair and Services System view_service.php sql injection
- CVE-2023-24101 PoCSourceCodester AC Repair and Services System view_booking.php sql injection
- CVE-2023-24111 PoCSourceCodester AC Repair and Services System view_inquiry.php sql injection
- CVE-2023-24121 PoCSourceCodester AC Repair and Services System manage_user.php sql injection
- CVE-2023-24131 PoCSourceCodester AC Repair and Services System manage_booking.php sql injection
- CVE-2023-24151 PoCOnline Booking & Scheduling Calendar for WordPress by vcita <= 4.2.10 - Missing Authorization to Account Logout
- CVE-2023-24161 PoCOnline Booking & Scheduling Calendar for WordPress by vcita <= 4.5 - Cross-Site Request Forgery to Account Logout
- CVE-2023-24171 PoCks-soft Advanced Host Monitor rma_active.exe unquoted search path
- CVE-2023-24181 PoCKonga Login API random values
- CVE-2023-24191 PoCZhong Bang CRMEB SystemAttachmentServices.php videoUpload unrestricted upload
- CVE-2023-24201 PoCMLECMS common.func.php get_url sql injection
- CVE-2023-24241 PoCDedeCMS config.php UpDateMemberModCache unrestricted upload
- CVE-2023-24251 PoCSourceCodester Simple Student Information System Add New Course cross site scripting
- CVE-2023-24271 PoCCross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq
- CVE-2023-24373 PoCsUserPro <= 5.1.1 - Authentication Bypass to Administrator
- CVE-2023-24511 PoCSourceCodester Online DJ Management System GET Parameter view_details.php sql injection
- CVE-2023-24701 PoCAdd to Feedly <= 1.2.11 - Admin+ Stored XSS
- CVE-2023-24721 PoCNewsletter, SMTP, Email marketing and Subscribe forms by Sendinblue < 3.1.61 - Reflected XSS
- CVE-2023-24741 PoCRebuild cross-site request forgery
- CVE-2023-24751 PoCDromara J2eeFAST System Message cross site scripting
- CVE-2023-24761 PoCDromara J2eeFAST Announcement cross site scripting
- CVE-2023-24771 PoCFunadmin Cx.php tagLoad cross site scripting
- CVE-2023-24791 PoCOS Command Injection in appium/appium-desktop
- CVE-2023-24821 PoCResponsive CSS EDITOR <= 1.0 - Admin+ SQLi
- CVE-2023-24881 PoCStop Spammers Security < 2023 - Reflected XSS
- CVE-2023-24891 PoCStop Spammers Security < 2023 - Admin+ Stored XSS
- CVE-2023-24921 PoCQueryWall: Plug'n Play Firewall <= 1.1.1 - Admin+ SQLi
- CVE-2023-24931 PoCAll In One Redirection < 2.2.0 - Admin+ SQLi
- CVE-2023-24951 PoCGreeklish-permalink < 3.5 - Unauthenticated Post Slug Update
- CVE-2023-25031 PoC10WebSocial < 1.2.9 - Reflected XSS
- CVE-2023-25071 PoCCleverTap Cordova Plugin 2.6.2 - Reflected XSS
- CVE-2023-25162 PoCsCross-site Scripting (XSS) - Stored in nilsteampassnet/teampass
- CVE-2023-25182 PoCsEasy Forms for Mailchimp < 6.8.9 - Reflected XSS
- CVE-2023-25221 PoCChengdu VEC40G Network Detection os command injection
- CVE-2023-25234 PoCsWeaver E-Office unrestricted upload
- CVE-2023-25271 PoCIntegration for Contact Form 7 and Zoho CRM, Bigin < 1.2.4 - Admin+ SQLi
- CVE-2023-25291 PoCEnable SVG Uploads <= 2.1.5 - Author+ Stored XSS via SVG
- CVE-2023-25311 PoCImproper Restriction of Excessive Authentication Attempts in azuracast/azuracast
- CVE-2023-25501 PoCCross-site Scripting (XSS) - Stored in thorsten/phpmyfaq
- CVE-2023-25511 PoCPHP Remote File Inclusion in unilogies/bumsys
- CVE-2023-25521 PoCCross-Site Request Forgery (CSRF) in unilogies/bumsys
- CVE-2023-25531 PoCCross-site Scripting (XSS) - Stored in unilogies/bumsys
- CVE-2023-25541 PoCExternal Control of File Name or Path in unilogies/bumsys
- CVE-2023-25601 PoCjja8 NewBingGoGo cross site scripting
- CVE-2023-25641 PoCOS Command Injection in sbs20/scanservjs
- CVE-2023-25651 PoCSourceCodester Multi Language Hotel Management Software POST Parameter ajax.php cross site scripting
- CVE-2023-25661 PoCCross-site Scripting (XSS) - Stored in openemr/openemr
- CVE-2023-25681 PoCPhoto Gallery by Ays < 5.1.7 - Reflected XSS
- CVE-2023-25711 PoCQuiz Maker < 6.4.2.7 - Reflected XSS
- CVE-2023-25721 PoCSurvey Maker < 3.4.7 - Reflected XSS
- CVE-2023-25732 PoCsAuthenticated Command Injection
- CVE-2023-25742 PoCsAuthenticated Command Injection
- CVE-2023-25752 PoCsAuthenticated Buffer Overflow
- CVE-2023-25761 PoCIncorrect Authorization in GitLab
- CVE-2023-25781 PoCBuy Me a Coffee < 3.7 - Admin+ Stored XSS
- CVE-2023-25793 PoCsInventoryPress <= 1.7 - Author+ Stored XSS
- CVE-2023-25801 PoCAI-Engine < 1.6.83 - Admin+ Stored XSS
- CVE-2023-25821 PoCA prototype pollution vulnerability exists in Strikingly CMS which can result in reflected cross-site scripting (XSS) in affected…
- CVE-2023-25831 PoCCode Injection in jsreport/jsreport
- CVE-2023-25901 PoCMissing Authorization in answerdev/answer
- CVE-2023-25912 PoCsImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in nilsteampassnet/teampass
- CVE-2023-25921 PoCFormCraft Premium < 3.9.7 - Admin+ SQLi
- CVE-2023-25941 PoCSourceCodester Food Ordering Management System Registration sql injection
- CVE-2023-25951 PoCSourceCodester Billing Management System POST Parameter ajax_service.php sql injection
- CVE-2023-25961 PoCSourceCodester Online Reviewer System GET Parameter user-update.php sql injection
- CVE-2023-25989 PoCsA flaw was found in the fixed buffer registration code for io_uring (io_sqe_buffer_register in io_uring/rsrc.c) in the Linux kernel that…
- CVE-2023-26001 PoCCustom Base Terms < 1.0.3 - Admin+ Stored XSS
- CVE-2023-26012 PoCsWP Brutal AI < 2.0.0 - SQL Injection via CSRF
- CVE-2023-26031 PoCA vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input…
- CVE-2023-26052 PoCsWP Brutal AI < 2.0.1 - Admin+ Reflected XSS
- CVE-2023-26061 PoCWP Brutal AI < 2.06 - Admin+ Stored XSS
- CVE-2023-26091 PoCNULL Pointer Dereference in vim/vim
- CVE-2023-26101 PoCInteger Overflow or Wraparound in vim/vim
- CVE-2023-26141 PoCCross-site Scripting (XSS) - DOM in pimcore/pimcore
- CVE-2023-26151 PoCCross-site Scripting (XSS) - Reflected in pimcore/pimcore
- CVE-2023-26161 PoCCross-site Scripting (XSS) - Generic in pimcore/pimcore
- CVE-2023-26171 PoCOpenCV wechat_qrcode Module decoded_bit_stream_parser.cpp decodeByteSegment null pointer dereference
- CVE-2023-26191 PoCSourceCodester Online Tours & Travels Management System disapprove_delete.php exec sql injection
- CVE-2023-26201 PoCInsertion of Sensitive Information Into Sent Data in GitLab
- CVE-2023-26231 PoCKiviCare Management System < 3.2.1 - Subscriber+ Sensitive Information Disclosure
- CVE-2023-26243 PoCsKiviCare Management System < 3.2.1 - Reflected Cross-Site Scripting
- CVE-2023-26271 PoCKiviCare Management System < 3.2.1 - Subscriber+ Unauthorised AJAX Calls
- CVE-2023-26281 PoCKiviCare Management System < 3.2.1 - Multiple CSRF
- CVE-2023-26291 PoCImproper Neutralization of Formula Elements in a CSV File in pimcore/customer-data-framework
- CVE-2023-26301 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2023-26341 PoCGet Your Number <= 1.1.3 - Admin+ Stored XSS
- CVE-2023-26351 PoCCall Now Accessibility Button < 1.1 - Admin+ Stored XSS
- CVE-2023-26363 PoCsAN_GradeBook <= 5.0.1 - Subscriber+ SQLi
- CVE-2023-264019 PoCsOn Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an…
- CVE-2023-26411 PoCSourceCodester Online Internship Management System POST Parameter login.php sql injection
- CVE-2023-26421 PoCSourceCodester Online Exam System GET Parameter updateCourse.php sql injection
- CVE-2023-26431 PoCSourceCodester File Tracker Manager System POST Parameter update_password.php sql injection
- CVE-2023-26451 PoCUSR USR-G806 Web Management Page hard-coded password
- CVE-2023-26471 PoCWeaver E-Office File Upload utility_all.php command injection
- CVE-2023-26485 PoCsWeaver E-Office uploadify.php unrestricted upload
- CVE-2023-26491 PoCTenda AC23 Service Port 7329 ate command injection
- CVE-2023-26521 PoCSourceCodester Lost and Found Information System sql injection
- CVE-2023-26531 PoCSourceCodester Lost and Found Information System index.php sql injection
- CVE-2023-26541 PoCConditional Menus < 1.2.1 - Reflected XSS
- CVE-2023-26551 PoCContact Form by WD <= 1.13.23 - Admin+ SQLi
- CVE-2023-26561 PoCSourceCodester AC Repair and Services System sql injection
- CVE-2023-26571 PoCSourceCodester Online Computer and Laptop Store products.php cross site scripting
- CVE-2023-26581 PoCSourceCodester Online Computer and Laptop Store products.php sql injection
- CVE-2023-26591 PoCSourceCodester Online Computer and Laptop Store view_product.php sql injection
- CVE-2023-26601 PoCSourceCodester Online Computer and Laptop Store view_categories.php sql injection
- CVE-2023-26611 PoCSourceCodester Online Computer and Laptop Store Master.php sql injection
- CVE-2023-26671 PoCSourceCodester Lost and Found Information System cross site scripting
- CVE-2023-26681 PoCSourceCodester Lost and Found Information System GET Parameter manager_category sql injection
- CVE-2023-26691 PoCSourceCodester Lost and Found Information System GET Parameter sql injection
- CVE-2023-26701 PoCSourceCodester Lost and Found Information System access control
- CVE-2023-26711 PoCSourceCodester Lost and Found Information System Contact Form cross site scripting
- CVE-2023-26721 PoCSourceCodester Lost and Found Information System GET Parameter view.php sql injection
- CVE-2023-26741 PoCImproper Access Control in openemr/openemr
- CVE-2023-26761 PoCH3C R160 aspForm stack-based overflow
- CVE-2023-26771 PoCSourceCodester Covid-19 Contact Tracing System manage.php sql injection
- CVE-2023-26781 PoCSourceCodester File Tracker Manager System POST Parameter save_user.php cross site scripting
- CVE-2023-26841 PoCFile Renaming on Upload < 2.5.2 - Admin+ Stored Cross-Site Scripting
- CVE-2023-26891 PoCSourceCodester Billing Management System GET Parameter editproduct.php sql injection
- CVE-2023-26901 PoCSourceCodester Personnel Property Equipment System GET Parameter returned_reuse_form.php sql injection
- CVE-2023-26911 PoCSourceCodester Personnel Property Equipment System POST Parameter add_item.php cross site scripting
- CVE-2023-26921 PoCSourceCodester ICT Laboratory Management System GET Parameter room_info.php cross site scripting
- CVE-2023-26931 PoCSourceCodester Online Exam System POST Parameter data sql injection
- CVE-2023-26941 PoCSourceCodester Online Exam System POST Parameter data sql injection
- CVE-2023-26951 PoCSourceCodester Online Exam System POST Parameter data sql injection
- CVE-2023-26961 PoCSourceCodester Online Exam System POST Parameter data sql injection
- CVE-2023-26971 PoCSourceCodester Online Exam System POST Parameter data sql injection
- CVE-2023-26981 PoCSourceCodester Lost and Found Information System GET Parameter sql injection
- CVE-2023-26991 PoCSourceCodester Lost and Found Information System GET Parameter sql injection
- CVE-2023-27011 PoCGravity Forms < 2.7.5 - Reflected XSS
- CVE-2023-27051 PoCAppointment booking addon for Gravity Forms < 1.10.0 - Reflected Cross-Site Scripting
- CVE-2023-27071 PoCAppointment booking addon for Gravity Forms <= 1.9.5.1 - Admin+ Stored XSS
- CVE-2023-27091 PoCAN_GradeBook <= 5.0.1 - Admin+ XSS
- CVE-2023-27111 PoCUltimate Product Catalog < 5.2.6 - Admin+ Stored XSS
- CVE-2023-27181 PoCContact Form Email < 1.3.38 - Unauthenticated Stored Cross-Site Scripting
- CVE-2023-27191 PoCSupportCandy < 3.1.7 - Subscriber+ SQLi
- CVE-2023-27281 PoCBypassing enforce mountable secrets policy imposed by the ServiceAccount admission plugin
- CVE-2023-27301 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2023-27311 PoCA NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local…
- CVE-2023-27325 PoCsMStore API <= 3.9.2 - Authentication Bypass
- CVE-2023-27341 PoCMStore API <= 3.9.1 - Authentication Bypass
- CVE-2023-27381 PoCTongda OA GatewayController.php actionGetdata unrestricted upload
- CVE-2023-27401 PoCSourceCodester Guest Management System GET Parameter dateTest.php cross site scripting
- CVE-2023-27421 PoCAI ChatBot < 4.5.5 - Admin+ Stored Cross-Site Scripting
- CVE-2023-27431 PoCWP ERP < 1.12.4 - Reflected Cross-Site Scripting
- CVE-2023-27443 PoCsWP ERP < 1.12.4 - Admin+ SQL Injection
- CVE-2023-27452 PoCsWordPress Core < 6.2.1 - Directory Traversal
- CVE-2023-27511 PoCUpload Resume <= 1.2.0 - Captcha Bypass
- CVE-2023-27561 PoCSQL Injection in pimcore/customer-data-framework
- CVE-2023-27581 PoCContec CONPROSYS HMI System (CHS) v3.5.2 Denial of Service
- CVE-2023-27611 PoCUser Activity Log < 1.6.3 - Admin+ SQL Injection
- CVE-2023-27651 PoCWeaver OA downfile.php absolute path traversal
- CVE-2023-27663 PoCsWeaver OA jx2_config.ini file access
- CVE-2023-27681 PoCSucms cross site scripting
- CVE-2023-27691 PoCSourceCodester Service Provider Management System sql injection
- CVE-2023-27701 PoCSourceCodester Online Exam System data sql injection
- CVE-2023-27711 PoCSourceCodester Online Exam System data sql injection
- CVE-2023-27721 PoCSourceCodester Budget and Expense Tracker System GET Parameter manage_budget.php sql injection
- CVE-2023-27731 PoCcode-projects Bus Dispatch and Information System view_admin.php sql injection
- CVE-2023-27741 PoCcode-projects Bus Dispatch and Information System view_branch.php sql injection
- CVE-2023-27751 PoCcode-projects Bus Dispatch and Information System adminHome.php sql injection
- CVE-2023-27794 PoCsSuper Socializer < 7.13.52 - Reflected XSS
- CVE-2023-27802 PoCsPath Traversal: '\..\filename' in mlflow/mlflow
- CVE-2023-27891 PoCGNU cflow parser.c parse_variable_declaration denial of service
- CVE-2023-27901 PoCTOTOLINK N200RE Telnet Service custom.conf password in configuration file
- CVE-2023-27951 PoCCodeColorer < 0.10.1 – Admin+ Stored Cross-Site Scripting
- CVE-2023-27963 PoCsEventON < 2.1.2 - Unauthenticated Event Access
- CVE-2023-27991 PoCcnoa OA hard-coded password
- CVE-2023-28021 PoCUltimate Addons for Contact Form 7 < 3.1.29 - Admin+ Stored XSS
- CVE-2023-28031 PoCUltimate Addons for Contact Form 7 < 3.1.29 - Reflected XSS
- CVE-2023-28041 PoCA heap-based buffer overflow issue was discovered in libjpeg-turbo in h2v2_merged_upsample_internal() function of jdmrgext.c file. The…
- CVE-2023-28051 PoCSupportCandy < 3.1.7 - Admin+ SQLi
- CVE-2023-28111 PoCAI ChatBot < 4.5.6 - Admin+ Stored Cross-Site Scripting
- CVE-2023-28121 PoCUltimate Dashboard < 3.7.6 - Admin+ Stored XSS
- CVE-2023-28132 PoCsMultiple Themes - Reflected XSS
- CVE-2023-28141 PoCSourceCodester Class Scheduling System POST Parameter save_teacher.php cross site scripting
- CVE-2023-28151 PoCSourceCodester Online Jewelry Store POST Parameter supplier.php sql injection
- CVE-2023-28224 PoCsEllucian Ethos Identity logout cross site scripting
- CVE-2023-28231 PoCSourceCodester Class Scheduling System GET Parameter edit_subject.php sql injection
- CVE-2023-28241 PoCSourceCodester Dental Clinic Appointment Reservation System POST Parameter service.php cross site scripting
- CVE-2023-282510 PoCsAn issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal…
- CVE-2023-28261 PoCSourceCodester Class Scheduling System POST Parameter search_teacher_result.php cross site scripting
- CVE-2023-28321 PoCSQL Injection in unilogies/bumsys
- CVE-2023-28331 PoCReviewX <= 1.6.13 - Arbitrary Usermeta Update to Authenticated (Subscriber+) Privilege Escalation
- CVE-2023-28351 PoCWP Directory Kit <= 1.2.3 - Reflected Cross-Site Scripting via 'search'
- CVE-2023-28361 PoCCRM Perks Forms <= 1.1.1 - Authenticated (Admin+) Stored Cross-Site Scripting
- CVE-2023-28371 PoCStack-based Buffer Overflow in gpac/gpac
- CVE-2023-28381 PoCOut-of-bounds Read in gpac/gpac
- CVE-2023-28391 PoCDivide By Zero in gpac/gpac
- CVE-2023-28401 PoCNULL Pointer Dereference in gpac/gpac
- CVE-2023-28421 PoCWP Inventory Manager < 2.1.0.14 - Inventory Items Deletion via CSRF
- CVE-2023-28431 PoCMultiParcels Shipping For WooCommerce < 1.14.15 - Subscribers+ SQLi
- CVE-2023-28441 PoCAuthorization Bypass Through User-Controlled Key in cloudexplorer-dev/cloudexplorer-lite
- CVE-2023-28451 PoCImproper Access Control in cloudexplorer-dev/cloudexplorer-lite
- CVE-2023-28521 PoCSQLi in SoftMed's SelfPatron
- CVE-2023-28592 PoCsCode Injection in nilsteampassnet/teampass
- CVE-2023-28631 PoCSimple Design Daily Journal SQLite Database cleartext storage in a file or on disk
- CVE-2023-28641 PoCSourceCodester Online Jewelry Store POST Parameter customer.php cross site scripting
- CVE-2023-28651 PoCSourceCodester Theme Park Ticketing System GET Parameter print_ticket.php sql injection
- CVE-2023-28685 PoCsKEVRemote Code injection in Barracuda Email Security Gateway
- CVE-2023-28702 PoCsEnTech Monitor Asset Manager IoControlCode 0x80002014 denial of service
- CVE-2023-28712 PoCsFabulaTech USB for Remote Desktop IoControlCode 0x220408 null pointer dereference
- CVE-2023-28722 PoCsFlexiHub IoControlCode fusbhub.sys 0x220088 null pointer dereference
- CVE-2023-28732 PoCsTwister Antivirus IoControlCode filppd.sys 0x80800043 memory corruption
- CVE-2023-28742 PoCsTwister Antivirus IoControlCode filppd.sys 0x804f2140 denial of service
- CVE-2023-28752 PoCseScan Antivirus IoControlCode PROCOBSRVESX.SYS 0x22E008u null pointer dereference
- CVE-2023-28772 PoCsFormidable Forms < 6.3.1 - Subscriber+ Remote Code Execution
- CVE-2023-28991 PoCGoogle Map Shortcode <= 3.1.2 - Contributor+ Stored XSS
- CVE-2023-29001 PoCNFine Rapid Development Platform CheckLogin weak hash
- CVE-2023-29011 PoCNFine Rapid Development Platform access control
- CVE-2023-29021 PoCNFine Rapid Development Platform access control
- CVE-2023-29031 PoCNFine Rapid Development Platform access control
- CVE-2023-29051 PoCCesanta Mongoose MQTT Message Parsing Heap Overflow
- CVE-2023-29062 PoCsWireshark CP2179 divide by zero
- CVE-2023-29081 PoCLibtiff: null pointer dereference in tif_dir.c
- CVE-2023-29151 PoCRockwell Automation ThinManager Thinserver Software Vulnerable to Input Validation Vulnerability
- CVE-2023-29161 PoCInfiniteWP Client <= 1.11.1 - Authenticated (Subscriber+) Sensitive Information Exposure
- CVE-2023-29171 PoCRockwell Automation ThinManager Thinserver Software Vulnerable to Input Validation Vulnerability
- CVE-2023-29211 PoCShort URL <= 1.6.8 - Subscriber+ SQLi
- CVE-2023-29221 PoCSourceCodester Comment System GET Parameter index.php cross site scripting
- CVE-2023-29231 PoCTenda AC6 fromDhcpListClient stack-based overflow
- CVE-2023-29241 PoCSupcon SimField reportupload.aspx unrestricted upload
- CVE-2023-29251 PoCWebkul krayin crm Edit Person Page 2 cross site scripting
- CVE-2023-29261 PoCSeaCMS Picture Upload member.php denial of service
- CVE-2023-29271 PoCJIZHICMS TemplateController.php index server-side request forgery
- CVE-2023-29282 PoCsDedeCMS article_allowurl_edit.php code injection
- CVE-2023-29421 PoCImproper Input Validation in openemr/openemr
- CVE-2023-29431 PoCCode Injection in openemr/openemr
- CVE-2023-29441 PoCImproper Access Control in openemr/openemr
- CVE-2023-29451 PoCMissing Authorization in openemr/openemr
- CVE-2023-29461 PoCImproper Access Control in openemr/openemr
- CVE-2023-29471 PoCCross-site Scripting (XSS) - Stored in openemr/openemr
- CVE-2023-29482 PoCsCross-site Scripting (XSS) - Generic in openemr/openemr
- CVE-2023-29492 PoCsCross-site Scripting (XSS) - Reflected in openemr/openemr
- CVE-2023-29501 PoCImproper Authorization in openemr/openemr
- CVE-2023-29512 PoCscode-projects Bus Dispatch and Information System delete_bus.php sql injection
- CVE-2023-29541 PoCCross-site Scripting (XSS) - Stored in liangliangyy/djangoblog
- CVE-2023-29551 PoCSourceCodester Students Online Internship Timesheet System GET Parameter rendered_report.php sql injection
- CVE-2023-29621 PoCSourceCodester Faculty Evaluation System sql injection
- CVE-2023-29641 PoCSimple Iframe < 1.2.0 - Contributor+ Stored XSS
- CVE-2023-29671 PoCTinyMCE Custom Styles < 1.1.4 - Admin+ Stored Cross-Site Scripting
- CVE-2023-29681 PoCUndefined variable usage in npm package "proxy" leads to remote denial of service
- CVE-2023-29711 PoCTypora Local File Disclosure
- CVE-2023-29721 PoCPrototype Pollution in antfu/utils
- CVE-2023-29731 PoCSourceCodester Students Online Internship Timesheet Syste cross site scripting
- CVE-2023-29781 PoCAbstrium Pydio Cells Change Subscription authorization
- CVE-2023-29791 PoCAbstrium Pydio Cells User Creation access control
- CVE-2023-29801 PoCAbstrium Pydio Cells User Creation resource injection
- CVE-2023-29811 PoCAbstrium Pydio Cells Chat cross site scripting
- CVE-2023-29825 PoCsWordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
- CVE-2023-29831 PoCPrivilege Defined With Unsafe Actions in pimcore/pimcore
- CVE-2023-29841 PoCPath Traversal: '\..\filename' in pimcore/pimcore
- CVE-2023-29863 PoCsAbandoned Cart Lite for WooCommerce <= 5.15.1 - Authentication Bypass
- CVE-2023-29891 PoCFortra Globalscape Administration Server Out of Bounds Memory Read
- CVE-2023-29901 PoCFortra Globalscape Administration Server Denial of Service
- CVE-2023-29911 PoCFortra Globalscape Administration Server Information Disclosure
- CVE-2023-29951 PoCLeyka < 3.30.4 - Admin+ Stored XSS
- CVE-2023-29961 PoCJetpack < 12.1.1 - Author+ Arbitrary File Manipulation via API