CVE-2023-32000 to CVE-2023-32999
58 CVEs with public proof-of-concept exploits.
- CVE-2023-320071 PoCApache Spark: Shell command injection via Spark UI
- CVE-2023-320311 PoCMicrosoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-320681 PoCURL Redirection to Untrusted Site in XWiki
- CVE-2023-320701 PoCImproper Neutralization of Script in Attributes in XWiki (X)HTML renderers
- CVE-2023-320733 PoCsAVideo command injection vulnerability
- CVE-2023-320771 PoCNetmaker has Hardcoded DNS Secret Key
- CVE-2023-321172 PoCsWordPress Integrate Google Drive plugin <= 1.1.99 - Unauthenticated Broken Access Control vulnerability
- CVE-2023-321831 PoCIncorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hacluster to escalate…
- CVE-2023-321841 PoCA Insecure Storage of Sensitive Information vulnerability in openSUSE opensuse-welcome allows local attackers to execute code as the user…
- CVE-2023-322339 PoCsIn the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform…
- CVE-2023-322354 PoCsGhost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/…
- CVE-2023-3224311 PoCsWordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
- CVE-2023-322711 PoCAn information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS…
- CVE-2023-322751 PoCAn information disclosure vulnerability exists in the CtEnumCa() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. Specially…
- CVE-2023-322841 PoCAn out-of-bounds write vulnerability exists in the tiff_planar_adobe functionality of Accusoft ImageGear 20.1. A specially crafted…
- CVE-2023-323092 PoCsArbitrary file inclusion with the pymdowm-snippets extension
- CVE-2023-323131 PoCInspect method manipulation in vm2
- CVE-2023-323142 PoCsSandbox Escape
- CVE-2023-3231521 PoCsKEVOpenfire administration console authentication bypass
- CVE-2023-323221 PoCArbitrary file read in Ombi
- CVE-2023-323241 PoCOpenPrinting CUPS vulnerable to heap buffer overflow
- CVE-2023-323531 PoCA logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.9 for Windows. An app may be able to elevate…
- CVE-2023-323641 PoCA logic issue was addressed with improved restrictions. This issue is fixed in macOS Ventura 13.5. A sandboxed process may be able to…
- CVE-2023-324071 PoCA logic issue was addressed with improved state management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6…
- CVE-2023-324131 PoCA race condition was addressed with improved state handling. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6…
- CVE-2023-324221 PoCThis issue was addressed by adding additional SQLite logging restrictions. This issue is fixed in iOS 16.5 and iPadOS 16.5, tvOS 16.5,…
- CVE-2023-324281 PoCThis issue was addressed with improved file handling. This issue is fixed in macOS Ventura 13.4, tvOS 16.5, iOS 16.5 and iPadOS 16.5,…
- CVE-2023-324346 PoCsKEVAn integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7…
- CVE-2023-325211 PoCA path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated…
- CVE-2023-325221 PoCA path traversal exists in a specific dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an authenticated remote…
- CVE-2023-325411 PoCA use-after-free vulnerability exists in the footerr functionality of Hancom Office 2020 HWord 11.0.0.7520. A specially crafted .doc file…
- CVE-2023-325604 PoCsAn attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary…
- CVE-2023-325631 PoCAn unauthenticated attacker could achieve the code execution through a RemoteControl server.
- CVE-2023-325713 PoCsDynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted input to methods…
- CVE-2023-325902 PoCsWordPress Subscribe to Category Plugin <= 2.7.4 is vulnerable to SQL Injection
- CVE-2023-326141 PoCA heap-based buffer overflow vulnerability exists in the create_png_object functionality of Accusoft ImageGear 20.1. A specially crafted…
- CVE-2023-326161 PoCA use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles 3D annotations. A specially crafted Javascript code…
- CVE-2023-3262915 PoCsLocal privilege escalation vulnerability in Ubuntu Kernels overlayfs ovl_copy_up_meta_inode_data skip permission checks when calling…
- CVE-2023-326341 PoCAn authentication bypass vulnerability exists in the CiRpcServerThread() functionality of SoftEther VPN 5.01.9674 and 4.41-9782-beta. An…
- CVE-2023-326531 PoCAn out-of-bounds write vulnerability exists in the dcm_pixel_data_decode functionality of Accusoft ImageGear 20.1. A specially crafted…
- CVE-2023-326641 PoCA type confusion vulnerability exists in the Javascript checkThisBox method as implemented in Foxit Reader 12.1.2.15332. Specially crafted…
- CVE-2023-326731 PoCCertain versions of HP PC Hardware Diagnostics Windows, HP Image Assistant, and HP Thunderbolt Dock G2 Firmware are potentially vulnerable…
- CVE-2023-326792 PoCsRemote Code Execution via unrestricted file extension in Craft CMS
- CVE-2023-326811 PoCUnintended leak of Proxy-Authorization header in requests
- CVE-2023-326971 PoCSqlite-jdbc vulnerable to remote code execution when JDBC url is attacker controlled
- CVE-2023-326982 PoCsnfpm vulnerable to Incorrect Default Permissions
- CVE-2023-326991 PoCMeterSphere denial of service vulnerability
- CVE-2023-327074 PoCs‘edit_user’ Capability Privilege Escalation
- CVE-2023-327496 PoCsPydio Cells allows users by default to create so-called external users in order to share files with them. By modifying the HTTP request…
- CVE-2023-327502 PoCsPydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the…
- CVE-2023-327512 PoCsPydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are generated using the…
- CVE-2023-327671 PoCThe web interface of Symcon IP-Symcon before 6.3 (i.e., before 2023-05-12) allows a remote attacker to read sensitive files via ..…
- CVE-2023-327811 PoCA command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an authenticated user…
- CVE-2023-3278412 PoCsIn KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a workspace is locked or…
- CVE-2023-328421 PoCIn 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving…
- CVE-2023-328431 PoCIn 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving…
- CVE-2023-328451 PoCIn 5G Modem, there is a possible system crash due to improper error handling. This could lead to remote denial of service when receiving…
- CVE-2023-329611 PoCWordPress Zotpress Plugin <= 7.3.3 is vulnerable to Cross Site Scripting (XSS)