CVE-2023-34000 to CVE-2023-34999
134 CVEs with public proof-of-concept exploits.
- CVE-2023-340201 PoCWordPress Uncanny Toolkit for LearnDash plugin <= 3.6.4.3 - Open Redirection vulnerability
- CVE-2023-340341 PoCUsing "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and…
- CVE-2023-340354 PoCsSpring Security versions 5.8 prior to 5.8.5, 6.0 prior to 6.0.5, and 6.1 prior to 6.1.2 could be susceptible to authorization rule…
- CVE-2023-340399 PoCsAria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A…
- CVE-2023-340404 PoCsJava Deserialization vulnerability in Spring-Kafka When Improperly Configured
- CVE-2023-340482 PoCsKEVVMware vCenter Server Out-of-Bounds Write Vulnerability
- CVE-2023-340501 PoCSpring AMQP Deserialization Vulnerability
- CVE-2023-340511 PoCVMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into…
- CVE-2023-340922 PoCsVite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)
- CVE-2023-340931 PoCStrapi allows actors to make all attributes on a content-type public without noticing it
- CVE-2023-340964 PoCsThruk has Path Traversal Vulnerability in panorama.pm
- CVE-2023-340971 PoCDatabase password exposed in logs in hoppscotch
- CVE-2023-341021 PoCPossible unsafe reflection / partial denial of service in avo
- CVE-2023-341031 PoCStored XSS (Cross Site Scripting) in html content based fields of avo
- CVE-2023-341052 PoCsSRS has command injection vulnerability in demonstration api-server for HTTP callback.
- CVE-2023-341112 PoCsCommand Injection Vulnerability in `Release PR Merged` Workflow in taosdata/grafanaplugin
- CVE-2023-341121 PoCJavaCPP project actions vulnerable to code injection
- CVE-2023-341243 PoCsThe authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This…
- CVE-2023-341271 PoCImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall…
- CVE-2023-341321 PoCUse of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks.…
- CVE-2023-341332 PoCsImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows…
- CVE-2023-341511 PoCA vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and…
- CVE-2023-341523 PoCsA vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes…
- CVE-2023-341531 PoCA vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or…
- CVE-2023-341921 PoCKEVCross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted…
- CVE-2023-342041 PoCimapsync through 2.229 uses predictable paths under /tmp and /var/tmp in its default mode of operation. Both of these are typically…
- CVE-2023-342121 PoCApache NiFi: Potential Deserialization of Untrusted Data with JNDI in JMS Components
- CVE-2023-342331 PoCSnowflake Python Connector vulnerable to Command Injection
- CVE-2023-342351 PoCLeaking sensitive user information still possible by filtering on private with prefix fields
- CVE-2023-342512 PoCsGrav Server Side Template Injection vulnerability
- CVE-2023-342521 PoCGrav Server-side Template Injection via Insufficient Validation in filterFilter
- CVE-2023-342532 PoCsGrav vulnerable to Server-side Template Injection (SSTI) via Denylist Bypass
- CVE-2023-342592 PoCsKyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow /wlmdeu%2f%2e%2e%2f%2e%2e directory traversal to read arbitrary files on…
- CVE-2023-342601 PoCKyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow a denial of service (service outage) via /wlmdeu%2f%2e%2e%2f%2e%2e…
- CVE-2023-342611 PoCKyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow identification of valid user accounts via username enumeration because…
- CVE-2023-343122 PoCsIn Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate pointers from…
- CVE-2023-343171 PoCAn improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform…
- CVE-2023-343531 PoCAn authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software OAS Platform…
- CVE-2023-343541 PoCA stored cross-site scripting (XSS) vulnerability exists in the upload_brand.cgi functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU).…
- CVE-2023-343561 PoCAn OS command injection vulnerability exists in the data.cgi xfer_dns functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially…
- CVE-2023-3436217 PoCsKEVIn Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a…
- CVE-2023-343661 PoCA use-after-free vulnerability exists in the Figure stream parsing functionality of Ichitaro 2023 1.0.1.59372. A specially crafted…
- CVE-2023-343671 PoCWindows 7 is vulnerable to a full blind TCP/IP hijacking attack. The vulnerability exists in Windows 7 (any Windows until Windows 8) and…
- CVE-2023-344071 PoCOfflinePlayerService.exe in Harbinger Offline Player 4.0.6.0.2 allows directory traversal as LocalSystem via ..\ in a URL.
- CVE-2023-344081 PoCDokuWiki before 2023-04-04a allows XSS via RSS titles.
- CVE-2023-344461 PoCiTop XSS vulnerability on pages/preferences.php
- CVE-2023-344482 PoCsGrav Server-side Template Injection (SSTI) via Twig Default Filters
- CVE-2023-344521 PoCGrav vulnerable to Self Cross Site Scripting in /forgot_password
- CVE-2023-344531 PoCsnappy-java's Integer Overflow vulnerability in shuffle leads to DoS
- CVE-2023-344541 PoCsnappy-java's Integer Overflow vulnerability in compress leads to DoS
- CVE-2023-344551 PoCsnappy-java's unchecked chunk length leads to DoS
- CVE-2023-344571 PoCMechanicalSoup vulnerable to malicious web server reading arbitrary files on client using file input inside HTML form
- CVE-2023-344671 PoCXWiki Platform may retrieve email addresses of all users
- CVE-2023-344688 PoCsApache NiFi: Potential Code Injection with Database Services using H2
- CVE-2023-344781 PoCApache Shiro before 1.12.0, or 2.0.0-alpha-3, may be susceptible to a path traversal attack when used together with APIs or other web…
- CVE-2023-344881 PoCNanoMQ 0.17.5 has a one-byte heap-based buffer over-read in the conn_handler function of mqtt_parser.c when it processes malformed messages.
- CVE-2023-345372 PoCsA Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter…
- CVE-2023-345614 PoCsA buffer overflow in the level parsing code of RobTop Games AB Geometry Dash v2.113 allows attackers to execute arbitrary code via…
- CVE-2023-345631 PoCnetgear R6250 Firmware Version 1.0.4.48 is vulnerable to Buffer Overflow after authentication.
- CVE-2023-345651 PoCNetbox 3.5.1 is vulnerable to Cross Site Scripting (XSS) in the "Create Wireless LAN Groups" function.
- CVE-2023-345813 PoCsSourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in…
- CVE-2023-345985 PoCsGibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files present in the…
- CVE-2023-345992 PoCsMultiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Gibbon v25.0.0, which enable attackers to execute arbitrary…
- CVE-2023-346001 PoCAdiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.
- CVE-2023-346021 PoCJeecgBoot up to v 3.5.1 was discovered to contain a SQL injection vulnerability via the component queryTableDictItemsByCode at…
- CVE-2023-346094 PoCsAn issue was discovered flexjson thru 3.3 allows attackers to cause a denial of service or other unspecified impacts via crafted object…
- CVE-2023-346101 PoCAn issue was discovered json-io thru 4.14.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object…
- CVE-2023-346111 PoCAn issue was discovered mjson thru 1.4.1 allows attackers to cause a denial of service or other unspecified impacts via crafted object…
- CVE-2023-346121 PoCAn issue was discovered ph-json thru 9.5.5 allows attackers to cause a denial of service or other unspecified impacts via crafted object…
- CVE-2023-346131 PoCAn issue was discovered sojo thru 1.1.1 allows attackers to cause a denial of service or other unspecified impacts via crafted object that…
- CVE-2023-346151 PoCAn issue was discovered JSONUtil thru 5.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object…
- CVE-2023-346161 PoCAn issue was discovered pbjson thru 0.4.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object…
- CVE-2023-346171 PoCAn issue was discovered genson thru 1.6 allows attackers to cause a denial of service or other unspecified impacts via crafted object that…
- CVE-2023-346201 PoCAn issue was discovered hjson thru 3.0.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object…
- CVE-2023-346231 PoCAn issue was discovered jtidy thru r938 allows attackers to cause a denial of service or other unspecified impacts via crafted object that…
- CVE-2023-346241 PoCAn issue was discovered htmlcleaner thru = 2.28 allows attackers to cause a denial of service or other unspecified impacts via crafted…
- CVE-2023-346251 PoCShowMojo MojoBox Digital Lockbox 1.4 is vulnerable to Authentication Bypass. The implementation of the lock opening mechanism via…
- CVE-2023-346344 PoCsGreenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .greenshot file is opened.
- CVE-2023-346352 PoCsWifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or…
- CVE-2023-346451 PoCjfinal CMS 5.1.0 has an arbitrary file read vulnerability.
- CVE-2023-346541 PoCtaocms <=3.0.2 is vulnerable to Cross Site Scripting (XSS).
- CVE-2023-346591 PoCjeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.
- CVE-2023-346661 PoCCross-site scripting (XSS) vulnerability in Phpgurukul Cyber Cafe Management System 1.0 allows remote attackers to inject arbitrary web…
- CVE-2023-346691 PoCTOTOLINK CP300+ V5.2cu.7594 contains a Denial of Service vulnerability in function RebootSystem of the file lib/cste_modules/system which…
- CVE-2023-347232 PoCsAn issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information via…
- CVE-2023-347241 PoCAn issue was discovered in TECHView LA5570 Wireless Gateway 1.0.19_T53, allows physical attackers to gain escalated privileges via the…
- CVE-2023-347251 PoCAn issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows physical attackers to gain escalated privileges via a…
- CVE-2023-347321 PoCAn issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c allows attackers to…
- CVE-2023-347341 PoCAnnet AC Centralized Management Platform 1.02.040 is vulnerable to Stored Cross-Site Scripting (XSS) .
- CVE-2023-347351 PoCProperty Cloud Platform Management Center 1.0 is vulnerable to error-based SQL injection.
- CVE-2023-347361 PoCGuantang Equipment Management System version 4.12 is vulnerable to Arbitrary File Upload.
- CVE-2023-347501 PoCbloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at…
- CVE-2023-347512 PoCsbloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at…
- CVE-2023-347522 PoCsbloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at…
- CVE-2023-347532 PoCsbloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at…
- CVE-2023-347542 PoCsbloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at…
- CVE-2023-347552 PoCsbloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit.
- CVE-2023-347562 PoCsbloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at…
- CVE-2023-347951 PoCxlsxio v0.1.2 to v0.2.34 was discovered to contain a free of uninitialized pointer in the xlsxioread_sheetlist_close() function. This…
- CVE-2023-348001 PoCD-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main.
- CVE-2023-348301 PoCi-doit Open v24 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the timeout parameter on the login page.
- CVE-2023-348321 PoCTP-Link Archer AX10(EU)_V1.2_230220 was discovered to contain a buffer overflow via the function FUN_131e8 - 0x132B4.
- CVE-2023-348341 PoCA Directory Browsing vulnerability in MCL-Net version 4.3.5.8788 webserver running on default port 5080, allows attackers to gain…
- CVE-2023-348351 PoCA Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to…
- CVE-2023-348361 PoCA Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to…
- CVE-2023-348371 PoCA Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to…
- CVE-2023-348381 PoCA Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to…
- CVE-2023-348391 PoCA Cross Site Request Forgery (CSRF) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows a remote attacker to gain privileges via a…
- CVE-2023-348401 PoCangular-ui-notification v0.1.0, v0.2.0, and v0.3.6 was discovered to contain a cross-site scripting (XSS) vulnerability.
- CVE-2023-348433 PoCsTraggo Server 0.3.0 is vulnerable to directory traversal via a crafted GET request.
- CVE-2023-348451 PoCBludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the component /admin/new-content. This vulnerability…
- CVE-2023-348491 PoCAn unauthorized command injection vulnerability exists in the ActionLogin function of the webman.lua file in Ikuai router OS through 3.7.1.
- CVE-2023-348521 PoCPublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.
- CVE-2023-348531 PoCBuffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of…
- CVE-2023-348671 PoCJerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the ecma_property_hashmap_create at…
- CVE-2023-348681 PoCJerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the parser_parse_for_statement_start at…
- CVE-2023-348721 PoCA vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a…
- CVE-2023-349161 PoCFuge CMS v1.0 contains an Open Redirect vulnerability via /front/ProcessAct.java.
- CVE-2023-349171 PoCFuge CMS v1.0 contains an Open Redirect vulnerability in member/RegisterAct.java.
- CVE-2023-349241 PoCH3C Magic B1STW B1STV100R012 was discovered to contain a stack overflow via the function SetAPInfoById. This vulnerability allows…
- CVE-2023-349275 PoCsCasdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This…
- CVE-2023-349281 PoCA stack overflow in the Edit_BasicSSID function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a…
- CVE-2023-349331 PoCA stack overflow in the UpdateWanParams function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a…
- CVE-2023-349341 PoCA stack overflow in the Edit_BasicSSID_5G function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a…
- CVE-2023-349351 PoCA stack overflow in the AddWlanMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a…
- CVE-2023-349361 PoCA stack overflow in the UpdateMacClone function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a…
- CVE-2023-349371 PoCA stack overflow in the UpdateSnat function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted…
- CVE-2023-349391 PoCOnlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component…
- CVE-2023-3496013 PoCsA command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary…
- CVE-2023-349651 PoCSSPanel-Uim 2023.3 does not restrict access to the /link/ interface which can lead to a leak of user information.
- CVE-2023-349901 PoCA relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized…
- CVE-2023-349923 PoCsA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 7.0.0 and 6.7.0…
- CVE-2023-349931 PoCA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through…
- CVE-2023-349941 PoCAn improper resource allocation vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software…