CVE-2023-38000 to CVE-2023-38999
105 CVEs with public proof-of-concept exploits.
- CVE-2023-380001 PoCAuth. Stored Cross-Site Scripting (XSS) vulnerability in WordPress core and Gutenberg plugin via Navigation Links Block
- CVE-2023-380359 PoCsKEVA security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass…
- CVE-2023-380391 PoCWhen curl retrieves an HTTP response, it stores the incoming headers so thatthey can be accessed later via the libcurl headers…
- CVE-2023-380401 PoCA reflected XSS vulnerability exists in Revive Adserver 5.4.1 and earlier versions..
- CVE-2023-380411 PoCA logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process…
- CVE-2023-380961 PoCNETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability
- CVE-2023-380981 PoCNETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability
- CVE-2023-381201 PoCAdtran SR400ac ping Command Injection Remote Code Execution Vulnerability
- CVE-2023-381271 PoCAn integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause the…
- CVE-2023-381282 PoCsAn out-of-bounds write vulnerability exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted…
- CVE-2023-381466 PoCsWindows Themes Remote Code Execution Vulnerability
- CVE-2023-381901 PoCAn issue was discovered in SuperWebMailer 9.00.0.01710. It allows Export SQL Injection via the size parameter.
- CVE-2023-381911 PoCAn issue was discovered in SuperWebMailer 9.00.0.01710. It allows spamtest_external.php XSS via a crafted filename.
- CVE-2023-381922 PoCsAn issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords.
- CVE-2023-381931 PoCAn issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command line.
- CVE-2023-381942 PoCsAn issue was discovered in SuperWebMailer 9.00.0.01710. It allows keepalive.php XSS via a GET parameter.
- CVE-2023-382031 PoCKEVAnalysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE
- CVE-2023-382041 PoCBypass APSB23-41 (CVE-2023-38203) - Pre-Auth RCE ColdFusion 2021 Update 8
- CVE-2023-382051 PoCKEVColdFusion Bypass - Vulnerability disclosure in ColdFusion | BYPASS CVE-2023-29298
- CVE-2023-382521 PoCW3m: out of bounds read in strnew_size() at w3m/str.c
- CVE-2023-382531 PoCW3m: out of bounds read in growbuf_to_str() at w3m/indep.c
- CVE-2023-383342 PoCsOmnis Studio 10.22.00 has incorrect access control. It advertises an irreversible feature for locking classes within Omnis libraries: it…
- CVE-2023-383352 PoCsOmnis Studio 10.22.00 has incorrect access control. It advertises a feature for making Omnis libraries "always private" - this is supposed…
- CVE-2023-383461 PoCAn issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also…
- CVE-2023-383573 PoCsSession tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized access to user…
- CVE-2023-383781 PoCThe web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to execute arbitrary code…
- CVE-2023-383791 PoCThe web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to change the admin…
- CVE-2023-383891 PoCWordPress Jupiter X Core plugin <= 3.3.8 - Unauthenticated Account Takeover vulnerability
- CVE-2023-3840810 PoCsThe PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution…
- CVE-2023-384331 PoCFujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticated attacker to…
- CVE-2023-384342 PoCsxHTTP 72f812d has a double free in close_connection in xhttp.c via a malformed HTTP request method.
- CVE-2023-384871 PoCHedgeDoc API allows to hide existing notes
- CVE-2023-384901 PoCKirby XML External Entity (XXE) vulnerability in the XML data handler
- CVE-2023-384951 PoCCrossplane vulnerable to possible image tampering from missing image validation for Packages
- CVE-2023-385012 PoCscopyparty vulnerable to reflected cross-site scripting via k304 parameter
- CVE-2023-385061 PoCCross-site Scripting (XSS) when pasting HTML into the rich text editor in Joplin
- CVE-2023-385071 PoCStrapi Improper Rate Limiting vulnerability
- CVE-2023-3854510 PoCsThis flaw makes curl overflow a heap based buffer in the SOCKS5 proxyhandshake.When curl is asked to pass along the host name to the…
- CVE-2023-385711 PoCThis issue was addressed with improved validation of symlinks. This issue is fixed in macOS Big Sur 11.7.9, macOS Monterey 12.6.8, macOS…
- CVE-2023-385731 PoCA use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles a signature field. A specially crafted Javascript code…
- CVE-2023-386001 PoCThe issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Ventura 13.5, Safari 16.6,…
- CVE-2023-386091 PoCAn injection issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.5. An app may be able to bypass…
- CVE-2023-386171 PoCOffice Suite Premium Version v10.9.1.42602 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the filter…
- CVE-2023-386321 PoCasync-sockets-cpp through 0.3.1 has a stack-based buffer overflow in tcpsocket.hpp when processing malformed TCP packets.
- CVE-2023-386332 PoCsA directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on…
- CVE-2023-3864652 PoCsMetabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server,…
- CVE-2023-386661 PoCBento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in mp4encrypt.
- CVE-2023-386691 PoCUse after free in paddle.diagonal in PaddlePaddle before 2.5.0. This resulted in a potentially exploitable condition.
- CVE-2023-386701 PoCNull pointer dereference in paddle.flip
- CVE-2023-386711 PoCHeap buffer overflow in paddle.trace
- CVE-2023-386721 PoCFPE in paddle.linalg.matrix_power
- CVE-2023-386731 PoCCommand injection in fs.py
- CVE-2023-386871 PoCExecution of arbitrary JavaScript from Svelecte item names
- CVE-2023-386981 PoC.eth registrar controller can shorten the duration of registered names
- CVE-2023-387011 PoCHydra's committed UTxOs at Commit validator and UTxOs at Initial validator can be spent arbitrarily by anyone
- CVE-2023-387021 PoCKnowage Server vulnerable to path traversal via upload functionality
- CVE-2023-387091 PoCApache HTTP Server: HTTP response splitting
- CVE-2023-387431 PoCZoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine.
- CVE-2023-388173 PoCsAn issue in Inspect Element Ltd Echo.ac v.5.2.1.0 allows a local attacker to gain privileges via a crafted command to the echo_driver.sys…
- CVE-2023-388291 PoCAn issue in NETIS SYSTEMS WF2409E v.3.6.42541 allows a remote attacker to execute arbitrary code via the ping and traceroute functions of…
- CVE-2023-3883172 PoCsKEVRARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The…
- CVE-2023-388363 PoCsFile Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type…
- CVE-2023-388401 PoCBitwarden Desktop 2023.7.0 and below allows an attacker with local access to obtain sensitive information via the Bitwarden.exe process.
- CVE-2023-388441 PoCSQL injection vulnerability in PMB v.7.4.7 and earlier allows a remote attacker to execute arbitrary code via the thesaurus parameter in…
- CVE-2023-388611 PoCAn issue in Wavlink WL_WNJ575A3 v.R75A3_V1410_220513 allows a remote attacker to execute arbitrary code via username parameter of the…
- CVE-2023-388621 PoCAn issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the destination parameter of sub_431F64 function in…
- CVE-2023-388631 PoCAn issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the ifname and mac parameters in the sub_410074…
- CVE-2023-388641 PoCAn issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter in the sub_41171C…
- CVE-2023-388651 PoCCOMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST request messages to…
- CVE-2023-388661 PoCCOMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588. Attackers can send POST request messages to…
- CVE-2023-388701 PoCA SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book has a feature to…
- CVE-2023-388721 PoCAn Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any…
- CVE-2023-388731 PoCThe commit 3730880 (April 2023) and v.0.9-beta1 of gugoan Economizzer is vulnerable to Clickjacking. Clickjacking, also known as a "UI…
- CVE-2023-388741 PoCA remote code execution (RCE) vulnerability via an insecure file upload exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880…
- CVE-2023-388751 PoCA reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary…
- CVE-2023-388771 PoCA host header injection vulnerability exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). By sending a specially…
- CVE-2023-388791 PoCThe Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to read arbitrary files via a directory traversal…
- CVE-2023-388861 PoCAn issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.
- CVE-2023-388881 PoCCross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and…
- CVE-2023-388903 PoCsOnline Shopping Portal Project 3.1 allows remote attackers to execute arbitrary SQL commands/queries via the login form, leading to…
- CVE-2023-389021 PoCA command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 series switches…
- CVE-2023-389041 PoCA Cross Site Scripting (XSS) vulnerability in Netlify CMS v.2.10.192 allows a remote attacker to execute arbitrary code via a crafted…
- CVE-2023-389051 PoCSQL injection vulnerability in Jeecg-boot v.3.5.0 and before allows a local attacker to cause a denial of service via the Benchmark,…
- CVE-2023-389101 PoCCSZ CMS 1.3.0 is vulnerable to cross-site scripting (XSS), which allows attackers to execute arbitrary web scripts or HTML via a crafted…
- CVE-2023-389111 PoCA Cross-Site Scripting (XSS) vulnerability in CSZ CMS 1.3.0 allows attackers to execute arbitrary code via a crafted payload to the…
- CVE-2023-389121 PoCSQL injection vulnerability in Super Store Finder PHP Script v.3.6 allows a remote attacker to execute arbitrary code via a crafted…
- CVE-2023-389431 PoCShuiZe_0x727 v1.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /iniFile/config.ini.
- CVE-2023-389471 PoCAn arbitrary file upload vulnerability in the /languages/install.php component of WBCE CMS v1.6.1 allows attackers to execute arbitrary…
- CVE-2023-389481 PoCAn arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers to execute…
- CVE-2023-389502 PoCsKEVA path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via…
- CVE-2023-389511 PoCZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on…
- CVE-2023-389522 PoCsInsecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that…
- CVE-2023-389601 PoCInsecure Permissions issue in Raiden Professional Server RaidenFTPD v.2.4 build 4005 allows a local attacker to gain privileges and…
- CVE-2023-389611 PoCBuffer Overflwo vulnerability in JerryScript Project jerryscript v.3.0.0 allows a remote attacker to execute arbitrary code via the…
- CVE-2023-389641 PoCCreative Item Academy LMS 6.0 was discovered to contain a cross-site scripting (XSS) vulnerability.
- CVE-2023-389652 PoCsLost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.
- CVE-2023-389692 PoCsCross Site Scripting vulnerabiltiy in Badaso v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the title…
- CVE-2023-389702 PoCsCross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload…
- CVE-2023-389712 PoCsCross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload…
- CVE-2023-389751 PoC* Buffer Overflow vulnerability in qdrant v.1.3.2 allows a remote attacker cause a denial of service via the chucnked_vectors.rs component.
- CVE-2023-389921 PoCjeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.
- CVE-2023-389961 PoCAn issue in all versions of Douran DSGate allows a local authenticated privileged attacker to execute arbitrary code via the debug command.
- CVE-2023-389971 PoCA directory traversal vulnerability in the Captive Portal templates of OPNsense Community Edition before 23.7 and Business Edition before…
- CVE-2023-389981 PoCAn open redirect in the Login page of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to…
- CVE-2023-389991 PoCA Cross-Site Request Forgery (CSRF) in the System Halt API (/system/halt) of OPNsense Community Edition before 23.7 and Business Edition…