CVE-2023-35000 to CVE-2023-35999
53 CVEs with public proof-of-concept exploits.
- CVE-2023-350014 PoCsLinux Kernel nftables Out-Of-Bounds Read/Write Vulnerability
- CVE-2023-350021 PoCA heap-based buffer overflow vulnerability exists in the pictwread functionality of Accusoft ImageGear 20.1. A specially crafted malformed…
- CVE-2023-350571 PoCAn integer overflow vulnerability exists in the LXT2 lxt2_rd_trace value elements allocation functionality of GTKWave 3.3.115. A specially…
- CVE-2023-3507812 PoCsKEVAn authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the…
- CVE-2023-350802 PoCsA vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to…
- CVE-2023-350822 PoCsKEVAn authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or…
- CVE-2023-350851 PoCAn integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and…
- CVE-2023-350862 PoCsASUS RT-AX56U V2 & RT-AC86U - Format String -1
- CVE-2023-351101 PoCAn issue was discovered jjson thru 0.1.7 allows attackers to cause a denial of service or other unspecified impacts via crafted object…
- CVE-2023-351241 PoCAn information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS…
- CVE-2023-351262 PoCsAn out-of-bounds write vulnerability exists within the parsers for both the "DocumentViewStyles" and "DocumentEditStyles" streams of…
- CVE-2023-351531 PoCXWiki Platform vulnerable to stored cross-site scripting in ClassEditSheet page via name parameters
- CVE-2023-351552 PoCsXWiki Platform vulnerable to cross-site scripting in target parameter via share page by email
- CVE-2023-351561 PoCXWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in delete template
- CVE-2023-351581 PoCXWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in restore template
- CVE-2023-351591 PoCXWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in deletespace template
- CVE-2023-351601 PoCXWiki Platform vulnerable to reflected cross-site scripting via back and xcontinue parameters in resubmit template
- CVE-2023-351611 PoCXWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in DeleteApplication page
- CVE-2023-351621 PoCXPlatform Wiki vulnerable to cross-site scripting via xcontinue parameter in preview actions template
- CVE-2023-351692 PoCsphp-imap vulnerable to RCE through a directory traversal vulnerability
- CVE-2023-351931 PoCAn OS command injection vulnerability exists in the api.cgi cmd.mvpn.x509.write functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A…
- CVE-2023-351941 PoCAn OS command injection vulnerability exists in the api.cgi cmd.mvpn.x509.write functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A…
- CVE-2023-353171 PoCWindows Server Update Service (WSUS) Elevation of Privilege Vulnerability
- CVE-2023-356361 PoCMicrosoft Outlook Information Disclosure Vulnerability
- CVE-2023-356711 PoCIn onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read the full card number…
- CVE-2023-356742 PoCsKEVIn onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead…
- CVE-2023-356791 PoCIn MtpPropertyValue of MtpProperty.h, there is a possible out of bounds read due to uninitialized data. This could lead to local…
- CVE-2023-356871 PoCIn MtpPropertyValue of MtpProperty.h, there is a possible memory corruption due to a use after free. This could lead to local escalation…
- CVE-2023-356951 PoCA remote attacker could leverage a vulnerability in Trend Micro Mobile Security (Enterprise) 9.8 SP5 to download a particular log file…
- CVE-2023-357081 PoCIn Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a…
- CVE-2023-357441 PoCD-Link DAP-2622 DDP Configuration Restore Server IPv6 Address Stack-based Buffer Overflow Remote Code Execution Vulnerability
- CVE-2023-357931 PoCAn issue was discovered in Cassia Access Controller 2.1.1.2303271039. Establishing a web SSH session to gateways is vulnerable to Cross…
- CVE-2023-357941 PoCAn issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) can be accessed…
- CVE-2023-358011 PoCA directory traversal vulnerability in Safe Software FME Server before 2022.2.5 allows an attacker to bypass validation when editing a…
- CVE-2023-358031 PoCIQ Engine before 10.6r2 on Extreme Network AP devices has a Buffer Overflow.
- CVE-2023-358136 PoCsMultiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce…
- CVE-2023-358281 PoCAn issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in renesas_usb3_remove in…
- CVE-2023-358291 PoCAn issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in rkvdec_remove in…
- CVE-2023-358391 PoCA bypass in the component sofa-hessian of Solon before v2.3.3 allows attackers to execute arbitrary code via providing crafted payload.
- CVE-2023-358401 PoC_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.
- CVE-2023-358411 PoCWinFlash Driver Permissions Issue
- CVE-2023-358436 PoCsNocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files…
- CVE-2023-358445 PoCspackages/backend/src/routers in Lightdash before 0.510.3 has insecure file endpoints, e.g., they allow .. directory traversal and do not…
- CVE-2023-358611 PoCA shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote…
- CVE-2023-358631 PoCIn MADEFORNET HTTP Debugger through 9.12, the Windows service does not set the seclevel registry key before launching the driver. Thus, it…
- CVE-2023-358661 PoCIn KeePassXC through 2.7.5, a local attacker can make changes to the Database security settings, including master password and…
- CVE-2023-358855 PoCsCloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
- CVE-2023-358871 PoCApache MINA SSHD: Information disclosure bugs with RootedFilesystem
- CVE-2023-359321 PoCjcvi vulnerable to Configuration Injection due to unsanitized user input
- CVE-2023-359421 PoCEnvoy's gRPC access log crash caused by the listener draining
- CVE-2023-359431 PoCEnvoy vulnerable to CORS filter segfault when origin header is removed
- CVE-2023-359441 PoCEnvoy vulnerable to incorrect handling of HTTP requests and responses with mixed case schemes
- CVE-2023-359853 PoCsAn arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to a failure to…