CVE-2023-33000 to CVE-2023-33999
147 CVEs with public proof-of-concept exploits.
- CVE-2023-330121 PoCA command injection vulnerability in the configuration parser of the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG…
- CVE-2023-331051 PoCConfiguration Issue in WLAN Host and Firmware
- CVE-2023-331072 PoCsKEVInteger Overflow or Wraparound in Graphics Linux
- CVE-2023-331311 PoCMicrosoft Outlook Remote Code Execution Vulnerability
- CVE-2023-331371 PoCMicrosoft Excel Remote Code Execution Vulnerability
- CVE-2023-331401 PoCMicrosoft OneNote Spoofing Vulnerability
- CVE-2023-331451 PoCMicrosoft Edge (Chromium-based) Information Disclosure Vulnerability
- CVE-2023-331482 PoCsMicrosoft Office Elevation of Privilege Vulnerability
- CVE-2023-331773 PoCsXibo CMS vulnerable to Remote Code Execution through Zip Slip
- CVE-2023-331851 PoCIncorrect signature verification in django-ses
- CVE-2023-331931 PoCEmby Server Proxy Header Spoofing Vulnerability
- CVE-2023-331941 PoCCraftCMS stored XSS in Quick Post widget error message
- CVE-2023-331951 PoCCraft CMS XSS in RSS widget feed
- CVE-2023-331962 PoCsCraft CMS stored XSS in review volume
- CVE-2023-331972 PoCsCraft CMS stored XSS in indexedVolumes
- CVE-2023-332411 PoCGG18 / GG20 TSS Beta Parameter Vulnerability
- CVE-2023-332422 PoCsLindell17 TSS Abort Mishandling
- CVE-2023-332433 PoCsRedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of…
- CVE-2023-3324625 PoCsKEVApache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
- CVE-2023-332481 PoCAmazon Alexa software version 8960323972 on Echo Dot 2nd generation and 3rd generation devices potentially allows attackers to deliver…
- CVE-2023-332531 PoCLabCollector 6.0 though 6.15 allows remote code execution. An authenticated remote low-privileged user can upload an executable PHP file…
- CVE-2023-332551 PoCAn issue was discovered in Papaya Viewer 1.0.1449. User-supplied input in form of DICOM or NIFTI images can be loaded into the Papaya web…
- CVE-2023-332681 PoCAn issue was discovered in DTS Monitoring 3.57.0. The parameter port within the SSL Certificate check function is vulnerable to OS command…
- CVE-2023-332691 PoCAn issue was discovered in DTS Monitoring 3.57.0. The parameter options within the WGET check function is vulnerable to OS command…
- CVE-2023-332701 PoCAn issue was discovered in DTS Monitoring 3.57.0. The parameter url within the Curl check function is vulnerable to OS command injection…
- CVE-2023-332711 PoCAn issue was discovered in DTS Monitoring 3.57.0. The parameter common_name within the SSL Certificate check function is vulnerable to OS…
- CVE-2023-332721 PoCAn issue was discovered in DTS Monitoring 3.57.0. The parameter ip within the Ping check function is vulnerable to OS command injection…
- CVE-2023-332731 PoCAn issue was discovered in DTS Monitoring 3.57.0. The parameter url within the WGET check function is vulnerable to OS command injection…
- CVE-2023-332741 PoCThe authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access…
- CVE-2023-332761 PoCThe web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 responds with a "404 - Not Found" status code if a path is…
- CVE-2023-332771 PoCThe web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 allows a remote attacker to read sensitive files via…
- CVE-2023-332891 PoCThe urlnorm crate through 0.1.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to lib.rs. NOTE: the…
- CVE-2023-333381 PoCOld Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter.
- CVE-2023-333561 PoCIceCMS v1.0.0 is vulnerable to Cross Site Scripting (XSS).
- CVE-2023-333591 PoCPiwigo 13.6.0 is vulnerable to Cross Site Request Forgery (CSRF) in the "add tags" function.
- CVE-2023-333621 PoCPiwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.
- CVE-2023-333811 PoCA command injection vulnerability was found in the ping functionality of the MitraStar GPT-2741GNAC router (firmware version…
- CVE-2023-333833 PoCsShelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition that results in a…
- CVE-2023-333861 PoCMarsCTF 1.2.1 has an arbitrary file upload vulnerability in the interface for uploading attachments in the background.
- CVE-2023-334041 PoCAn Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and…
- CVE-2023-334052 PoCsBlogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect.
- CVE-2023-334081 PoCMinical 1.0.0 is vulnerable to Cross Site Scripting (XSS). The vulnerability exists due to insufficient input validation in the…
- CVE-2023-334091 PoCMinical 1.0.0 is vulnerable to Cross Site Request Forgery (CSRF) via minical/public/application/controllers/settings/company.php.
- CVE-2023-334101 PoCMinical 1.0.0 and earlier contains a CSV injection vulnerability which allows an attacker to execute remote code. The vulnerability exists…
- CVE-2023-334391 PoCSourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_task.php?id=.
- CVE-2023-334402 PoCsSourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_user.
- CVE-2023-334761 PoCReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. The vulnerability is caused by incorrect…
- CVE-2023-334771 PoCIn Harmonic NSG 9000-6G devices, an authenticated remote user can obtain source code by directly requesting a special path.
- CVE-2023-334781 PoCRemoteClinic 2.0 has a SQL injection vulnerability in the ID parameter of /medicines/stocks.php.
- CVE-2023-334791 PoCRemoteClinic version 2.0 contains a SQL injection vulnerability in the /staff/edit.php file.
- CVE-2023-334801 PoCRemoteClinic 2.0 contains a critical vulnerability chain that can be exploited by a remote attacker with low-privileged user credentials…
- CVE-2023-334851 PoCTOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a post-authentication buffer overflow via parameter sPort/ePort…
- CVE-2023-334861 PoCTOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpModeCfg. This…
- CVE-2023-334871 PoCTOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulnerability in setDiagnosisCfg.This…
- CVE-2023-335101 PoCJeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters.
- CVE-2023-335181 PoCemoncms v11 and later was discovered to contain an information disclosure vulnerability which allows attackers to obtain the web directory…
- CVE-2023-335331 PoCNetgear D6220 with Firmware Version 1.0.0.80, D8500 with Firmware Version 1.0.3.60, R6700 with Firmware Version 1.0.2.26, and R6900 with…
- CVE-2023-335341 PoCA Cross-Site Request Forgery (CSRF) in Guanzhou Tozed Kangwei Intelligent Technology ZLTS10G software version S10G_3.11.6 allows attackers…
- CVE-2023-335371 PoCTP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the component…
- CVE-2023-335385 PoCsKEVTP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the…
- CVE-2023-335441 PoChawtio 2.17.2 is vulnerable to Path Traversal. it is possible to input malicious zip files, which can result in the high-risk files after…
- CVE-2023-335461 PoCJanino 3.1.9 and earlier are subject to denial of service (DOS) attacks when using the expression evaluator.guess parameter name method.…
- CVE-2023-335531 PoCAn issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication and escalate privileges to root via…
- CVE-2023-335561 PoCTOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw parameter at…
- CVE-2023-335683 PoCsAn issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer…
- CVE-2023-335701 PoCBagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).
- CVE-2023-335803 PoCsPhpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" field on Admin…
- CVE-2023-335844 PoCsSourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL…
- CVE-2023-335925 PoCsLost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component…
- CVE-2023-336171 PoCAn OS Command Injection vulnerability in Parks Fiberlink 210 firmware version V2.1.14_X000 was found via the /boaform/admin/formPing…
- CVE-2023-336211 PoCGL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is…
- CVE-2023-336252 PoCsD-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability via the ST parameter…
- CVE-2023-336261 PoCD-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a stack overflow via the gena.cgi binary.
- CVE-2023-336292 PoCsH3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the DeltriggerList interface at /goform/aspForm.
- CVE-2023-336561 PoCA memory leak vulnerability exists in NanoMQ 0.17.2. The vulnerability is located in the file message.c. An attacker could exploit this…
- CVE-2023-336571 PoCA use-after-free vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function…
- CVE-2023-336591 PoCA heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function…
- CVE-2023-336611 PoCMultiple cross-site scripting (XSS) vulnerabilities were discovered in Church CRM v4.5.3 in GroupReports.php via GroupRole, ReportModel,…
- CVE-2023-336681 PoCDigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared…
- CVE-2023-336693 PoCsTenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the timeZone parameter in the sub_44db3c function.
- CVE-2023-336701 PoCTenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sub_4a79ec function.
- CVE-2023-336711 PoCTenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the deviceId parameter in the saveParentControlInfo function.
- CVE-2023-336721 PoCTenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function.
- CVE-2023-336731 PoCTenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.
- CVE-2023-336751 PoCTenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the get_parentControl_list_Info function.
- CVE-2023-336761 PoCSourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*"…
- CVE-2023-336771 PoCSourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*".
- CVE-2023-337171 PoCmp4v2 v2.1.3 was discovered to contain a memory leak when a method calling MP4File::ReadBytes() had allocated memory but did not catch…
- CVE-2023-337181 PoCmp4v2 v2.1.3 was discovered to contain a memory leak via MP4File::ReadString() at mp4file_io.cpp
- CVE-2023-337191 PoCmp4v2 v2.1.3 was discovered to contain a memory leak via MP4SdpAtom::Read() at atom_sdp.cpp
- CVE-2023-337201 PoCmp4v2 v2.1.2 was discovered to contain a memory leak via the class MP4BytesProperty.
- CVE-2023-337301 PoCPrivilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any…
- CVE-2023-337311 PoCReflected Cross Site Scripting (XSS) in the view dashboard detail feature in Microworld Technologies eScan management console…
- CVE-2023-337321 PoCCross Site Scripting (XSS) in the New Policy form in Microworld Technologies eScan management console 14.0.1400.2281 allows a remote…
- CVE-2023-337334 PoCsReportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file.
- CVE-2023-337401 PoCIncorrect access control in luowice v3.5.18 allows attackers to access cloud source code information via modification fo the Verify…
- CVE-2023-337411 PoCMacrovideo v380pro v1.4.97 shares the device id and password when sharing the device.
- CVE-2023-337473 PoCsCloudPanel v2.2.2 allows attackers to execute a path traversal.
- CVE-2023-337541 PoCThe captive portal in Inpiazza Cloud WiFi versions prior to v4.2.17 does not enforce limits on the number of attempts for password…
- CVE-2023-337571 PoCA lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Android App) v1.8.5…
- CVE-2023-337581 PoCSplicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the CLIENT_NAME and…
- CVE-2023-337591 PoCSpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts, allowing attackers to bypass…
- CVE-2023-337601 PoCSpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow attackers to…
- CVE-2023-337611 PoCeMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the…
- CVE-2023-337631 PoCeMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the…
- CVE-2023-337641 PoCeMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the…
- CVE-2023-337682 PoCsIncorrect signature verification of the firmware during the Device Firmware Update process of Belkin Wemo Smart Plug WSP080 v1.2 allows…
- CVE-2023-337781 PoCDraytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below…
- CVE-2023-337801 PoCA stored cross-site scripting (XSS) vulnerability in TFDi Design smartCARS 3 v0.7.0 and below allows attackers to execute arbitrary web…
- CVE-2023-337811 PoCAn issue in D-Link DIR-842V2 v1.0.3 allows attackers to execute arbitrary commands via importing a crafted file.
- CVE-2023-337821 PoCD-Link DIR-842V2 v1.0.3 was discovered to contain a command injection vulnerability via the iperf3 diagnostics function.
- CVE-2023-337851 PoCA stored cross-site scripting (XSS) vulnerability in the Create Rack Roles (/dcim/rack-roles/) function of Netbox v3.5.1 allows attackers…
- CVE-2023-337861 PoCA stored cross-site scripting (XSS) vulnerability in the Create Circuit Types (/circuits/circuit-types/) function of Netbox v3.5.1 allows…
- CVE-2023-337871 PoCA stored cross-site scripting (XSS) vulnerability in the Create Tenant Groups (/tenancy/tenant-groups/) function of Netbox v3.5.1 allows…
- CVE-2023-337881 PoCA stored cross-site scripting (XSS) vulnerability in the Create Providers (/circuits/providers/) function of Netbox v3.5.1 allows…
- CVE-2023-337891 PoCA stored cross-site scripting (XSS) vulnerability in the Create Contact Groups (/tenancy/contact-groups/) function of Netbox v3.5.1 allows…
- CVE-2023-337901 PoCA stored cross-site scripting (XSS) vulnerability in the Create Locations (/dcim/locations/) function of Netbox v3.5.1 allows attackers to…
- CVE-2023-337911 PoCA stored cross-site scripting (XSS) vulnerability in the Create Provider Accounts (/circuits/provider-accounts/) function of Netbox v3.5.1…
- CVE-2023-337921 PoCA stored cross-site scripting (XSS) vulnerability in the Create Site Groups (/dcim/site-groups/) function of Netbox v3.5.1 allows…
- CVE-2023-337931 PoCA stored cross-site scripting (XSS) vulnerability in the Create Power Panels (/dcim/power-panels/) function of Netbox v3.5.1 allows…
- CVE-2023-337941 PoCA stored cross-site scripting (XSS) vulnerability in the Create Tenants (/tenancy/tenants/) function of Netbox v3.5.1 allows attackers to…
- CVE-2023-337951 PoCA stored cross-site scripting (XSS) vulnerability in the Create Contact Roles (/tenancy/contact-roles/) function of Netbox v3.5.1 allows…
- CVE-2023-337961 PoCA vulnerability in Netbox v3.5.1 allows unauthenticated attackers to execute queries against the GraphQL database, granting them access to…
- CVE-2023-337971 PoCA stored cross-site scripting (XSS) vulnerability in the Create Sites (/dcim/sites/) function of Netbox v3.5.1 allows attackers to execute…
- CVE-2023-337981 PoCA stored cross-site scripting (XSS) vulnerability in the Create Rack (/dcim/rack/) function of Netbox v3.5.1 allows attackers to execute…
- CVE-2023-337991 PoCA stored cross-site scripting (XSS) vulnerability in the Create Contacts (/tenancy/contacts/) function of Netbox v3.5.1 allows attackers…
- CVE-2023-338001 PoCA stored cross-site scripting (XSS) vulnerability in the Create Regions (/dcim/regions/) function of Netbox v3.5.1 allows attackers to…
- CVE-2023-338021 PoCA buffer overflow in SumatraPDF Reader v3.4.6 allows attackers to cause a Denial of Service (DoS) via a crafted text file.
- CVE-2023-338171 PoChoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability.
- CVE-2023-338298 PoCsA stored cross-site scripting (XSS) vulnerability in Cloudogu GmbH SCM Manager v1.2 to v1.60 allows attackers to execute arbitrary web…
- CVE-2023-338314 PoCsA remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary…
- CVE-2023-338633 PoCsSerialiseValue in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. 0xffffffff is sign-extended to…
- CVE-2023-338643 PoCsStreamReader::ReadFromExternal in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. It uses…
- CVE-2023-338653 PoCsRenderDoc before 1.27 allows local privilege escalation via a symlink attack. It relies on the /tmp/RenderDoc directory regardless of…
- CVE-2023-338661 PoCA use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 12.1.2.15332. By prematurely…
- CVE-2023-338691 PoCEnphase Envoy OS Command Injection
- CVE-2023-338761 PoCA use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15332 handles destroying annotations. Specially crafted Javascript…
- CVE-2023-339021 PoCIn bluetooth service, there is a missing permission check. This could lead to local information disclosure with no additional execution…
- CVE-2023-339561 PoCParameter based Indirect Object Referencing leading to private file exposure in Kanboard
- CVE-2023-339591 PoCVerification bypass can cause users into verifying the wrong artifact
- CVE-2023-339601 PoCOpenProject vulnerable to project identifier information leakage through robots.txt
- CVE-2023-339622 PoCsJStachio XSS vulnerability: Unescaped single quotes
- CVE-2023-339681 PoCMissing Access Control allows User to move and duplicate tasks in Kanboard
- CVE-2023-339691 PoCStored Cross site scripting in the Task External Link Functionality in Kanboard
- CVE-2023-339701 PoCMissing access control in internal task links feature in Kanboard
- CVE-2023-339711 PoCFormcreator vulnerable to stored XSS from ##FULLFORM##
- CVE-2023-339772 PoCsStored cross site scripting (XSS) via unrestricted file upload in Kiwi TCMS