CVE-2023-42000 to CVE-2023-42999
62 CVEs with public proof-of-concept exploits.
- CVE-2023-420001 PoCArcserve UDP Agent Unauthenticated Path Traversal File Upload
- CVE-2023-421152 PoCsExim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability
- CVE-2023-421341 PoCPAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.45_20230314 or earlier can allow the signed partition overwrite and…
- CVE-2023-421351 PoCPAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter…
- CVE-2023-421361 PoCPAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands…
- CVE-2023-421371 PoCPAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high…
- CVE-2023-422221 PoCWebCatalog before 49.0 is vulnerable to Incorrect Access Control. WebCatalog calls the Electron shell.openExternal function without…
- CVE-2023-422701 PoCGrocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF).
- CVE-2023-422781 PoChutool v5.8.21 was discovered to contain a buffer overflow via the component JSONUtil.parse().
- CVE-2023-422823 PoCsThe ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally…
- CVE-2023-422831 PoCBlind SQL injection in api_id parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL…
- CVE-2023-422841 PoCBlind SQL injection in api_version parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted…
- CVE-2023-422951 PoCAn issue in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the…
- CVE-2023-422991 PoCBuffer Overflow vulnerability in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of…
- CVE-2023-423071 PoCCross Site Scripting (XSS) vulnerability in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via "Subject…
- CVE-2023-423081 PoCCross Site Scripting (XSS) vulnerability in Manage Fastrack Subjects in Code-Projects Exam Form Submission 1.0 allows attackers to run…
- CVE-2023-423201 PoCBuffer Overflow vulnerability in Tenda AC10V4 v.US_AC10V4.0si_V16.03.10.13_cn_TDC01 allows a remote attacker to cause a denial of service…
- CVE-2023-423231 PoCCross Site Request Forgery (CSRF) vulnerability in DouHaocms v.3.3 allows a remote attacker to execute arbitrary code via the…
- CVE-2023-423262 PoCsAn issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the…
- CVE-2023-423341 PoCAn Indirect Object Reference (IDOR) in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to escalate privileges via…
- CVE-2023-423351 PoCUnrestricted File Upload vulnerability in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to execute arbitrary code…
- CVE-2023-423431 PoCA Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type.
- CVE-2023-423441 PoCAlkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack…
- CVE-2023-423621 PoCAn arbitrary file upload vulnerability in Teller Web App v.4.4.0 allows a remote attacker to execute arbitrary commands and obtain…
- CVE-2023-424051 PoCSQL injection vulnerability in FIT2CLOUD RackShift v1.7.1 allows attackers to execute arbitrary code via the `sort` parameter to…
- CVE-2023-424062 PoCsSQL injection vulnerability in D-Link Online behavior audit gateway DAR-7000 V31R02B1413C allows a remote attacker to obtain sensitive…
- CVE-2023-424261 PoCCross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote attackers to execute arbitrary code via the 'Insert…
- CVE-2023-424426 PoCsJumpServer session replays download without authentication
- CVE-2023-424491 PoCMalicious head initialiser can extract PTs from control of Hydra scripts, leading to locked participant commits or spoofed commits
- CVE-2023-424561 PoCsudo-rs Session File Relative Path Traversal vulnerability
- CVE-2023-424611 PoCSQL injection in ITIL actors in GLPI
- CVE-2023-424621 PoCFile deletion through document upload process in GLPI
- CVE-2023-424681 PoCThe com.cutestudio.colordialer application through 2.1.8-2 for Android allows a remote attacker to initiate phone calls without user…
- CVE-2023-424691 PoCThe com.full.dialer.top.secure.encrypted application through 1.0.1 for Android enables any installed application (with no permissions) to…
- CVE-2023-424701 PoCThe Imou Life com.mm.android.smartlifeiot application through 6.8.0 for Android allows Remote Code Execution via a crafted intent to an…
- CVE-2023-424711 PoCThe wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted…
- CVE-2023-426271 PoCMultiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal 7.3.5 through 7.4.3.91, and Liferay…
- CVE-2023-426281 PoCStored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay DXP 7.0 fix pack…
- CVE-2023-426291 PoCStored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP…
- CVE-2023-427531 PoCKernel: netfilter: potential slab-out-of-bound access due to integer underflow
- CVE-2023-427541 PoCKernel: ipv4: null pointer dereference in ipv4_send_dest_unreach()
- CVE-2023-427551 PoCKernel: rsvp: out-of-bounds read in rsvp_classify()
- CVE-2023-427561 PoCKernel: netfilter: race condition between ipset_cmd_add and ipset_cmd_swap
- CVE-2023-427871 PoCA client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and…
- CVE-2023-427881 PoCAn improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager &…
- CVE-2023-427891 PoCA out-of-bounds write in Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0…
- CVE-2023-427911 PoCA relative path traversal in Fortinet FortiManager version 7.4.0 and 7.2.0 through 7.2.3 and 7.0.0 through 7.0.8 and 6.4.0 through 6.4.12…
- CVE-2023-4279325 PoCsKEVIn JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
- CVE-2023-427951 PoCApache Tomcat: Failure during request clean-up leads to sensitive data leaking to subsequent requests
- CVE-2023-427991 PoCBuffer overflow due to use of `strcpy` in `parseUrlAddrFromRtspUrlString`
- CVE-2023-428001 PoCBuffer overflow due to use of `strcpy` in `performRtspHandshake`
- CVE-2023-428021 PoCGLPI vulnerable to unallowed PHP script execution
- CVE-2023-428081 PoCCommon Voice Cross-site Scripting vulnerability
- CVE-2023-428112 PoCsAEADs/aes-gcm: Plaintext exposed in decrypt_in_place_detached even on tag verification failure
- CVE-2023-428121 PoCGalaxy vulnerable to Server Side Request Forgery during data imports
- CVE-2023-428191 PoCPath traversal in Jumpserver
- CVE-2023-428205 PoCsRandom seed leakage in Jumpserver
- CVE-2023-428212 PoCsgithub.com/gomarkdown/markdown Out-of-bounds Read while parsing citations
- CVE-2023-428291 PoCThe issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Big Sur 11.7.9,…
- CVE-2023-428601 PoCA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS…
- CVE-2023-429141 PoCThe issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2,…
- CVE-2023-429312 PoCsThe issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. A…