CVE-2023-3000 to CVE-2023-3999
385 CVEs with public proof-of-concept exploits.
- CVE-2023-30031 PoCSourceCodester Train Station Ticketing System GET Parameter manage_prices.php sql injection
- CVE-2023-30041 PoCSourceCodester Simple Chat System POST Parameter sql injection
- CVE-2023-30051 PoCSourceCodester Local Service Search Engine Management System POST Parameter cross site scripting
- CVE-2023-30071 PoCningzichun Student Management System Password Reset resetPassword.php password recovery
- CVE-2023-30081 PoCningzichun Student Management System login.php sql injection
- CVE-2023-30092 PoCsCross-site Scripting (XSS) - Stored in nilsteampassnet/teampass
- CVE-2023-30121 PoCNULL Pointer Dereference in gpac/gpac
- CVE-2023-30131 PoCUnchecked Return Value in gpac/gpac
- CVE-2023-30141 PoCBeipyVideoResolution admincore.php cross site scripting
- CVE-2023-30151 PoCyiwent Vip Video Analysis title.php server-side request forgery
- CVE-2023-30161 PoCyiwent Vip Video Analysis admincore.php cross site scripting
- CVE-2023-30171 PoCSourceCodester Lost and Found Information System Manage User Page cross site scripting
- CVE-2023-30181 PoCSourceCodester Lost and Found Information System access control
- CVE-2023-30201 PoCCross-site Scripting (XSS) - Reflected in mkucej/i-librarian-free
- CVE-2023-30211 PoCCross-site Scripting (XSS) - Stored in mkucej/i-librarian-free
- CVE-2023-30291 PoCGuangdong Pythagorean OA Office System delete cross-site request forgery
- CVE-2023-30351 PoCGuangdong Pythagorean OA Office System Schedule cross site scripting
- CVE-2023-30411 PoCAutochat <= 1.1.7- Unauthenticated Stored XSS
- CVE-2023-30441 PoCDivide-by-zero in Xpdf 4.04 due to very large page size
- CVE-2023-30472 PoCsSQLi in TMT's Lockcell
- CVE-2023-30481 PoCIDOR in TMT's Lockcell
- CVE-2023-30491 PoCFile Upload in TMT's Lockcell
- CVE-2023-30501 PoCAuthentication Bypass in TMT's Lockcell
- CVE-2023-30561 PoCYFCMF index.php path traversal
- CVE-2023-30571 PoCYFCMF Ajax.php path traversal
- CVE-2023-30581 PoC07FLY CRM User Profile cross site scripting
- CVE-2023-30591 PoCSourceCodester Online Exam Form Submission update_s6.php sql injection
- CVE-2023-30671 PoCCross-site Scripting (XSS) - Stored in zadam/trilium
- CVE-2023-30681 PoCCampcodes Retro Cellphone Online Store modal_add_product.php sql injection
- CVE-2023-30691 PoCUnverified Password Change in tsolucio/corebos
- CVE-2023-30701 PoCCross-site Scripting (XSS) - Stored in tsolucio/corebos
- CVE-2023-30711 PoCCross-site Scripting (XSS) - Stored in tsolucio/corebos
- CVE-2023-30731 PoCCross-site Scripting (XSS) - Stored in tsolucio/corebos
- CVE-2023-30761 PoCMStore API < 3.9.9 - Unauthenticated Privilege Escalation
- CVE-2023-30772 PoCsMStore API < 3.9.8 - Unauthenticated Blind SQLi
- CVE-2023-30793 PoCsKEVType confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2023-30831 PoCCross-site Scripting (XSS) - Stored in nilsteampassnet/teampass
- CVE-2023-30841 PoCCross-site Scripting (XSS) - Stored in nilsteampassnet/teampass
- CVE-2023-30861 PoCCross-site Scripting (XSS) - Stored in nilsteampassnet/teampass
- CVE-2023-30941 PoCcode-projects Agro-School Management System btn_functions.php doUpdateQuestion sql injection
- CVE-2023-30951 PoCImproper Access Control in nilsteampassnet/teampass
- CVE-2023-30961 PoCKylinSoft kylin-software-properties changedSource access control
- CVE-2023-30971 PoCKylinSoft kylin-software-properties setMainSource os command injection
- CVE-2023-30981 PoCKylinSoft youker-assistant restore_all_sound_file path traversal
- CVE-2023-30991 PoCKylinSoft youker-assistant Arbitrary File dbus.SystemBus delete_file access control
- CVE-2023-31001 PoCIBOS del actionDel sql injection
- CVE-2023-31021 PoCInsertion of Sensitive Information Into Sent Data in GitLab
- CVE-2023-31051 PoCLearnDash LMS <= 4.6.0 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Password Change
- CVE-2023-31091 PoCCross-site Scripting (XSS) - Stored in admidio/admidio
- CVE-2023-31151 PoCIncorrect User Management in GitLab
- CVE-2023-31181 PoCExport All URLs < 4.6 - Reflected XSS
- CVE-2023-31191 PoCSourceCodester Service Provider Management System view.php sql injection
- CVE-2023-31201 PoCSourceCodester Service Provider Management System view_service.php sql injection
- CVE-2023-31211 PoCDahua Smart Parking Management image server-side request forgery
- CVE-2023-31241 PoCElementor Pro <= 3.11.6 - Authenticated(Subscriber+) Privilege Escalation via update_page_option
- CVE-2023-31282 PoCsGrafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily…
- CVE-2023-31291 PoCURL Shortify < 1.7.0 - Admin+ Cross Site Scripting
- CVE-2023-31301 PoCShort URL < 1.6.5 - Admin+ Cross Site Scripting
- CVE-2023-31311 PoCMStore API < 3.9.7 - Subscriber+ Unauthorized Settings Update
- CVE-2023-31331 PoCTutor LMS < 2.2.1 - Unauthenticated Access to Tutor LMS Lesson Resources via REST API
- CVE-2023-31341 PoCForminator < 1.24.4 - Reflected XSS
- CVE-2023-31392 PoCsProtect WP Admin < 4.0 - Unauthenticated Protection Bypass
- CVE-2023-31421 PoCCross-site Scripting (XSS) - Stored in microweber/microweber
- CVE-2023-31431 PoCSourceCodester Online Discussion Forum Site manage_post.php cross site scripting
- CVE-2023-31441 PoCSourceCodester Online Discussion Forum Site manage_post.php cross site scripting
- CVE-2023-31451 PoCSourceCodester Online Discussion Forum Site sql injection
- CVE-2023-31461 PoCSourceCodester Online Discussion Forum Site manage_category.php sql injection
- CVE-2023-31471 PoCSourceCodester Online Discussion Forum Site view_category.php sql injection
- CVE-2023-31481 PoCSourceCodester Online Discussion Forum Site manage_post.php sql injection
- CVE-2023-31491 PoCSourceCodester Online Discussion Forum Site manage_user.php sql injection
- CVE-2023-31501 PoCSourceCodester Online Discussion Forum Site manage_post.php sql injection
- CVE-2023-31511 PoCSourceCodester Online Discussion Forum Site manage_user.php sql injection
- CVE-2023-31521 PoCSourceCodester Online Discussion Forum Site view_post.php sql injection
- CVE-2023-31541 PoCNextGEN Gallery < 3.39 - Admin+ PHAR Deserialization
- CVE-2023-31551 PoCNextGEN Gallery < 3.39 - Admin+ Arbitrary File Read and Delete
- CVE-2023-31591 PoCA use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel. In this flaw a local…
- CVE-2023-31651 PoCSourceCodester Life Insurance Management System POST Parameter insertNominee.php cross site scripting
- CVE-2023-31692 PoCstagDiv Composer < 4.2 - Unauthenticated Stored XSS
- CVE-2023-31701 PoCtagDiv Composer < 4.2 - Admin+ Stored XSS
- CVE-2023-31731 PoCImproper Restriction of Excessive Authentication Attempts in froxlor/froxlor
- CVE-2023-31751 PoCAI ChatBot < 4.6.1 - Admin+ Stored Cross-Site Scripting
- CVE-2023-31761 PoCSourceCodester Lost and Found Information System manage_user.php sql injection
- CVE-2023-31771 PoCSourceCodester Lost and Found Information System view_inquiry.php sql injection
- CVE-2023-31781 PoCPOST SMTP Mailer < 2.5.7 - Arbitrary Log Deletion via CSRF
- CVE-2023-31791 PoCPOST SMTP Mailer < 2.5.7 - Account Takeover via CSRF
- CVE-2023-31821 PoCMembership Plugin - Restrict Content < 3.2.3 - Reflected XSS
- CVE-2023-31831 PoCSourceCodester Performance Indicator System addproduct.php cross site scripting
- CVE-2023-31843 PoCsSourceCodester Sales Tracker Management System cross site scripting
- CVE-2023-31861 PoCSupsystic Popup < 1.10.19 - Prototype Pollution
- CVE-2023-31872 PoCsPHPGurukul Teachers Record Management System Profile Picture changeimage.php unrestricted upload
- CVE-2023-31882 PoCsServer-Side Request Forgery (SSRF) in owncast/owncast
- CVE-2023-31891 PoCSourceCodester Online School Fees System POST Parameter branch.php cross site scripting
- CVE-2023-31901 PoCImproper Encoding or Escaping of Output in nilsteampassnet/teampass
- CVE-2023-31911 PoCCross-site Scripting (XSS) - Stored in nilsteampassnet/teampass
- CVE-2023-31921 PoCSession Fixation in froxlor/froxlor
- CVE-2023-31971 PoCMStore API <= 4.0.1 - Unauthenticated SQL Injection
- CVE-2023-32051 PoCInefficient Regular Expression Complexity in GitLab
- CVE-2023-32061 PoCChengdu VEC40G denial of service
- CVE-2023-32081 PoCRoadFlow Visual Process Engine .NET Core Mvc Login sql injection
- CVE-2023-32091 PoCMStore API < 3.9.7 - Settings Update via CSRF
- CVE-2023-32101 PoCInefficient Regular Expression Complexity in GitLab
- CVE-2023-32111 PoCWordPress Database Administrator <= 1.0.3 - Unauthenticated SQL Injection
- CVE-2023-32181 PoCRace Condition within a Thread in it-novum/openitcockpit
- CVE-2023-32193 PoCsEventON < 2.1.2 - Unauthenticated Post Access via IDOR
- CVE-2023-32241 PoCCode Injection in nuxt/nuxt
- CVE-2023-32251 PoCFloat menu < 5.0.3 - Admin+ Stored Cross-Site Scripting
- CVE-2023-32261 PoCPopup Builder < 4.2.0 - Admin+ Stored Cross-Site Scripting
- CVE-2023-32271 PoCInsufficient Granularity of Access Control in fossbilling/fossbilling
- CVE-2023-32281 PoCBusiness Logic Errors in fossbilling/fossbilling
- CVE-2023-32291 PoCBusiness Logic Errors in fossbilling/fossbilling
- CVE-2023-32301 PoCMissing Authorization in fossbilling/fossbilling
- CVE-2023-32311 PoCUJCMS ZIP Package information disclosure
- CVE-2023-32321 PoCZhong Bang CRMEB Image Upload app_auth deserialization
- CVE-2023-32331 PoCZhong Bang CRMEB PublicController.php get_image_base64 server-side request forgery
- CVE-2023-32341 PoCZhong Bang CRMEB PublicController.php put_image deserialization
- CVE-2023-32351 PoCmccms Comic.php pic_api server-side request forgery
- CVE-2023-32361 PoCmccms Comic.php pic_save server-side request forgery
- CVE-2023-32371 PoCOTCMS hard-coded password
- CVE-2023-32381 PoCOTCMS server-side request forgery
- CVE-2023-32391 PoCOTCMS path traversal
- CVE-2023-32401 PoCOTCMS usersNews_deal.php path traversal
- CVE-2023-32411 PoCOTCMS path traversal
- CVE-2023-32441 PoCComments Like Dislike <= 1.2.0 - Missing Authorization to Authenticated (Subscriber+) Plugin Setting Reset
- CVE-2023-32451 PoCFloating Chat Widget < 3.1.2 - Admin+ Stored Cross-Site Scripting
- CVE-2023-32461 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2023-32481 PoCAll-in-one Floating Contact Form < 2.1.2 - Admin+ Stored Cross-Site Scripting
- CVE-2023-32621 PoCThe Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the…
- CVE-2023-32693 PoCsDistros-[dirtyvma] privilege escalation via non-rcu-protected vma traversal
- CVE-2023-32741 PoCcode-projects Supplier Management System Picture btn_functions.php unrestricted upload
- CVE-2023-32751 PoCPHPGurukul Rail Pass Management System POST Request view-pass-detail.php sql injection
- CVE-2023-32761 PoCDromara HuTool XML Parsing Module XmlUtil.java readBySax xml external entity reference
- CVE-2023-32771 PoCMStore API <= 4.10.7 - Unauthorized Account Access and Privilege Escalation
- CVE-2023-32791 PoCNextGEN Gallery < 3.39 - Admin+ Local File Inclusion
- CVE-2023-32911 PoCHeap-based Buffer Overflow in gpac/gpac
- CVE-2023-32921 PoCGrid Kit Premium < 2.2.0 - Multiple Reflected Cross-Site Scripting
- CVE-2023-32941 PoCCross-site Scripting (XSS) - DOM in saleor/react-storefront
- CVE-2023-33041 PoCImproper Access Control in admidio/admidio
- CVE-2023-33051 PoCC-DATA Web Management System User Creation access control
- CVE-2023-33063 PoCsRuijie RG-EW1200G Admin Password app.09df2a9e44ab48766f5f.js access control
- CVE-2023-33071 PoCminiCal sql injection
- CVE-2023-33081 PoCwhaleal IceFrog Aviator Template Engine deserialization
- CVE-2023-33091 PoCSourceCodester Resort Reservation System Manage Room Page ?page=rooms cross site scripting
- CVE-2023-33101 PoCcode-projects Agro-School Management System loaddata.php sql injection
- CVE-2023-33111 PoCPuneethReddyHC online-shopping-system-advanced addsuppliers.php cross site scripting
- CVE-2023-33161 PoCA NULL pointer dereference in TIFFClose() is caused by a failure to open an output file (non-existent path or a path that requires…
- CVE-2023-33181 PoCSourceCodester Resort Management System cross site scripting
- CVE-2023-33202 PoCsThe WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due…
- CVE-2023-33281 PoCCustom Field For WP Job Manager < 1.2 - Admin+ Stored XSS
- CVE-2023-33382 PoCsCrash due to a null pointer dereference in the dn_nsp_send function
- CVE-2023-33391 PoCcode-projects Agro-School Management System exam-delete.php sql injection
- CVE-2023-33401 PoCSourceCodester Online School Fees System GET Parameter ajx.php sql injection
- CVE-2023-33441 PoCAuto Location for WP Job Manager via Google < 1.1 - Admin+ Cross Site Scripting
- CVE-2023-33452 PoCsLMS by Masteriyo < 1.6.8 - Information Exposure
- CVE-2023-33501 PoCCryptographic Issues on IBERMATICA RPS
- CVE-2023-33561 PoCSubscribers Text Counter < 1.7.1 - Settings Update via CSRF to Stored XSS
- CVE-2023-33601 PoCWeaver Show Posts < 1.8.1 - Admin+ PHP Object Injection
- CVE-2023-33641 PoCInefficient Regular Expression Complexity in GitLab
- CVE-2023-33651 PoCMultiParcels Shipping For WooCommerce < 1.14.14 - Subscriber+ Arbitrary Shipment Deletion
- CVE-2023-33661 PoCMultiParcels Shipping For WooCommerce < 1.15.2 - Arbitrary Shipment Deletion via CSRF
- CVE-2023-33682 PoCsChamilo LMS Unauthenticated Command Injection
- CVE-2023-33721 PoCLana Shortcodes < 1.2.0 - Contributor+ Stored XSS
- CVE-2023-33802 PoCsWavlink WN579X3 Ping Test adm.cgi injection
- CVE-2023-33811 PoCSourceCodester Online School Fees System GET Parameter datatable.php cross site scripting
- CVE-2023-33821 PoCSourceCodester Game Result Matrix System GET Parameter save-delegates.php cross site scripting
- CVE-2023-33831 PoCSourceCodester Game Result Matrix System GET Parameter athlete-profile.php sql injection
- CVE-2023-33851 PoCImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
- CVE-2023-33881 PoCBeautiful Cookie Consent Banner <= 2.10.1 - Unauthenticated Stored Cross-Site Scripting
- CVE-2023-33902 PoCsUse-after-free in Linux kernel's netfilter subsystem
- CVE-2023-33911 PoCSourceCodester Human Resource Management System detailview.php sql injection
- CVE-2023-33921 PoCRead More & Accordion < 3.2.7 - Admin+ PHP Object Injection
- CVE-2023-33931 PoCCode Injection in fossbilling/fossbilling
- CVE-2023-33941 PoCSession Fixation in fossbilling/fossbilling
- CVE-2023-33961 PoCCampcodes Retro Cellphone Online Store index.php sql injection
- CVE-2023-33981 PoCDenial of Service in jgraph/drawio
- CVE-2023-33991 PoCInsertion of Sensitive Information Into Sent Data in GitLab
- CVE-2023-34011 PoCImproper Control of Generation of Code ('Code Injection') in GitLab
- CVE-2023-34131 PoCInsertion of Sensitive Information Into Sent Data in GitLab
- CVE-2023-34201 PoCType Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2023-34231 PoCWeak Password Requirements in cloudexplorer-dev/cloudexplorer-lite
- CVE-2023-34241 PoCInefficient Regular Expression Complexity in GitLab
- CVE-2023-34311 PoCImproper Access Control in plantuml/plantuml
- CVE-2023-34321 PoCServer-Side Request Forgery (SSRF) in plantuml/plantuml
- CVE-2023-34351 PoCUser Activity Log < 1.6.5 - Unauthenticated SQLi
- CVE-2023-34413 PoCsExposure of Sensitive Information Due to Incompatible Policies in GitLab
- CVE-2023-34431 PoCIncorrect Authorization in GitLab
- CVE-2023-34441 PoCIncorrect Authorization in GitLab
- CVE-2023-34451 PoCCross-site Scripting (XSS) - Stored in spinacms/spina
- CVE-2023-34491 PoCIBOS OA Interview Management Export export&interviews=x actionExport sql injection
- CVE-2023-34503 PoCsRuijie RG-BCR860 Network Diagnostic Page os command injection
- CVE-2023-34525 PoCsCanto <= 3.0.4 - Unauthenticated Remote File Inclusion
- CVE-2023-34571 PoCSourceCodester Shopping Website index.php sql injection
- CVE-2023-34581 PoCSourceCodester Shopping Website forgot-password.php sql injection
- CVE-2023-346014 PoCsUltimate Member < 2.6.7 - Unauthenticated Privilege Escalation
- CVE-2023-34691 PoCCross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq
- CVE-2023-34731 PoCCampcodes Retro Cellphone Online Store edit_product.php sql injection
- CVE-2023-34781 PoCIBOS OA Add User edit&op=member actionEdit sql injection
- CVE-2023-34792 PoCsCross-site Scripting (XSS) - Reflected in hestiacp/hestiacp
- CVE-2023-34841 PoCIncorrect Authorization in GitLab
- CVE-2023-34901 PoCSQL Injection in fossbilling/fossbilling
- CVE-2023-34911 PoCUnrestricted Upload of File with Dangerous Type in fossbilling/fossbilling
- CVE-2023-34921 PoCWP Shopping Pages <= 1.14 - Stored XSS via CSRF
- CVE-2023-34991 PoCRobo Gallery < 3.2.16 - Admin+ Stored XSS
- CVE-2023-35001 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2023-35011 PoCFormCraft < 1.2.7 - Admin+ Stored XSS
- CVE-2023-35021 PoCSourceCodester Shopping Website search-result.php sql injection
- CVE-2023-35031 PoCSourceCodester Shopping Website insert-product.php unrestricted upload
- CVE-2023-35071 PoCWooCommerce Pre-Orders < 2.0.3 - Arbitrary Pre-Order Canceling via CSRF
- CVE-2023-35081 PoCWooCommerce Pre-Orders < 2.0.3 - Unauthorised Actions via CSRF
- CVE-2023-35091 PoCIncorrect Authorization in GitLab
- CVE-2023-35101 PoCFTP Access <= 1.0 - Subscriber+ Stored XSS
- CVE-2023-35111 PoCIncorrect Authorization in GitLab
- CVE-2023-35131 PoCRazerCentralService Unsafe Deserialization Escalation of Privilege
- CVE-2023-35141 PoCRazerCentralSerivce Unsafe Named Pipe Permission Escalation of Privilege Vulnerability
- CVE-2023-35151 PoCOpen Redirect in go-gitea/gitea
- CVE-2023-351917 PoCsKEVUnauthenticated remote code execution
- CVE-2023-35201 PoCSensitive Cookie in HTTPS Session Without 'Secure' Attribute in it-novum/openitcockpit
- CVE-2023-35212 PoCsCross-site Scripting (XSS) - Reflected in fossbilling/fossbilling
- CVE-2023-35231 PoCOut-of-bounds Read in gpac/gpac
- CVE-2023-35241 PoCWPCode < 2.0.13.1 - Reflected XSS
- CVE-2023-35311 PoCCross-site Scripting (XSS) - Stored in nilsteampassnet/teampass
- CVE-2023-35321 PoCCross-site Scripting (XSS) - Stored in outline/outline
- CVE-2023-35332 PoCsChamilo LMS Unauthenticated Remote Code Execution via Arbitrary File Write
- CVE-2023-35341 PoCSourceCodester Shopping Website check_availability.php sql injection
- CVE-2023-35451 PoCChamilo LMS Htaccess File Upload Security Bypass
- CVE-2023-35471 PoCAll in One B2B for WooCommerce <= 1.0.3 - Multiple CSRF
- CVE-2023-35511 PoCCode Injection in nilsteampassnet/teampass
- CVE-2023-35521 PoCImproper Encoding or Escaping of Output in nilsteampassnet/teampass
- CVE-2023-35531 PoCExposure of Sensitive Information to an Unauthorized Actor in nilsteampassnet/teampass
- CVE-2023-35651 PoCCross-site Scripting (XSS) - Generic in nilsteampassnet/teampass
- CVE-2023-35661 PoCwallabag Profile Config config allocation of resources
- CVE-2023-35751 PoCQuiz And Survey Master < 8.1.11 - Contributor+ Stored XSS
- CVE-2023-35782 PoCsDedeCMS co_do.php server-side request forgery
- CVE-2023-35791 PoCHadSky User cross-site request forgery
- CVE-2023-35801 PoCImproper Handling of Additional Special Element in squidex/squidex
- CVE-2023-35991 PoCSourceCodester Best Fee Management System Add User admin_class.php save_user access control
- CVE-2023-36011 PoCSimple Author Box < 2.52 - Contributor+ Arbitrary User Information Disclosure via IDOR
- CVE-2023-36041 PoCChange WP Admin < 1.1.4 - Secret Login Page Disclosure
- CVE-2023-36061 PoCTamronOS ping os command injection
- CVE-2023-36071 PoCkodbox WebConsole Plug-In webconsole.php.txt Execute os command injection
- CVE-2023-36081 PoCRuijie BCR810W Tracert Page os command injection
- CVE-2023-36091 PoCUse-after-free in Linux kernel's net/sched: cls_u32 component
- CVE-2023-36171 PoCSourceCodester Best POS Management System Login Page admin_class.php sql injection
- CVE-2023-36201 PoCCross-site Scripting (XSS) - Stored in amauric/tarteaucitron.js
- CVE-2023-36211 PoCIBOS OA Delete Packet delete createDeleteCommand sql injection
- CVE-2023-36231 PoCSuncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System Duty Module UploadHandler.ashx unrestricted upload
- CVE-2023-36251 PoCSuncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System Duty Write-UploadFile UploadFile.ashx unrestricted upload
- CVE-2023-36261 PoCSuncreate Mountain Flood Disaster Prevention Monitoring and Early Warning System UpLoadFloodPlanFile UpLoadFloodPlanFile.ashx unrestricted…
- CVE-2023-36271 PoCCross-Site Request Forgery (CSRF) in salesagility/suitecrm-core
- CVE-2023-36351 PoCOkio GzipSource unhandled exception Denial of Service
- CVE-2023-36401 PoCKernel: x86/mm: a per-cpu entry area leak was identified through the init_cea_offsets function when prefetchnta and prefetcht2…
- CVE-2023-36433 PoCsBoss Mini document file inclusion
- CVE-2023-36451 PoCContact Form Builder by Bit Form < 2.2.0 - Admin+ Stored XSS
- CVE-2023-36471 PoCIURNY by INDIGITALL < 3.2.3 - Admin+ Stored XSS
- CVE-2023-36501 PoCBubble Menu < 3.0.5 - Admin+ Stored XSS
- CVE-2023-36601 PoCCampcodes Retro Cellphone Online Store add_user_modal.php cross site scripting
- CVE-2023-36641 PoCFileOrganizer <= 1.0.2 - Admin+ Arbitrary File Access
- CVE-2023-36661 PoCSticky Side Buttons < 2.0.0 - Admin+ Stored XSS
- CVE-2023-36671 PoCBit Assist < 1.1.9 - Admin+ Stored Cross-Site Scripting
- CVE-2023-36711 PoCMultiParcels Shipping For WooCommerce < 1.15.4 - Reflected XSS
- CVE-2023-36721 PoCCross-site Scripting (XSS) - DOM in plaidweb/webmention.js
- CVE-2023-36731 PoCSQL Injection in pimcore/pimcore
- CVE-2023-36761 PoCKubernetes - Windows nodes - Insufficient input sanitization leads to privilege escalation
- CVE-2023-36811 PoCCampcodes Retro Cellphone Online Store modal_add_product.php cross site scripting
- CVE-2023-36921 PoCUnrestricted Upload of File with Dangerous Type in admidio/admidio
- CVE-2023-36931 PoCSourceCodester Life Insurance Management System login.php sql injection
- CVE-2023-36941 PoCSourceCodester/projectworlds House Rental and Property Listing index.php sql injection
- CVE-2023-36951 PoCCampcodes Beauty Salon Management System add-product.php sql injection
- CVE-2023-36961 PoCPrototype Pollution in automattic/mongoose
- CVE-2023-37061 PoCActivityPub for WordPress < 1.0.0 - Subscriber+ Arbitrary Post Title Disclosure
- CVE-2023-37071 PoCActivityPub for WordPress < 1.0.0 - Subscriber+ Arbitrary Post Content Disclosure
- CVE-2023-37104 PoCsPrinter web page invalid command execution
- CVE-2023-37201 PoCUpload Media By URL < 1.0.8 - Stored XSS via CSRF
- CVE-2023-37211 PoCWP-EMail < 2.69.1 - Admin+ Stored Cross-Site Scripting
- CVE-2023-37222 PoCsAvaya Aura Device Services Remote Code Execution
- CVE-2023-37241 PoCTLS 1.3 client issue handling malicious server when not including a KSE and PSK extension
- CVE-2023-37251 PoCPotential buffer overflow vulnerability in the Zephyr CANbus subsystem
- CVE-2023-37261 PoCOCSInventory-ocsreports 2.12.0 - Stored cross-site Scripting
- CVE-2023-37461 PoCActivityPub for WordPress < 1.0.1 - Contributor+ Stored XSS
- CVE-2023-37591 PoCIntergard SGS permission
- CVE-2023-37601 PoCIntergard SGS Change Password denial of service
- CVE-2023-37611 PoCIntergard SGS Password Change cleartext transmission
- CVE-2023-37621 PoCIntergard SGS sensitive information in memory
- CVE-2023-37631 PoCIntergard SGS SQL Query cleartext transmission
- CVE-2023-37652 PoCsAbsolute Path Traversal in mlflow/mlflow
- CVE-2023-37711 PoCT1 theme <= 19.0 - Open Redirect
- CVE-2023-37821 PoCDoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to…
- CVE-2023-37832 PoCsWebile HTTP POST Request cross site scripting
- CVE-2023-37842 PoCsDooblou WiFi File Explorer cross site scripting
- CVE-2023-37852 PoCsPaulPrinting CMS cross site scripting
- CVE-2023-37861 PoCAures Komet Kiosk Mode access control
- CVE-2023-37872 PoCsCodecanyon Tiva Events Calender cross site scripting
- CVE-2023-37882 PoCsActiveITzone Active Super Shop CMS Manage Details Page cross site scripting
- CVE-2023-37892 PoCsPaulPrinting CMS Search delivery cross site scripting
- CVE-2023-37902 PoCsBoom CMS assets-manager add cross site scripting
- CVE-2023-37911 PoCIBOS OA Personal Office Address Book export actionExport sql injection
- CVE-2023-37921 PoCBeijing Netcon NS-ASG test_status.php direct request
- CVE-2023-37971 PoCGen Technology Four Mountain Torrent Disaster Prevention and Control of Monitoring and Early Warning System UploadFloodPlanFileUpdate.ashx…
- CVE-2023-37981 PoCChengdu Flash Flood Disaster Monitoring and Warning System upload.aspx unrestricted upload
- CVE-2023-37991 PoCIBOS OA Delete Category del sql injection
- CVE-2023-38001 PoCEasyAdmin8 File Upload Module index.html unrestricted upload
- CVE-2023-38011 PoCIBOS OA Mobile Notification edit actionEdit sql injection
- CVE-2023-38021 PoCChengdu Flash Flood Disaster Monitoring and Warning System Ajaxfileupload.ashx unrestricted upload
- CVE-2023-38031 PoCChengdu Flash Flood Disaster Monitoring and Warning System File Name ImageStationDataService.asmx random values
- CVE-2023-38041 PoCChengdu Flash Flood Disaster Monitoring and Warning System FileHandler.ashx unrestricted upload
- CVE-2023-38051 PoCXiamen Four Letter Video Surveillance Management System Login UserInfoAction.class improper authorization
- CVE-2023-38061 PoCSourceCodester House Rental and Property Listing System btn_functions.php unrestricted upload
- CVE-2023-38071 PoCCampcodes Beauty Salon Management System edit_product.php sql injection
- CVE-2023-38081 PoCHospital Management System patientforgotpassword.php sql injection
- CVE-2023-38091 PoCHospital Management System patient.php sql injection
- CVE-2023-38101 PoCHospital Management System patientappointment.php sql injection
- CVE-2023-38111 PoCHospital Management System patientprofile.php sql injection
- CVE-2023-38141 PoCAdvanced File Manager < 5.1.1 - Admin+ Arbitrary File/Folder Access
- CVE-2023-38191 PoCExposure of Sensitive Information to an Unauthorized Actor in pimcore/pimcore
- CVE-2023-38201 PoCSQL Injection in pimcore/pimcore
- CVE-2023-38211 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2023-38221 PoCCross-site Scripting (XSS) - Reflected in pimcore/pimcore
- CVE-2023-38231 PoCSecurity issue with external entity loading in XML without enabling it
- CVE-2023-38245 PoCsBuffer overflow and overread in phar_dir_read()
- CVE-2023-38261 PoCIBOS OA Interview edit&op=status sql injection
- CVE-2023-38364 PoCsDahua Smart Park Management unrestricted upload
- CVE-2023-38371 PoCDedeBIZ sys_sql_query.php cross site scripting
- CVE-2023-38381 PoCDedeBIZ vote_edit.php cross site scripting
- CVE-2023-38391 PoCDedeBIZ sys_sql_query.php sql injection
- CVE-2023-38433 PoCsmooSocial mooDating URL question cross site scripting
- CVE-2023-38443 PoCsmooSocial mooDating URL friends cross site scripting
- CVE-2023-38453 PoCsmooSocial mooDating URL ajax_invite cross site scripting
- CVE-2023-38463 PoCsmooSocial mooDating URL pages cross site scripting
- CVE-2023-38473 PoCsmooSocial mooDating URL users cross site scripting
- CVE-2023-38483 PoCsmooSocial mooDating URL view cross site scripting
- CVE-2023-38493 PoCsmooSocial mooDating URL find-a-match cross site scripting
- CVE-2023-38521 PoCOpenRapid RapidCMS upload.php unrestricted upload
- CVE-2023-38711 PoCCampcodes Beauty Salon Management System edit_category.php sql injection
- CVE-2023-38721 PoCCampcodes Beauty Salon Management System edit-services.php sql injection
- CVE-2023-38731 PoCCampcodes Beauty Salon Management System index.php sql injection
- CVE-2023-38741 PoCCampcodes Beauty Salon Management System admin-profile.php sql injection
- CVE-2023-38751 PoCCampcodes Beauty Salon Management System del_feedback.php sql injection
- CVE-2023-38761 PoCCampcodes Beauty Salon Management System search-appointment.php sql injection
- CVE-2023-38771 PoCCampcodes Beauty Salon Management System add-services.php sql injection
- CVE-2023-38781 PoCCampcodes Beauty Salon Management System about-us.php sql injection
- CVE-2023-38791 PoCCampcodes Beauty Salon Management System del_category.php sql injection
- CVE-2023-38801 PoCCampcodes Beauty Salon Management System del_service.php sql injection
- CVE-2023-38811 PoCCampcodes Beauty Salon Management System forgot-password.php sql injection
- CVE-2023-38821 PoCCampcodes Beauty Salon Management System edit-accepted-appointment.php sql injection
- CVE-2023-38831 PoCCampcodes Beauty Salon Management System add-category.php cross site scripting
- CVE-2023-38841 PoCCampcodes Beauty Salon Management System edit_product.php cross site scripting
- CVE-2023-38851 PoCCampcodes Beauty Salon Management System edit_category.php cross site scripting
- CVE-2023-38861 PoCCampcodes Beauty Salon Management System invoice.php cross site scripting
- CVE-2023-38871 PoCCampcodes Beauty Salon Management System search-appointment.php cross site scripting
- CVE-2023-38881 PoCCampcodes Beauty Salon Management System admin-profile.php cross site scripting
- CVE-2023-38901 PoCCampcodes Beauty Salon Management System edit-accepted-appointment.php cross site scripting
- CVE-2023-38911 PoCLapce v0.2.8 - Privilege escalation via Race Condition
- CVE-2023-38961 PoCA divide by zero issue existed in vim of OpenCloudOS Stream
- CVE-2023-38972 PoCsBypassing CAPTCHA & Enumerating Usernames via Password Reset Page
- CVE-2023-39001 PoCImproper Validation of Specified Type of Input in GitLab
- CVE-2023-39041 PoCImproper Validation of Specified Type of Input in GitLab
- CVE-2023-39061 PoCImproper Validation of Specified Type of Input in GitLab
- CVE-2023-39071 PoCImproper User Management in GitLab
- CVE-2023-39091 PoCInefficient Regular Expression Complexity in GitLab
- CVE-2023-39141 PoCIncorrect User Management in GitLab
- CVE-2023-39151 PoCIncorrect Execution-Assigned Permissions in GitLab
- CVE-2023-39171 PoCImproper Validation of Specified Type of Input in GitLab
- CVE-2023-39201 PoCIncorrect Authorization in GitLab
- CVE-2023-39221 PoCURL Redirection to Untrusted Site ('Open Redirect') in GitLab
- CVE-2023-39321 PoCIncorrect User Management in GitLab
- CVE-2023-39362 PoCsBlog2Social < 7.2.1 - Reflected XSS
- CVE-2023-39491 PoCInsertion of Sensitive Information Into Sent Data in GitLab
- CVE-2023-39501 PoCCleartext Storage of Sensitive Information in GitLab
- CVE-2023-39541 PoCMultiParcels Shipping For WooCommerce 1.15.2-1.15.3 - Reflected XSS
- CVE-2023-39641 PoCIncorrect Authorization in GitLab
- CVE-2023-39691 PoCGZ Scripts Availability Booking Calendar PHP HTTP POST Request index.php cross site scripting
- CVE-2023-39701 PoCGZ Scripts Availability Booking Calendar PHP Image cross site scripting
- CVE-2023-39711 PoCController: html injection in custom login info
- CVE-2023-39781 PoCImproper rendering of text nodes in golang.org/x/net/html
- CVE-2023-39791 PoCIncorrect Authorization in GitLab
- CVE-2023-39801 PoCCross-site Scripting (XSS) - Stored in omeka/omeka-s
- CVE-2023-39811 PoCServer-Side Request Forgery (SSRF) in omeka/omeka-s
- CVE-2023-39821 PoCCross-site Scripting (XSS) - Stored in omeka/omeka-s
- CVE-2023-39831 PoCAn authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authenticated remote…
- CVE-2023-39851 PoCSourceCodester Online Jewelry Store login.php sql injection
- CVE-2023-39861 PoCSourceCodester Simple Online Mens Salon Management System cross site scripting
- CVE-2023-39871 PoCSourceCodester Simple Online Mens Salon Management System sql injection
- CVE-2023-39881 PoCCafe Billing System Order index.php sql injection
- CVE-2023-39902 PoCsMingsoft MCMS HTTP POST Request search.do cross site scripting
- CVE-2023-39921 PoCPostX - Gutenberg Post Grid Blocks < 3.0.6 - Reflected Cross-Site Scripting
- CVE-2023-39941 PoCInefficient Regular Expression Complexity in GitLab