CVE-2023-36000 to CVE-2023-36999
99 CVEs with public proof-of-concept exploits.
- CVE-2023-360033 PoCsXAML Diagnostics Elevation of Privilege Vulnerability
- CVE-2023-360253 PoCsKEVWindows SmartScreen Security Feature Bypass Vulnerability
- CVE-2023-360761 PoCSQL Injection vulnerability in smanga version 3.1.9 and earlier, allows remote attackers to execute arbitrary code and gain sensitive…
- CVE-2023-360852 PoCsThe sisqualWFM 7.1.319.103 thru 7.1.319.111 for Android, has a host header injection vulnerability in its "/sisqualIdentityServer/core/"…
- CVE-2023-360931 PoCThere is a storage type cross site scripting (XSS) vulnerability in the filing number of the Basic Information tab on the backend…
- CVE-2023-361091 PoCBuffer Overflow vulnerability in JerryScript version 3.0, allows remote attackers to execute arbitrary code via…
- CVE-2023-361213 PoCsCross Site Scripting vulnerability in e107 v.2.3.2 allows a remote attacker to execute arbitrary code via the description function in the…
- CVE-2023-361231 PoCDirectory Traversal vulnerability in Hex-Dragon Plain Craft Launcher 2 version Alpha 1.3.9, allows local attackers to execute arbitrary…
- CVE-2023-361432 PoCsMaxprint Maxlink 1200G v3.4.11E has an OS command injection vulnerability in the "Diagnostic tool" functionality of the device.
- CVE-2023-361442 PoCsAn authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file…
- CVE-2023-361461 PoCA Stored Cross-Site Scripting (XSS) vulnerability was found in Multilaser RE 170 using firmware 2.2.6733.
- CVE-2023-361582 PoCsCross Site Scripting (XSS) vulnerability in sourcecodester Toll Tax Management System 1.0 allows remote attackers to run arbitrary code…
- CVE-2023-361591 PoCCross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers to run arbitrary…
- CVE-2023-361633 PoCsCross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted…
- CVE-2023-361831 PoCBuffer Overflow vulnerability in OpenImageIO v.2.4.12.0 and before allows a remote to execute arbitrary code and obtain sensitive…
- CVE-2023-362101 PoCMotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the…
- CVE-2023-362111 PoCThe Barebones CMS v2.0.2 is vulnerable to Stored Cross-Site Scripting (XSS) when an authenticated user interacts with certain features on…
- CVE-2023-362122 PoCsFile Upload vulnerability in Total CMS v.1.7.4 allows a remote attacker to execute arbitrary code via a crafted PHP file to the edit page…
- CVE-2023-362132 PoCsSQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of the search function.
- CVE-2023-362171 PoCCross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of…
- CVE-2023-362201 PoCDirectory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain…
- CVE-2023-362391 PoClibming listswf 0.4.7 was discovered to contain a buffer overflow in the parseSWF_DEFINEFONTINFO() function at parser.c.
- CVE-2023-362431 PoCFLVMeta v1.2.1 was discovered to contain a buffer overflow via the xml_on_metadata_tag_only function at dump_xml.c.
- CVE-2023-362501 PoCCSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via crafted .tsv file…
- CVE-2023-362552 PoCsAn issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the…
- CVE-2023-362561 PoCThe Online Examination System Project 1.0 version is vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker can craft a…
- CVE-2023-362661 PoCAn issue was discovered in Keeper Password Manager for Desktop version 16.10.2 (fixed in 17.2), and the KeeperFill Browser Extensions…
- CVE-2023-362711 PoCLibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_wcs2nlen at bits.c.
- CVE-2023-362721 PoCLibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_utf8_to_TU at bits.c.
- CVE-2023-362731 PoCLibreDWG v0.12.5 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c.
- CVE-2023-362741 PoCLibreDWG v0.11 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_write_TF at bits.c.
- CVE-2023-362811 PoCAn issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This is related to…
- CVE-2023-362841 PoCAn unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a…
- CVE-2023-362871 PoCAn unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session…
- CVE-2023-362891 PoCAn unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session…
- CVE-2023-363062 PoCsA Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code…
- CVE-2023-363081 PoCdisintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a…
- CVE-2023-363191 PoCFile Upload vulnerability in Openupload Stable v.0.4.3 allows a remote attacker to execute arbitrary code via the action parameter of the…
- CVE-2023-363452 PoCsA Cross-Site Request Forgery (CSRF) in POS Codekop v2.0 allows attackers to escalate privileges.
- CVE-2023-363464 PoCsPOS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parameter at print.php.
- CVE-2023-363472 PoCsA broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data.
- CVE-2023-363483 PoCsPOS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter.
- CVE-2023-363541 PoCTP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR740N V1/V2, TL-WR940N V2/V3, and TL-WR941ND V5/V6 were discovered to contain a buffer…
- CVE-2023-363551 PoCTP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm. This…
- CVE-2023-363571 PoCAn issue in the /userRpm/LocalManageControlRpm component of TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8/V10, and TL-WR941ND V5 allows…
- CVE-2023-363591 PoCTP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR940N V2/V3 and TL-WR941ND V5/V6 were discovered to contain a buffer overflow in the component…
- CVE-2023-363751 PoCCross Site Scripting vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to…
- CVE-2023-364072 PoCsWindows Hyper-V Elevation of Privilege Vulnerability
- CVE-2023-364242 PoCsKEVWindows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2023-364271 PoCWindows Hyper-V Elevation of Privilege Vulnerability
- CVE-2023-364711 PoCHTML sanitizer allows form elements in restricted in org.xwiki.commons:xwiki-commons-xml
- CVE-2023-364721 PoCStrapi may leak sensitive user information, user reset password, tokens via content-manager views
- CVE-2023-365311 PoCWordPress LiquidPoll plugin <= 3.3.68 - Broken Access Control vulnerability
- CVE-2023-365421 PoCApache NiFi: Potential Code Injection with Properties Referencing Remote Resources
- CVE-2023-366182 PoCsAtos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-privileged…
- CVE-2023-366192 PoCsAtos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users.
- CVE-2023-366201 PoCAn issue was discovered in the Boomerang Parental Control application before 13.83 for Android. The app is missing the…
- CVE-2023-366221 PoCThe websocket configuration endpoint of the Loxone Miniserver Go Gen.2 before 14.1.5.9 allows remote authenticated administrators to…
- CVE-2023-366231 PoCThe root password of the Loxone Miniserver Go Gen.2 before 14.2 is calculated using hard-coded secrets and the MAC address. This allows a…
- CVE-2023-366241 PoCLoxone Miniserver Go Gen.2 through 14.0.3.28 allows an authenticated operating system user to escalate privileges via the Sudo…
- CVE-2023-366291 PoCThe ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.
- CVE-2023-366301 PoCIn CloudPanel before 2.3.1, insecure file upload leads to privilege escalation and authentication bypass.
- CVE-2023-366431 PoCIncorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all orders from the online shop via oordershow…
- CVE-2023-366441 PoCIncorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all order confirmations from the online shop via…
- CVE-2023-366451 PoCSQL injection vulnerability in ITB-GmbH TradePro v9.5, allows remote attackers to run SQL queries via oordershow component in customer…
- CVE-2023-366561 PoCCross Site Scripting (XSS) vulnerability in Jaegertracing Jaeger UI before v.1.31.0 allows a remote attacker to execute arbitrary code via…
- CVE-2023-366611 PoCShibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo element. (This…
- CVE-2023-366644 PoCsArtifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character…
- CVE-2023-366651 PoC"protobuf.js (aka protobufjs) 6.10.0 through 7.x before 7.2.5 allows Prototype Pollution, a different vulnerability than CVE-2022-25878. A…
- CVE-2023-367231 PoCWindows Container Manager Service Elevation of Privilege Vulnerability
- CVE-2023-367451 PoCMicrosoft Exchange Server Remote Code Execution Vulnerability
- CVE-2023-368026 PoCsKEVMicrosoft Streaming Service Proxy Elevation of Privilege Vulnerability
- CVE-2023-368061 PoCContao cross site scripting vulnerability via input unit widget
- CVE-2023-368081 PoCGLPI vulnerable to SQL injection through Computer Virtual Machine information
- CVE-2023-368091 PoCKiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox
- CVE-2023-368122 PoCsRemote Code Execution in OpenTSDB
- CVE-2023-368131 PoCKanboard Authenticated SQL Injections vulnerability
- CVE-2023-368161 PoCCross-Site Scripting (XSS) at Account creation in 2FAuth
- CVE-2023-368202 PoCsmicronaut security has invalid IdTokenClaimsValidator logic on aud
- CVE-2023-368212 PoCsUptime Kuma vulnerable to authenticated remote code execution via malicious plugin installation
- CVE-2023-368221 PoCUptime Kuma authenticated path traversal via plugin repository name may lead to unavailability or data loss
- CVE-2023-368282 PoCsStatamic's Antlers sanitizer cannot effectively sanitize malicious SVG
- CVE-2023-368448 PoCsKEVJunos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
- CVE-2023-3684522 PoCsKEVJunos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
- CVE-2023-368462 PoCsKEVJunos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
- CVE-2023-368471 PoCKEVJunos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
- CVE-2023-368641 PoCAn integer overflow vulnerability exists in the fstReaderIterBlocks2 temp_signal_value_buf allocation functionality of GTKWave 3.3.115. A…
- CVE-2023-368748 PoCsKEVWindows Error Reporting Service Elevation of Privilege Vulnerability
- CVE-2023-368801 PoCMicrosoft Edge (Chromium-based) Information Disclosure Vulnerability
- CVE-2023-368845 PoCsKEVWindows Search Remote Code Execution Vulnerability
- CVE-2023-368871 PoCMicrosoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2023-368993 PoCsASP.NET Elevation of Privilege Vulnerability
- CVE-2023-369001 PoCWindows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2023-369341 PoCIn Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and…
- CVE-2023-369471 PoCTOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the File…
- CVE-2023-369501 PoCTOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the…
- CVE-2023-369541 PoCTOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.
- CVE-2023-369681 PoCA SQL Injection vulnerability detected in Food Ordering System v1.0 allows attackers to run commands on the database by sending crafted…
- CVE-2023-369691 PoCCMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.