CVE-2023-40000 to CVE-2023-40999
111 CVEs with public proof-of-concept exploits.
- CVE-2023-400004 PoCsWordPress LiteSpeed Cache plugin <= 5.7 - Unauthenticated Site Wide Stored XSS vulnerability
- CVE-2023-400131 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in external-svg-loader
- CVE-2023-400211 PoCTiming Attack Reveals CSRF Tokens in oppia
- CVE-2023-400241 PoCReflected Cross-Site Scripting (XSS) in scancode.io license endpoint
- CVE-2023-4002814 PoCsArbitrary file read via symlinks in Ghost
- CVE-2023-400291 PoCCluster secret might leak in cluster details page in Argo CD
- CVE-2023-400312 PoCsNotepad++ vulnerable to heap buffer write overflow in Utf8_16_Read::convert
- CVE-2023-400352 PoCsCraft CMS vulnerable to Remote Code Execution via validatePath bypass
- CVE-2023-400361 PoCNotepad++ global buffer read overflow in CharDistributionAnalysis::HandleOneChar
- CVE-2023-400371 PoCApache NiFi: Incomplete Validation of JDBC and JNDI Connection URLs
- CVE-2023-400446 PoCsKEVWS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability
- CVE-2023-400681 PoCCross-site scripting vulnerability in Advanced Custom Fields versions 6.1.0 to 6.1.7 and Advanced Custom Fields Pro versions 6.1.0 to…
- CVE-2023-400841 PoCIn run of MDnsSdListener.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of…
- CVE-2023-401091 PoCIn createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions bypass. This could…
- CVE-2023-401275 PoCsIn multiple locations, there is a possible way to access screenshots due to a confused deputy. This could lead to local information…
- CVE-2023-401301 PoCIn onBindingDied of CallRedirectionProcessor.java, there is a possible permission bypass due to a logic error in the code. This could lead…
- CVE-2023-401331 PoCIn multiple locations of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could…
- CVE-2023-401631 PoCAn out-of-bounds write vulnerability exists in the allocate_buffer_for_jpeg_decoding functionality of Accusoft ImageGear 20.1. A specially…
- CVE-2023-401641 PoCNotepad++ global buffer read overflow in nsCodingStateMachine::NextState
- CVE-2023-401661 PoCNotepad++ heap buffer read overflow in FileManager::detectLanguageFromTextBegining
- CVE-2023-401671 PoCJetty accepts "+" prefixed value in Content-Length
- CVE-2023-401811 PoCInteger-Underflow leading to Out-Of-Bound Read in FreeRDP
- CVE-2023-401861 PoCIntegerOverflow leading to Out-Of-Bound Write Vulnerability in FreeRDP
- CVE-2023-401871 PoCUse-After-Free in FreeRDP
- CVE-2023-401881 PoCOut-Of-Bounds Read in FreeRDP
- CVE-2023-401941 PoCAn arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to mistreatment of…
- CVE-2023-402081 PoCWordPress Stock Ticker Plugin <= 3.23.3 is vulnerable to Cross Site Scripting (XSS)
- CVE-2023-402111 PoCWordPress Post Grid Plugin <= 2.2.50 is vulnerable to Sensitive Data Exposure
- CVE-2023-402741 PoCAn issue was discovered in zola 0.13.0 through 0.17.2. The custom implementation of a web server, available via the "zola serve" command,…
- CVE-2023-402761 PoCAn issue was discovered in OpenClinic GA 5.247.01. An Unauthenticated File Download vulnerability has been discovered in…
- CVE-2023-402771 PoCAn issue was discovered in OpenClinic GA 5.247.01. A Reflected Cross-Site Scripting (XSS) vulnerability has been discovered in the…
- CVE-2023-402782 PoCsAn issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the…
- CVE-2023-402792 PoCsAn issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET…
- CVE-2023-402801 PoCAn issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET…
- CVE-2023-402891 PoCA command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to…
- CVE-2023-402911 PoCHarman Infotainment 20190525031613 allows root access via SSH over a USB-to-Ethernet dongle with a password that is an internal project…
- CVE-2023-402921 PoCHarman Infotainment 20190525031613 and later discloses the IP address via CarPlay CTRL packets.
- CVE-2023-402931 PoCHarman Infotainment 20190525031613 and later allows command injection via unauthenticated RPC with a D-Bus connection object.
- CVE-2023-402941 PoClibboron in Boron 2.0.8 has a heap-based buffer overflow in ur_parseBlockI at i_parse_blk.c.
- CVE-2023-402951 PoClibboron in Boron 2.0.8 has a heap-based buffer overflow in ur_strInitUtf8 at string.c.
- CVE-2023-402961 PoCasync-sockets-cpp through 0.3.1 has a stack-based buffer overflow in ReceiveFrom and Receive in udpsocket.hpp when processing malformed…
- CVE-2023-402971 PoCStakater Forecastle 1.0.139 and before allows %5C../ directory traversal in the website component.
- CVE-2023-403051 PoCGNU indent 2.2.13 has a heap-based buffer overflow in search_brace in indent.c via a crafted file.
- CVE-2023-403151 PoCROLE_FILESYSTEM_EDITOR Can Be Used To Escalate To ROLE_ADMIN
- CVE-2023-403552 PoCsCross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5,…
- CVE-2023-403611 PoCSECUDOS Qiata (DOMOS OS) 4.13 has Insecure Permissions for the previewRm.sh daily cronjob. To exploit this, an attacker needs access as a…
- CVE-2023-403621 PoCAn issue was discovered in CentralSquare Click2Gov Building Permit before October 2023. Lack of access control protections allows remote…
- CVE-2023-404042 PoCsA use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sonoma 14.1. An app may be able to…
- CVE-2023-404291 PoCA permissions issue was addressed with improved validation. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma…
- CVE-2023-404481 PoCThe issue was addressed with improved handling of protocols. This issue is fixed in tvOS 17, iOS 16.7 and iPadOS 16.7, watchOS 10, iOS 17…
- CVE-2023-404531 PoCDocker Machine through 0.16.2 allows an attacker, who has control of a worker node, to provide crafted version data, which might…
- CVE-2023-404592 PoCsImproper input leads to DoS
- CVE-2023-404771 PoCRARLAB WinRAR Recovery Volume Improper Validation of Array Index Remote Code Execution Vulnerability
- CVE-2023-404811 PoC7-Zip SquashFS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
- CVE-2023-404981 PoCLG Simple Editor cp Command Directory Traversal Remote Code Execution Vulnerability
- CVE-2023-405042 PoCsLG Simple Editor readVideoInfo Command Injection Remote Code Execution Vulnerability
- CVE-2023-405671 PoCOut-Of-Bounds Write in FreeRDP
- CVE-2023-405691 PoCOut-Of-Bounds Write in FreeRDP
- CVE-2023-405741 PoCOut-Of-Bounds Write in FreeRDP
- CVE-2023-405751 PoCOut-Of-Bounds Read in FreeRDP
- CVE-2023-405761 PoCOut-Of-Bounds Read in FreeRDP
- CVE-2023-405861 PoCgo package github.com/corazawaf/coraza is vulnerable to denial of service
- CVE-2023-405891 PoCFreeRDP Global-Buffer-Overflow in ncrush_decompress
- CVE-2023-405902 PoCsUntrusted search path on Windows systems leading to arbitrary code execution
- CVE-2023-406002 PoCsWordPress EWWW Image Optimizer Plugin <= 7.2.0 is vulnerable to Sensitive Data Exposure
- CVE-2023-406101 PoCApache Superset: Privilege escalation with default examples database
- CVE-2023-406181 PoCA reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start versions 4, 5, 6, 7 as well as Visual Project…
- CVE-2023-407481 PoCPHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.
- CVE-2023-407491 PoCPHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.
- CVE-2023-407501 PoCThere is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Yacht Listing Script v1.0.
- CVE-2023-407511 PoCPHPJabbers Fundraising Script v1.0 is vulnerable to Cross Site Scripting (XSS) via the "action" parameter of index.php.
- CVE-2023-407521 PoCThere is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.
- CVE-2023-407531 PoCThere is a Cross Site Scripting (XSS) vulnerability in the message parameter of index.php in PHPJabbers Ticket Support Script v3.2.
- CVE-2023-407551 PoCThere is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Callback Widget v1.0.
- CVE-2023-407791 PoCAn issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the…
- CVE-2023-407961 PoCPhicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call.
- CVE-2023-407971 PoCIn Tenda AC23 v16.03.07.45_cn, the sub_4781A4 function does not validate the parameters entered by the user, resulting in a…
- CVE-2023-407981 PoCIn Tenda AC23 v16.03.07.45_cn, the formSetIPv6status and formGetWanParameter functions do not authenticate user input parameters,…
- CVE-2023-407991 PoCTenda AC23 Vv16.03.07.45_cn is vulnerable to Buffer Overflow via sub_450A4C function.
- CVE-2023-408001 PoCThe compare_parentcontrol_time function does not authenticate user input parameters, resulting in a post-authentication stack overflow…
- CVE-2023-408011 PoCThe sub_451784 function does not validate the parameters entered by the user, resulting in a stack overflow vulnerability in Tenda AC23…
- CVE-2023-408021 PoCThe get_parentControl_list_Info function does not verify the parameters entered by the user, causing a post-authentication heap overflow…
- CVE-2023-408091 PoCOpenCRX version 5.2.0 is vulnerable to HTML injection via the Activity Search Criteria-Activity Number.
- CVE-2023-408101 PoCOpenCRX version 5.2.0 is vulnerable to HTML injection via Product Name Field.
- CVE-2023-408121 PoCOpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Group Name Field.
- CVE-2023-408131 PoCOpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Saved Search Creation.
- CVE-2023-408141 PoCOpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Name Field.
- CVE-2023-408151 PoCOpenCRX version 5.2.0 is vulnerable to HTML injection via the Category Creation Name Field.
- CVE-2023-408161 PoCOpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Milestone Name Field.
- CVE-2023-408171 PoCOpenCRX version 5.2.0 is vulnerable to HTML injection via the Product Configuration Name Field.
- CVE-2023-408191 PoCID4Portais in version < V.2022.837.002a returns message parameter unsanitized in the response, resulting in a HTML Injection vulnerability.
- CVE-2023-408341 PoCOpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing…
- CVE-2023-408511 PoCCross Site Scripting (XSS) vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows…
- CVE-2023-408521 PoCSQL Injection vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to…
- CVE-2023-408571 PoCBuffer Overflow vulnerability in VirusTotal yara v.4.3.2 allows a remote attacker to execute arbtirary code via the yr_execute_cod…
- CVE-2023-408681 PoCCross Site Request Forgery vulnerability in mooSocial MooSocial Software v.Demo allows a remote attacker to execute arbitrary code via the…
- CVE-2023-408691 PoCCross Site Scripting vulnerability in mooSocial mooSocial Software 3.1.6 and 3.1.7 allows a remote attacker to execute arbitrary code via…
- CVE-2023-409242 PoCsSolarView Compact < 6.00 is vulnerable to Directory Traversal.
- CVE-2023-409301 PoCAn issue in the directory /system/bin/blkid of Skyworth v3.0 allows attackers to perform a directory traversal via mounting the Udisk to…
- CVE-2023-409314 PoCsA SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute…
- CVE-2023-409331 PoCA SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration…
- CVE-2023-409421 PoCTenda AC9 V3.0BR_V15.03.06.42_multi_TD01 was discovered stack overflow via parameter 'firewall_value' at url /goform/SetFirewallCfg.
- CVE-2023-409541 PoCA SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12.0 through…
- CVE-2023-409551 PoCA SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in…
- CVE-2023-409561 PoCA SQL injection vulnerability in Cloudroits Website Job Search v.15.0 allows a remote authenticated attacker to execute arbitrary code via…
- CVE-2023-409571 PoCA SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in…
- CVE-2023-409581 PoCA SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in…
- CVE-2023-409681 PoCBuffer Overflow vulnerability in hzeller timg v.1.5.1 and before allows a remote attacker to cause a denial of service via the…
- CVE-2023-409691 PoCSenayan Library Management Systems SLIMS 9 Bulian v9.6.1 is vulnerable to Server Side Request Forgery (SSRF) via…
- CVE-2023-409701 PoCSenayan Library Management Systems SLIMS 9 Bulian v 9.6.1 is vulnerable to SQL Injection via admin/modules/circulation/loan_rules.php.
- CVE-2023-409891 PoCSQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted…