CVE-2023-30000 to CVE-2023-30999
93 CVEs with public proof-of-concept exploits.
- CVE-2023-300133 PoCsTOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg.…
- CVE-2023-300191 PoCimgproxy <=3.14.0 is vulnerable to Server-Side Request Forgery (SSRF) due to a lack of sanitization of the imageURL parameter.
- CVE-2023-300531 PoCTOTOLINK A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection.
- CVE-2023-300541 PoCTOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injection vulnerability. An attacker can obtain a stable root shell through a…
- CVE-2023-300611 PoCD-Link DIR-879 v105A1 is vulnerable to Authentication Bypass via phpcgi.
- CVE-2023-300822 PoCsA denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is…
- CVE-2023-300831 PoCBuffer Overflow vulnerability found in Libming swftophp v.0.4.8 allows a local attacker to cause a denial of service via the newVar_N in…
- CVE-2023-300841 PoCAn issue found in libming swftophp v.0.4.8 allows a local attacker to cause a denial of service via the stackVal function in…
- CVE-2023-300851 PoCBuffer Overflow vulnerability found in Libming swftophp v.0.4.8 allows a local attacker to cause a denial of service via the cws2fws…
- CVE-2023-300861 PoCBuffer Overflow vulnerability found in Libtiff V.4.0.7 allows a local attacker to cause a denial of service via the tiffcp function in…
- CVE-2023-300871 PoCBuffer Overflow vulnerability found in Cesanta MJS v.1.26 allows a local attacker to cause a denial of service via the mjs_mk_string…
- CVE-2023-300881 PoCAn issue found in Cesanta MJS v.1.26 allows a local attacker to cause a denial of service via the mjs_execute function in mjs.c.
- CVE-2023-300921 PoCSourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter.
- CVE-2023-300931 PoCA cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers to execute…
- CVE-2023-300942 PoCsA stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2023-300952 PoCsA stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or…
- CVE-2023-300962 PoCsA stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or…
- CVE-2023-300972 PoCsA stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or…
- CVE-2023-301231 PoCwuzhicms v4.1.0 is vulnerable to Cross Site Scripting (XSS) in the Member Center, Account Settings.
- CVE-2023-301351 PoCTenda AC18 v15.03.05.19(6318_)_cn was discovered to contain a command injection vulnerability via the deviceName parameter in the…
- CVE-2023-301453 PoCsCamaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter.
- CVE-2023-301461 PoCAssmann Digitus Plug&View IP Camera HT-IP211HDP, version 2.000.022 allows unauthenticated attackers to download a copy of the camera's…
- CVE-2023-301491 PoCSQL injection vulnerability in the City Autocomplete (cityautocomplete) module from ebewe.net for PrestaShop, prior to version 1.8.12 (for…
- CVE-2023-301501 PoCPrestaShop leocustomajax 1.0 and 1.0.0 are vulnerable to SQL Injection via modules/leocustomajax/leoajax.php.
- CVE-2023-301841 PoCA stored cross-site scripting (XSS) vulnerability in Typecho v1.2.0 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2023-301851 PoCCRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component…
- CVE-2023-301891 PoCPrestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook().
- CVE-2023-301911 PoCPrestaShop cdesigner < 3.1.9 is vulnerable to SQL Injection via CdesignerTraitementModuleFrontController::initContent().
- CVE-2023-301922 PoCsPrestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().
- CVE-2023-301942 PoCsPrestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook().
- CVE-2023-301981 PoCPrestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download.php.
- CVE-2023-302101 PoCOURPHP <= 7.2.0 is vulnerable to Cross Site Scripting (XSS) via ourphp_tz.php.
- CVE-2023-3021215 PoCsOURPHP <= 7.2.0 is vulnerale to Cross Site Scripting (XSS) via /client/manage/ourphp_out.php.
- CVE-2023-302261 PoCAn issue was discovered in function get_gnu_verneed in rizinorg Rizin prior to 0.5.0 verneed_entry allows attackers to cause a denial of…
- CVE-2023-302371 PoCCyberGhostVPN Windows Client before v8.3.10.10015 was discovered to contain a DLL injection vulnerability via the component Dashboard.exe.
- CVE-2023-3025311 PoCsDolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in…
- CVE-2023-302563 PoCsCross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back…
- CVE-2023-302571 PoCA buffer overflow in the component /proc/ftxxxx-debug of FiiO M6 Build Number v1.0.4 allows attackers to escalate privileges to root.
- CVE-2023-3025814 PoCsCommand Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via…
- CVE-2023-302591 PoCA Buffer Overflow vulnerability in importshp plugin in LibreCAD 2.2.0 allows attackers to obtain sensitive information via a crafted DBF…
- CVE-2023-303281 PoCAn issue in the helper tool of Mailbutler GmbH Shimo VPN Client for macOS v5.0.4 allows attackers to bypass authentication via PID re-use.
- CVE-2023-303302 PoCsSoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function…
- CVE-2023-303311 PoCAn issue in the render function of beetl v3.15.0 allows attackers to execute server-side template injection (SSTI) via a crafted payload.
- CVE-2023-303471 PoCCross Site Scripting (XSS) vulnerability in Neox Contact Center 2.3.9, via the serach_sms_api_name parameter to the SMA API search.
- CVE-2023-303491 PoCJFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function.
- CVE-2023-303502 PoCsFS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin password.
- CVE-2023-303621 PoCBuffer Overflow vulnerability in coap_send function in libcoap library 4.3.1-103-g52cfd56 fixed in 4.3.1-120-ge242200 allows attackers to…
- CVE-2023-303631 PoCvConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts.
- CVE-2023-303672 PoCsMulti-Remote Next Generation Connection Manager (mRemoteNG) is free software that enables users to store and manage multi-protocol…
- CVE-2023-303801 PoCAn issue in the component /dialog/select_media.php of DedeCMS v5.7.107 allows attackers to execute a directory traversal.
- CVE-2023-303991 PoCInsecure permissions in the settings page of GARO Wallbox GLB/GTB/GTC before v189 allows attackers to redirect users to a crafted update…
- CVE-2023-304021 PoCYASM v1.3.0 was discovered to contain a heap overflow via the function handle_dot_label at /nasm/nasm-token.re. Note: This has been…
- CVE-2023-304051 PoCA cross-site scripting (XSS) vulnerability in Aigital Wireless-N Repeater Mini_Router v0.131229 allows attackers to execute arbitrary web…
- CVE-2023-304151 PoCSourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at…
- CVE-2023-304581 PoCA username enumeration issue was discovered in Medicine Tracker System 1.0. The login functionality allows a malicious user to guess a…
- CVE-2023-304591 PoCSmartPTT SCADA 1.1.0.0 allows remote code execution (when the attacker has administrator privileges) by writing a malicious C# script and…
- CVE-2023-304861 PoCWordPress Square theme <= 2.0.0 - Broken Access Control
- CVE-2023-305331 PoCSheetJS Community Edition before 0.19.3 allows Prototype Pollution via a crafted file. In other words. 0.19.2 and earlier are affected,…
- CVE-2023-305342 PoCsInsecure Deserialization in Cacti
- CVE-2023-305371 PoCorg.xwiki.platform:xwiki-platform-flamingo-theme-ui vulnerable to privilege escalation
- CVE-2023-305478 PoCsSandbox Escape in vm2
- CVE-2023-305501 PoCIDOR vulnerability exists in metersphere
- CVE-2023-305701 PoCpluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1…
- CVE-2023-305771 PoCAMANDA (Advanced Maryland Automatic Network Disk Archiver) before tag-community-3.5.4 mishandles argument checking for runtar.c, a…
- CVE-2023-306202 PoCsArbitrary File Write when Extracting a Remotely retrieved Tarball in mindsdb/mindsdb
- CVE-2023-306231 PoCArbitrary command injection in embano1/wip
- CVE-2023-306253 PoCsrudder-server vulnerable to SQL Injection
- CVE-2023-306281 PoCKiwi TCMS has command injection vulnerability in changelog.yml CI workflow
- CVE-2023-307651 PoCDelta Electronics InfraSuite Device Master Improper Access Control
- CVE-2023-307741 PoCA vulnerability was found in the libtiff library. This flaw causes a heap buffer overflow issue via the TIFFTAG_INKNAMES and…
- CVE-2023-307773 PoCsWordPress Advanced Custom Fields / Advanced Custom Fields PRO plugins <= 6.1.5 vulnerable to Cross Site Scripting (XSS)
- CVE-2023-307871 PoCMonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the…
- CVE-2023-307881 PoCMonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people/add`…
- CVE-2023-307891 PoCMonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the…
- CVE-2023-307901 PoCMonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the…
- CVE-2023-307992 PoCsMikroTik RouterOS Administrator Privilege Escalation
- CVE-2023-308004 PoCsMikroTik RouterOS Web Interface Heap Corruption
- CVE-2023-308021 PoCSangfor Next-Gen Application Firewall Source Code Disclosure
- CVE-2023-308031 PoCSangfor Next-Gen Application Firewall Authentication Bypass
- CVE-2023-308041 PoCSangfor Next-Gen Application Firewall Authenticated File Disclosure
- CVE-2023-308051 PoCSangfor Next-Gen Application Firewall Login Un Param Command Injection
- CVE-2023-308061 PoCSangfor Next-Gen Application Firewall PHPSESSID Command Injection
- CVE-2023-308391 PoCPrestaShop vulnerable to SQL filter bypass leading to arbitrary write requests using "SQL Manager"
- CVE-2023-308431 PoCPayload's hidden fields can be leaked on readable collections
- CVE-2023-308451 PoCESPv2 vulnerable to JWT authentication bypass via `X-HTTP-Method-Override` header
- CVE-2023-308541 PoCWWBN AVideo vulnerable to OS Command Injection
- CVE-2023-308591 PoCSpigot Command Exploit in Triton
- CVE-2023-308602 PoCsWWBN/AVideo stored XSS vulnerability leads to takeover of any user's account, including admin's account
- CVE-2023-308611 PoCFlask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header
- CVE-2023-308682 PoCsWordPress CMS Tree Page View Plugin <= 1.6.7 is vulnerable to Cross Site Scripting (XSS)
- CVE-2023-308691 PoCWordPress Easy Digital Downloads Plugin 3.1-3.1.1.4.1 is vulnerable to Privilege Escalation
- CVE-2023-309434 PoCsMoodle: tinymce loaders susceptible to arbitrary folder creation
- CVE-2023-309901 PoCIBM i command execution