CVE-2023-39000 to CVE-2023-39999
132 CVEs with public proof-of-concept exploits.
- CVE-2023-390001 PoCA reflected cross-site scripting (XSS) vulnerability in the component /ui/diagnostics/log/core/ of OPNsense Community Edition before 23.7…
- CVE-2023-390011 PoCA command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Business Edition before…
- CVE-2023-390022 PoCsA cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition before 23.7 and…
- CVE-2023-390031 PoCOPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory…
- CVE-2023-390041 PoCInsecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2…
- CVE-2023-390051 PoCInsecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2.
- CVE-2023-390061 PoCThe Crash Reporter (crash_reporter.php) component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 mishandles…
- CVE-2023-390072 PoCs/ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via…
- CVE-2023-390081 PoCA command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business…
- CVE-2023-390101 PoCBoofCV 0.42 was discovered to contain a code injection vulnerability via the component boofcv.io.calibration.CalibrationIO.load. This…
- CVE-2023-390171 PoCquartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component…
- CVE-2023-390263 PoCsDirectory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive…
- CVE-2023-390621 PoCCross Site Scripting vulnerability in Spipu HTML2PDF before v.5.2.8 allows a remote attacker to execute arbitrary code via a crafted…
- CVE-2023-390631 PoCBuffer Overflow vulnerability in RaidenFTPD 2.4.4005 allows a local attacker to execute arbitrary code via the Server name field of the…
- CVE-2023-390701 PoCAn issue in Cppcheck 2.12 dev allows a local attacker to execute arbitrary code via the removeContradiction parameter in token.cpp:1934.
- CVE-2023-390751 PoCRenault Zoe EV 2021 automotive infotainment system versions 283C35202R to 283C35519R (builds 11.10.2021 to 16.01.2023) allows attackers to…
- CVE-2023-391082 PoCsrconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Function of…
- CVE-2023-391092 PoCsrconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Function of…
- CVE-2023-391102 PoCsrconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPath.php. This…
- CVE-2023-391131 PoCngiflib commit fb271 was discovered to contain a segmentation violation via the function "main" at gif2tag.c. This vulnerability is…
- CVE-2023-391141 PoCngiflib commit 84a75 was discovered to contain a segmentation violation via the function SDL_LoadAnimatedGif at ngiflibSDL.c. This…
- CVE-2023-391153 PoCsinstall/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document.
- CVE-2023-391212 PoCsemlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.
- CVE-2023-391251 PoCNTSC-CRT 2.2.1 has an integer overflow and out-of-bounds write in loadBMP in bmp_rw.c because a file's width, height, and BPP are not…
- CVE-2023-391351 PoCAn issue in Zip Swift v2.1.2 allows attackers to execute a path traversal attack via a crafted zip entry.
- CVE-2023-391362 PoCsAn unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to cause a Denial of Service (DoS) via a…
- CVE-2023-391372 PoCsAn issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.
- CVE-2023-391381 PoCAn issue in ZIPFoundation v0.9.16 allows attackers to execute a path traversal via extracting a crafted zip file.
- CVE-2023-391391 PoCAn issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file.
- CVE-2023-391413 PoCswebui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.
- CVE-2023-391434 PoCsPaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files.…
- CVE-2023-391441 PoCElement55 KnowMore appliances version 21 and older was discovered to store passwords in plaintext.
- CVE-2023-391472 PoCsAn arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.
- CVE-2023-391671 PoCSENEC: Storage Box V1,V2 and V3 affected by improper access control vulnerability
- CVE-2023-391711 PoCSENEC Storage Box V1,V2 and V3 accidentially expose a management interface
- CVE-2023-392651 PoCApache Superset: Possible Unauthorized Registration of SQLite Database Connections
- CVE-2023-393061 PoCWordPress Avada Builder plugin <= 3.11.1 - Reflected Cross Site Scripting (XSS) vulnerability
- CVE-2023-393091 PoCWordPress Avada Builder plugin <= 3.11.1 - Auth. SQL Injection vulnerability
- CVE-2023-393101 PoCWordPress Avada Builder plugin <= 3.11.1 - Authenticated Broken Access Control vulnerability
- CVE-2023-393111 PoCWordPress Avada Builder plugin <= 3.11.1 - Cross Site Request Forgery (CSRF) vulnerability
- CVE-2023-393201 PoCArbitrary code execution via go.mod toolchain directive in cmd/go
- CVE-2023-393251 PoCHTTP/2 rapid reset can cause excessive work in net/http
- CVE-2023-393501 PoCIncorrect offset calculation leading to denial of service in FreeRDP
- CVE-2023-393511 PoCFreeRDP Null Pointer Dereference leading denial of service
- CVE-2023-393521 PoCInvalid offset validation leading to Out Of Bound Write in FreeRDP
- CVE-2023-393531 PoCMissing offset validation leading to Out Of Bound Read in FreeRDP
- CVE-2023-393541 PoCFreeRDP Out-Of-Bounds Read in nsc_rle_decompress_data
- CVE-2023-393551 PoCFreeRDP Use-After-Free in RDPGFX_CMDID_RESETGRAPHICS
- CVE-2023-393561 PoCMissing offset validation leading to Out-of-Bounds Read in FreeRDP
- CVE-2023-393571 PoCA Defect in sql_save() Causes Multiple SQL Injection Vulnerabilities in Cacti
- CVE-2023-393581 PoCAuthenticated SQL injection vulnerability in reports_user.php in Cacti
- CVE-2023-393591 PoCAuthenticated SQL injection vulnerability in graphs.php in Cacti
- CVE-2023-393601 PoCReflected Cross-site Scripting in graphs_new.php in Cacti
- CVE-2023-393615 PoCsUnauthenticated SQL Injection in graph_view.php in Cacti
- CVE-2023-393626 PoCsAuthenticated command injection in SNMP options of a Device
- CVE-2023-393641 PoCOpen redirect in change password functionality in Cacti
- CVE-2023-393651 PoCUnchecked regular expressions can lead to SQL Injection and data leakage in Cacti
- CVE-2023-393661 PoCStored Cross-site Scripting in data_sources.php through Device-Name in 'select' input in Cacti
- CVE-2023-394431 PoCMultiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functionality of GTKWave 3.3.115. A specially-crafted .lxt2 file…
- CVE-2023-394441 PoCMultiple out-of-bounds write vulnerabilities exist in the LXT2 parsing functionality of GTKWave 3.3.115. A specially-crafted .lxt2 file…
- CVE-2023-394531 PoCA use-after-free vulnerability exists in the tif_parse_sub_IFD functionality of Accusoft ImageGear 20.1. A specially crafted malformed…
- CVE-2023-394751 PoCInductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability
- CVE-2023-394761 PoCInductive Automation Ignition JavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability
- CVE-2023-395101 PoCStored Cross-site Scripting in reports_admin.php through Device-Name in 'select' input in Cacti
- CVE-2023-395111 PoCStored Cross-Site-Scripting on reports_admin.php device name in Cacti
- CVE-2023-395121 PoCStored Cross-site Scripting on data_sources.php device name view in Cacti
- CVE-2023-395131 PoCStored Cross-site Scripting on host.php verbose data-query debug view in Cacti
- CVE-2023-395141 PoCStored Cross-site Scripting on graphs.php data template formated name view in Cacti
- CVE-2023-395151 PoCStored Cross-site Scripting on data_debug.php datasource path view in Cacti
- CVE-2023-395161 PoCStored Cross-Site-Scripting on data_sources.php debug html-block in Cacti
- CVE-2023-395171 PoCCross site scripting (XSS) when clicking on an untrusted `<map>` link in Joplin
- CVE-2023-395201 PoCCryptomator vulnerable to Local Elevation of Privileges
- CVE-2023-395232 PoCsScanCode.io command injection in docker image fetch process
- CVE-2023-395261 PoCPrestaShopSQL manager vulnerability (potential RCE)
- CVE-2023-395391 PoCFailure when uploading a Logo image file
- CVE-2023-395421 PoCA code execution vulnerability exists in the Javascript saveAs API of Foxit Reader 12.1.3.15356. A specially crafted malformed file can…
- CVE-2023-395511 PoCPHPGurukul Online Security Guards Hiring System v.1.0 is vulnerable to SQL Injection via osghs/admin/search.php.
- CVE-2023-395581 PoCAudimexEE v15.0 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the Show Kai Data component.
- CVE-2023-395591 PoCAudimexEE 15.0 was discovered to contain a full path disclosure vulnerability.
- CVE-2023-395603 PoCsECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php.
- CVE-2023-395621 PoCGPAC v2.3-DEV-rev449-g5948e4f70-master was discovered to contain a heap-use-after-free via the gf_bs_align function at bitstream.c. This…
- CVE-2023-395751 PoCA reflected cross-site scripting (XSS) vulnerability in the url_str URL parameter of ISL ARP Guard v4.0.2 allows attackers to execute…
- CVE-2023-395931 PoCInsecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated…
- CVE-2023-395981 PoCCross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitrary code via a…
- CVE-2023-395991 PoCCross-Site Scripting (XSS) vulnerability in CSZ CMS v.1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Social…
- CVE-2023-396001 PoCIceWarp 11.4.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the color parameter.
- CVE-2023-396101 PoCAn issue in TP-Link Tapo C100 v1.1.15 Build 211130 Rel.15378n(4555) and before allows attackers to cause a Denial of Service (DoS) via…
- CVE-2023-396111 PoCAn issue in Software FX Chart FX 7 version 7.0.4962.20829 allows attackers to enumerate and read files from the local filesystem by…
- CVE-2023-396122 PoCsA cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 allows an authenticated attacker to escalate privileges to…
- CVE-2023-396151 PoCXmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxml2/SAX2.c. This…
- CVE-2023-396312 PoCsAn issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr…
- CVE-2023-396391 PoCLeoTheme leoblog up to v3.1.2 was discovered to contain a SQL injection vulnerability via the component LeoBlogBlog::getListBlogs.
- CVE-2023-396411 PoCActive Design psaffiliate before v1.9.8 was discovered to contain a SQL injection vulnerability via the component…
- CVE-2023-396421 PoCCarts Guru cartsguru up to v2.4.2 was discovered to contain a SQL injection vulnerability via the component…
- CVE-2023-396431 PoCBl Modules xmlfeeds before v3.9.8 was discovered to contain a SQL injection vulnerability via the component SearchApiXml::Xmlfeeds().
- CVE-2023-396501 PoCTheme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /tvcmsblog/single.
- CVE-2023-396591 PoCAn issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the…
- CVE-2023-396601 PoCAn issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the…
- CVE-2023-396611 PoCAn issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak function.
- CVE-2023-396621 PoCAn issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in…
- CVE-2023-396751 PoCSimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php.
- CVE-2023-396761 PoCFieldPopupNewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the…
- CVE-2023-396772 PoCsMyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information…
- CVE-2023-396811 PoCCuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at…
- CVE-2023-396831 PoCCross Site Scripting (XSS) vulnerability in EasyEmail v.4.12.2 and before allows a local attacker to execute arbitrary code via the user…
- CVE-2023-396851 PoCAn issue in hjson-java up to v3.0.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted JSON string.
- CVE-2023-396951 PoCInsufficient session expiration in Elenos ETG150 FM Transmitter v3.12 allows attackers to arbitrarily change transmitter configuration and…
- CVE-2023-397001 PoCIceWarp Mail Server v10.4.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the color parameter.
- CVE-2023-397071 PoCA stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute…
- CVE-2023-397081 PoCA stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute…
- CVE-2023-397091 PoCMultiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute…
- CVE-2023-397101 PoCMultiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute…
- CVE-2023-397111 PoCMultiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute…
- CVE-2023-397121 PoCMultiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute…
- CVE-2023-397141 PoCMultiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute…
- CVE-2023-397411 PoClrzip v0.651 was discovered to contain a heap overflow via the libzpaq::PostProcessor::write(int) function at /libzpaq/libzpaq.cpp. This…
- CVE-2023-397432 PoCslrzip-next LZMA v23.01 was discovered to contain an access violation via the component /bz3_decode_block src/libbz3.c.
- CVE-2023-397771 PoCA cross-site scripting (XSS) vulnerability in the Admin Control Panel of vBulletin 5.7.5 and 6.0.0 allows attackers to execute arbitrary…
- CVE-2023-397801 PoCKEVOn ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm…
- CVE-2023-397851 PoCTenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the list parameter in the set_qosMib_list function.
- CVE-2023-397861 PoCTenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sscanf function.
- CVE-2023-397961 PoCSQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code…
- CVE-2023-398271 PoCTenda A18 V15.13.07.09 was discovered to contain a stack overflow via the rule_info parameter in the formAddMacfilterRule function.
- CVE-2023-398281 PoCTenda A18 V15.13.07.09 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet function.
- CVE-2023-398291 PoCTenda A18 V15.13.07.09 was discovered to contain a stack overflow via the wpapsk_crypto2_4g parameter in the fromSetWirelessRepeat function.
- CVE-2023-398341 PoCPbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function.
- CVE-2023-399101 PoCThe cryptocurrency wallet entropy seeding mechanism used in Libbitcoin Explorer 3.0.0 through 3.6.0 is weak, aka the Milk Sad issue. The…
- CVE-2023-399641 PoC1Panel O&M management panel has a background arbitrary file reading vulnerability
- CVE-2023-399652 PoCs1Panel Unauthorized access in Backend
- CVE-2023-399661 PoC1Panel arbitrary file write vulnerability exists in the background
- CVE-2023-399671 PoCFull read and controlled SSRF through URL parameter when testing a request inside wiremock-studio
- CVE-2023-399991 PoCWordPress < 6.3.2 is vulnerable to Broken Access Control