CVE-2023-41000 to CVE-2023-41999
86 CVEs with public proof-of-concept exploits.
- CVE-2023-410001 PoCGPAC through 2.2.1 has a use-after-free vulnerability in the function gf_bifs_flush_command_list in bifs/memory_decoder.c.
- CVE-2023-410111 PoCCommand Execution vulnerability in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker…
- CVE-2023-410121 PoCAn issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary…
- CVE-2023-410141 PoCcode-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via the Username parameter for "Employer."
- CVE-2023-410151 PoCcode-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via /Employer/DeleteJob.php?JobId=1.
- CVE-2023-410361 PoCMacvim's Insecure Usage of IPC Mechanisms
- CVE-2023-410402 PoCsGitPython blind local file inclusion
- CVE-2023-410412 PoCsUser session is still usable after logout in graylog2-server
- CVE-2023-410441 PoCPartial path traversal vulnerability in Support Bundle feature of Graylog
- CVE-2023-410451 PoCInsecure source port usage for DNS queries in Graylog
- CVE-2023-410471 PoCImproper Neutralization of Special Elements Used in a Template Engine in OctoPrint
- CVE-2023-410541 PoCLibreY Server-Side Request Forgery (SSRF) vulnerability in image_proxy.php
- CVE-2023-410551 PoCLibreY Server-Side Request Forgery (SSRF) vulnerability via wikipedia_language cookie
- CVE-2023-410644 PoCsKEVA buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey…
- CVE-2023-410651 PoCA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17,…
- CVE-2023-410661 PoCAn authentication issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14. An app may be able to…
- CVE-2023-410671 PoCA logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may bypass Gatekeeper checks.
- CVE-2023-410681 PoCAn access issue was addressed with improved access restrictions. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, iOS…
- CVE-2023-410801 PoCApache Tomcat: Open redirect with FORM authentication
- CVE-2023-411071 PoCTEF portal 2023-07-17 is vulnerable to a persistent cross site scripting (XSS)attack.
- CVE-2023-411081 PoCTEF portal 2023-07-17 is vulnerable to authenticated remote code execution.
- CVE-2023-411092 PoCsSmartNode SN200 (aka SN200) 3.21.2-23021 allows unauthenticated OS Command Injection.
- CVE-2023-412651 PoCKEVAn HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February…
- CVE-2023-412661 PoCKEVA path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7…
- CVE-2023-412702 PoCsSamsung Smart TV UE40D7000 WPS DoS attack
- CVE-2023-413161 PoCHTML Injection with email in Tolgee
- CVE-2023-413201 PoCAccount takeover via SQL Injection in UI layout preferences in GLPI
- CVE-2023-413251 PoCOP-TEE double free in shdr_verify_signature
- CVE-2023-413302 PoCsUnsafe deserialization in knplabs/knp-snappy
- CVE-2023-413342 PoCsastropy vulnerable to RCE in TranformGraph().to_dot_graph function
- CVE-2023-413621 PoCMyBB before 1.8.36 allows Code Injection by users with certain high privileges. Templates in Admin CP intentionally use eval, and there…
- CVE-2023-413641 PoCIn tine through 2023.01.14.325, the sort parameter of the /index.php endpoint allows SQL Injection.
- CVE-2023-413871 PoCA SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session tokens and overwrite…
- CVE-2023-4142522 PoCsCross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted…
- CVE-2023-414362 PoCsCross Site Scripting vulnerability in CSZCMS v.1.3.0 allows a local attacker to execute arbitrary code via a crafted script to the…
- CVE-2023-414421 PoCAn issue in Kloudq Technologies Limited Tor Equip 1.0, Tor Loco Mini 1.0 through 3.1 allows a remote attacker to execute arbitrary code…
- CVE-2023-414442 PoCsAn issue in Binalyze IREC.sys v.3.11.0 and before allows a local attacker to execute arbitrary code and escalate privileges via the…
- CVE-2023-414451 PoCCross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted…
- CVE-2023-414461 PoCCross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted…
- CVE-2023-414471 PoCCross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted…
- CVE-2023-414481 PoCCross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted…
- CVE-2023-414491 PoCAn issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.
- CVE-2023-414501 PoCAn issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.
- CVE-2023-414511 PoCCross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted…
- CVE-2023-414521 PoCCross Site Request Forgery vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted…
- CVE-2023-414531 PoCCross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted…
- CVE-2023-414741 PoCDirectory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via…
- CVE-2023-415031 PoCStudent Enrollment In PHP v1.0 was discovered to contain a SQL injection vulnerability via the Login function.
- CVE-2023-415041 PoCSQL Injection vulnerability in Student Enrollment In PHP 1.0 allows attackers to run arbitrary code via the Student Search function.
- CVE-2023-415051 PoCAn arbitrary file upload vulnerability in the Add Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to…
- CVE-2023-415061 PoCAn arbitrary file upload vulnerability in the Update/Edit Student's Profile Picture function of Student Enrollment In PHP v1.0 allows…
- CVE-2023-415071 PoCSuper Store Finder v3.6 was discovered to contain multiple SQL injection vulnerabilities in the store locator component via the products,…
- CVE-2023-415081 PoCA hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel.
- CVE-2023-415381 PoCphpjabbers PHP Forum Script 3.0 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter.
- CVE-2023-415641 PoCAn arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via…
- CVE-2023-415751 PoCMultiple stored cross-site scripting (XSS) vulnerabilities in /bbdms/sign-up.php of Blood Bank & Donor Management v2.2 allow attackers to…
- CVE-2023-415801 PoCPhpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php.…
- CVE-2023-415971 PoCEyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.
- CVE-2023-415992 PoCsAn issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal.
- CVE-2023-416011 PoCMultiple cross-site scripting (XSS) vulnerabilities in install/index.php of CSZ CMS v1.3.0 allow attackers to execute arbitrary web…
- CVE-2023-416131 PoCEzViz Studio v2.2.0 is vulnerable to DLL hijacking.
- CVE-2023-416211 PoCA Cross Site Scripting (XSS) vulnerability was discovered in Emlog Pro v2.1.14 via the component /admin/store.php.
- CVE-2023-416351 PoCA XML External Entity (XXE) vulnerability in the VerifichePeriodiche.aspx component of GruppoSCAI RealGimm v1.1.37p38 allows attackers to…
- CVE-2023-416371 PoCAn arbitrary file upload vulnerability in the Carica immagine function of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute…
- CVE-2023-416381 PoCAn arbitrary file upload vulnerability in the Gestione Documentale module of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute…
- CVE-2023-416401 PoCAn improper error handling vulnerability in the component ErroreNonGestito.aspx of GruppoSCAI RealGimm 1.1.37p38 allows attackers to…
- CVE-2023-416422 PoCsMultiple reflected cross-site scripting (XSS) vulnerabilities in the ErroreNonGestito.aspx component of GruppoSCAI RealGimm 1.1.37p38…
- CVE-2023-416461 PoCButtercup v2.20.3 allows attackers to obtain the hash of the master password for the password manager via accessing the file /vaults.json/
- CVE-2023-416521 PoCWordPress RSVPMarker Plugin <= 10.6.6 is vulnerable to SQL Injection
- CVE-2023-417171 PoCInappropriate file type control in Zscaler Proxy versions 3.6.1.25 and prior allows local attackers to bypass file download/upload…
- CVE-2023-417631 PoCKEVSkype for Business Elevation of Privilege Vulnerability
- CVE-2023-417721 PoCWin32k Elevation of Privilege Vulnerability
- CVE-2023-418792 PoCsMagento LTS's guest order "protect code" can be brute-forced too easily
- CVE-2023-418841 PoCZoneMinder Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in watch.php
- CVE-2023-418851 PoCPiccolo's current `BaseUser.login` implementation is vulnerable to time based user enumeration
- CVE-2023-418861 PoCOpenRefine vulnerable to arbitrary file read in project import with mysql jdbc url attack
- CVE-2023-418871 PoCRemote Code exec in project import with mysql jdbc url attack
- CVE-2023-418891 PoCLate-Unicode normalization vulnerability in SHIRASAGI
- CVE-2023-4189212 PoCsCraft CMS Remote Code Execution vulnerability
- CVE-2023-419541 PoCWordPress ProfilePress plugin <= 4.13.1 - Unauthenticated Limited Privilege Escalation vulnerability
- CVE-2023-419744 PoCsKEVA use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17. An app may be able to…
- CVE-2023-419912 PoCsKEVA certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be…
- CVE-2023-419921 PoCKEVThe issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A…
- CVE-2023-419936 PoCsKEVThe issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code…
- CVE-2023-419981 PoCArcserve UDP Unauthenticated RCE
- CVE-2023-419991 PoCArcserve UDP Management Authentication Bypass