CVE-2023-37000 to CVE-2023-37999
170 CVEs with public proof-of-concept exploits.
- CVE-2023-370021 PoCOpen5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
- CVE-2023-370031 PoCOpen5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
- CVE-2023-370041 PoCOpen5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
- CVE-2023-370051 PoCOpen5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
- CVE-2023-370061 PoCOpen5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
- CVE-2023-370071 PoCOpen5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
- CVE-2023-370081 PoCOpen5GS MME versions <= 2.6.4 contain a buffer overflow in the ASN.1 deserialization function of the S1AP handler. This buffer overflow…
- CVE-2023-370091 PoCOpen5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
- CVE-2023-370101 PoCOpen5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
- CVE-2023-370111 PoCOpen5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
- CVE-2023-370121 PoCOpen5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
- CVE-2023-370131 PoCOpen5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a sufficiently large ASN.1 packet over the S1AP…
- CVE-2023-370141 PoCOpen5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.…
- CVE-2023-370151 PoCOpen5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.…
- CVE-2023-370161 PoCOpen5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
- CVE-2023-370171 PoCOpen5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
- CVE-2023-370181 PoCOpen5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.…
- CVE-2023-370191 PoCOpen5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface.…
- CVE-2023-370201 PoCOpen5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
- CVE-2023-370211 PoCOpen5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
- CVE-2023-370221 PoCOpen5GS MME versions <= 2.6.4 contain a reachable assertion in the `UE Context Release Request` packet handler. A packet containing an…
- CVE-2023-370231 PoCOpen5GS MME versions <= 2.6.4 contain a reachable assertion in the `Uplink NAS Transport` packet handler. A packet missing its…
- CVE-2023-370241 PoCA reachable assertion in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit…
- CVE-2023-370251 PoCA Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit…
- CVE-2023-370271 PoCNull pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit…
- CVE-2023-370281 PoCA Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit…
- CVE-2023-370291 PoCMagma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) are susceptible to an assertion-based crash when…
- CVE-2023-370301 PoCA Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit…
- CVE-2023-370311 PoCA Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit…
- CVE-2023-370321 PoCA Stack-based buffer overflow in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit…
- CVE-2023-370331 PoCA Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit…
- CVE-2023-370341 PoCA Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit…
- CVE-2023-370361 PoCA Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit…
- CVE-2023-370371 PoCA Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit…
- CVE-2023-370381 PoCA Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit…
- CVE-2023-370682 PoCsCode-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, leading to…
- CVE-2023-370692 PoCsCode-Projects Online Hospital Management System V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate…
- CVE-2023-370703 PoCsCode Projects Hospital Information System 1.0 is vulnerable to Cross Site Scripting (XSS)
- CVE-2023-371391 PoCChakraCore branch master cbb9b was discovered to contain a stack overflow vulnerability via the function…
- CVE-2023-371401 PoCChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function…
- CVE-2023-371411 PoCChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function…
- CVE-2023-371421 PoCChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::EntryPointInfo::HasInlinees().
- CVE-2023-371431 PoCChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function BackwardPass::IsEmptyLoopAfterMemOp().
- CVE-2023-371441 PoCTenda AC10 v15.03.06.26 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.
- CVE-2023-371451 PoCTOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname parameter in the…
- CVE-2023-371461 PoCTOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the…
- CVE-2023-371481 PoCTOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter in the setUssd…
- CVE-2023-371491 PoCTOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the…
- CVE-2023-371522 PoCsProjectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page.…
- CVE-2023-371531 PoCKodExplorer 4.51 contains a Cross-Site Scripting (XSS) vulnerability in the Description box of the Light App creation feature. An attacker…
- CVE-2023-371642 PoCsDiafan CMS v6.0 was discovered to contain a reflected cross-site scripting via the cat_id parameter at /shop/?module=shop&action=search.
- CVE-2023-371651 PoCMillhouse-Project v1.414 was discovered to contain a remote code execution (RCE) vulnerability via the component /add_post_sql.php.
- CVE-2023-371701 PoCTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the…
- CVE-2023-371711 PoCTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the admuser parameter in the…
- CVE-2023-371721 PoCTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter in the…
- CVE-2023-371731 PoCTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the command parameter in the…
- CVE-2023-371741 PoCGPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the dump_isom_scene function at…
- CVE-2023-371771 PoCSQL Injection vulnerability in PMB Services PMB v.7.4.7 and before allows a remote unauthenticated attacker to execute arbitrary code via…
- CVE-2023-371891 PoCA stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute…
- CVE-2023-371901 PoCA stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or…
- CVE-2023-371911 PoCA stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or…
- CVE-2023-371922 PoCsMemory management and protection issues in Bitcoin Core v22 allows attackers to modify the stored sending address within the app's memory,…
- CVE-2023-372061 PoCUploading files which contain symlinks may have allowed an attacker to trick a user into submitting sensitive data to a malicious website.…
- CVE-2023-372502 PoCsUnity Parsec has a TOCTOU race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in "Per…
- CVE-2023-372631 PoCStrapi's field level permissions not being respected in relationship title
- CVE-2023-372641 PoCPipelines do not validate child UIDs
- CVE-2023-372651 PoCIncorrect identification of source IP addresses in CasaOS
- CVE-2023-372661 PoCWeak json web token (JWT) secrets in CasaOS
- CVE-2023-372692 PoCsWinter CMS vulnerable to stored XSS through privileged upload of SVG file
- CVE-2023-372702 PoCsPiwigo SQL Injection vulnerability in "User-Agent"
- CVE-2023-372761 PoCaiohttp vulnerable to HTTP request smuggling
- CVE-2023-372792 PoCsFaktory Web Dashboard can lead to denial of service(DOS) via malicious user input
- CVE-2023-373021 PoCAn issue was discovered in SiteLinksView.php in Wikibase in MediaWiki through 1.39.3. There is XSS via a crafted badge title attribute.…
- CVE-2023-373041 PoCAn issue was discovered in the DoubleWiki extension for MediaWiki through 1.39.3. includes/DoubleWiki.php allows XSS via the column…
- CVE-2023-373051 PoCAn issue was discovered in the ProofreadPage (aka Proofread Page) extension for MediaWiki through 1.39.3. In…
- CVE-2023-373061 PoCMISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the…
- CVE-2023-373611 PoCREDCap 12.0.26 LTS and 12.3.2 Standard allows SQL Injection via scheduling, repeatforms, purpose, app_title, or randomization.
- CVE-2023-374561 PoCThe session restore helper crashed whenever there was no parameter sent to the message handler. This vulnerability affects Firefox for iOS…
- CVE-2023-374603 PoCsPlexus Archiver vulnerable to Arbitrary File Creation in AbstractUnArchiver
- CVE-2023-374611 PoCPath traversal in metersphere
- CVE-2023-374621 PoCImproper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in org.xwiki.platform:xwiki-platform-skin-ui
- CVE-2023-374661 PoCvm2 Sandbox Escape vulnerability
- CVE-2023-374744 PoCsPath traversal in copyparty
- CVE-2023-374752 PoCsAttacker-controlled parameter can cause denial of service in hamba avro
- CVE-2023-374771 PoCCommand injection in firewall ip functionality in 1Panel
- CVE-2023-374782 PoCspnpm incorrectly parses tar archives relative to specification
- CVE-2023-375692 PoCsOS Command Injection Vulnerability in Emagic Data Center Management Suite
- CVE-2023-375801 PoCKEVZimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.
- CVE-2023-375827 PoCsApache RocketMQ: Possible remote code execution when using the update configuration function
- CVE-2023-375961 PoCCross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via a…
- CVE-2023-375971 PoCCross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the…
- CVE-2023-375981 PoCA Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the…
- CVE-2023-375992 PoCsAn issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory
- CVE-2023-376001 PoCOffice Suite Premium Version v10.9.1.42602 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id…
- CVE-2023-376011 PoCOffice Suite Premium v10.9.1.42602 was discovered to contain a local file inclusion (LFI) vulnerability via the component /etc/hosts.
- CVE-2023-376021 PoCAn arbitrary file upload vulnerability in the component /workplace#!explorer of Alkacon OpenCMS v15.0 allows attackers to execute…
- CVE-2023-376071 PoCDirectory Traversal in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information via…
- CVE-2023-376081 PoCAn issue in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information because there…
- CVE-2023-376251 PoCA stored cross-site scripting (XSS) vulnerability in Netbox v3.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted…
- CVE-2023-376271 PoCCode-projects Online Restaurant Management System 1.0 is vulnerable to SQL Injection. Through SQL injection, an attacker can bypass the…
- CVE-2023-376281 PoCOnline Piggery Management System 1.0 is vulnerable to SQL Injection.
- CVE-2023-376294 PoCsOnline Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request…
- CVE-2023-376301 PoCOnline Piggery Management System 1.0 is vulnerable to Cross Site Scripting (XSS). An unauthenticated user can POST JavaScript code to…
- CVE-2023-376351 PoCUVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the…
- CVE-2023-376441 PoCSWFTools 0.9.2 772e55a allows attackers to trigger a large memory-allocation attempt via a crafted document, as demonstrated by pdf2swf.…
- CVE-2023-376451 PoCeyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.
- CVE-2023-376491 PoCIncorrect access control in the component /models/Content of Cockpit CMS v2.5.2 allows unauthorized attackers to access sensitive data.
- CVE-2023-376501 PoCA Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands.
- CVE-2023-376795 PoCsA remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the…
- CVE-2023-376831 PoCOnline Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Profile Page of the Admin.
- CVE-2023-376841 PoCOnline Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Details of the…
- CVE-2023-376851 PoCOnline Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Page of the…
- CVE-2023-376861 PoCOnline Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Nurse Page in the Admin…
- CVE-2023-376871 PoCOnline Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the View Request of Nurse Page in…
- CVE-2023-376881 PoCMaid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Admin page.
- CVE-2023-376891 PoCMaid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Booking Request page.
- CVE-2023-376901 PoCMaid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Search Maid page.
- CVE-2023-376921 PoCAn arbitrary file upload vulnerability in October CMS v3.4.4 allows attackers to execute arbitrary code via a crafted file.
- CVE-2023-377101 PoCTenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the wpapsk_crypto parameter in the…
- CVE-2023-377111 PoCTenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the deviceId parameter in the…
- CVE-2023-377121 PoCTenda AC1206 V15.03.06.23, F1202 V1.2.0.20(408), and FH1202 V1.2.0.20(408) were discovered to contain a stack overflow in the page…
- CVE-2023-377141 PoCTenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function…
- CVE-2023-377151 PoCTenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function…
- CVE-2023-377161 PoCTenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to…
- CVE-2023-377171 PoCTenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to…
- CVE-2023-377181 PoCTenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function…
- CVE-2023-377191 PoCTenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function…
- CVE-2023-377211 PoCTenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function…
- CVE-2023-377221 PoCTenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function…
- CVE-2023-377231 PoCTenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function…
- CVE-2023-377281 PoCIceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter.
- CVE-2023-377341 PoCEZ softmagic MP3 Audio Converter 2.7.3.700 was discovered to contain a buffer overflow.
- CVE-2023-377391 PoCi-doit Pro v25 and below was discovered to be vulnerable to path traversal.
- CVE-2023-377481 PoCngiflib commit 5e7292 was discovered to contain an infinite loop via the function DecodeGifImg at ngiflib.c.
- CVE-2023-377551 PoCi-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no…
- CVE-2023-377561 PoCI-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation. Attackers are…
- CVE-2023-377592 PoCsIncorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticated attackers to…
- CVE-2023-377651 PoCGPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_dump_vrml_sffield function at…
- CVE-2023-377661 PoCGPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the gf_isom_remove_user_data function at…
- CVE-2023-377671 PoCGPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the BM_ParseIndexValueReplace function at…
- CVE-2023-377701 PoCfaust commit ee39a19 was discovered to contain a stack overflow via the component boxppShared::print() at /boxes/ppbox.cpp.
- CVE-2023-377711 PoCArt Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php.
- CVE-2023-377721 PoCOnline Shopping Portal Project v3.1 was discovered to contain a SQL injection vulnerability via the Email parameter at /shopping/login.php.
- CVE-2023-377851 PoCA cross-site scripting (XSS) vulnerability in ImpressCMS v1.4.5 and before allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2023-377862 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Geeklog v2.2.2 allow attackers to execute arbitrary web scripts or HTML via a…
- CVE-2023-377871 PoCMultiple cross-site scripting (XSS) vulnerabilities in Geeklog v2.2.2 allow attackers to execute arbitrary web scripts or HTML via a…
- CVE-2023-377881 PoCgoproxy v1.1 was discovered to contain an issue which can lead to a Denial of service (DoS) via unspecified vectors.
- CVE-2023-377902 PoCsJaspersoft Clarity PPM version 14.3.0.298 was discovered to contain an arbitrary file upload vulnerability via the Profile Picture Upload…
- CVE-2023-377911 PoCD-Link DIR-619L v2.04(TW) was discovered to contain a stack overflow via the curTime parameter at /goform/formLogin.
- CVE-2023-377981 PoCA stored cross-site scripting (XSS) vulnerability in the new REDCap project creation function of Vanderbilt REDCap 13.1.35 allows…
- CVE-2023-378311 PoCAn issue discovered in Elenos ETG150 FM transmitter v3.12 allows attackers to enumerate user accounts based on server responses when…
- CVE-2023-378321 PoCA lack of rate limiting in Elenos ETG150 FM transmitter v3.12 allows attackers to obtain user credentials via brute force and cause other…
- CVE-2023-378331 PoCImproper access control in Elenos ETG150 FM transmitter v3.12 allows attackers to make arbitrary configuration edits that are only…
- CVE-2023-378361 PoClibjpeg commit db33a6e was discovered to contain a reachable assertion via BitMapHook::BitMapHook at bitmaphook.cpp. This vulnerability…
- CVE-2023-378371 PoClibjpeg commit db33a6e was discovered to contain a heap buffer overflow via LineBitmapRequester::EncodeRegion at linebitmaprequester.cpp.…
- CVE-2023-378491 PoCA DLL hijacking vulnerability in Panda Security VPN for Windows prior to version v15.14.8 allows attackers to execute arbitrary code via…
- CVE-2023-378971 PoCServer-side Template Injection (SSTI) in grav
- CVE-2023-378981 PoCSafe mode Cross-site Scripting (XSS) vulnerability in Joplin
- CVE-2023-379031 PoCSandbox Escape in vm2
- CVE-2023-379071 PoCCryptomator's MSI installer allows local privilege escalation
- CVE-2023-379081 PoCorg.xwiki.rendering:xwiki-rendering-xml Improper Neutralization of Invalid Characters in Identifiers in Web Pages vulnerability
- CVE-2023-379101 PoCorg.xwiki.platform:xwiki-platform-attachment-api vulnerable to Missing Authorization on Attachment Move
- CVE-2023-379151 PoCMalformed PID_PROPERTY_LIST parameter in DATA submessage remotely crashes OpenDDS
- CVE-2023-379161 PoCLeak password hash of any user
- CVE-2023-379171 PoCPrivilege Escalation in kubepi
- CVE-2023-379182 PoCsAPI token authentication bypass in HTTP endpoints in Dapr
- CVE-2023-379413 PoCsApache Superset: Metadata db write access can lead to remote code execution
- CVE-2023-379794 PoCsWordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)
- CVE-2023-379882 PoCsWordPress Contact Form Generator Plugin <= 2.5.5 is vulnerable to Cross Site Scripting (XSS)
- CVE-2023-379991 PoCWordPress HT Mega Absolute Addons for Elementor plugin <= 2.2.0 - Unauthenticated Privilege Escalation vulnerability