CVE-2023-44000 to CVE-2023-44999
50 CVEs with public proof-of-concept exploits.
- CVE-2023-440081 PoCFile Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.
- CVE-2023-440121 PoCCross Site Scripting vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the helpkey parameter in…
- CVE-2023-440421 PoCA stored cross-site scripting (XSS) vulnerability in /settings/index.php of Black Cat CMS 1.4.1 allows attackers to execute arbitrary web…
- CVE-2023-440431 PoCA reflected cross-site scripting (XSS) vulnerability in /install/index.php of Black Cat CMS 1.4.1 allows attackers to execute arbitrary…
- CVE-2023-440441 PoCSuper Store Finder v3.6 and below was discovered to contain a SQL injection vulnerability via the Search parameter at /admin/stores.php.
- CVE-2023-440472 PoCsSourcecodester Toll Tax Management System v1 is vulnerable to SQL Injection.
- CVE-2023-440482 PoCsSourcecodester Expense Tracker App v1 is vulnerable to Cross Site Scripting (XSS) via add category.
- CVE-2023-440613 PoCsFile Upload vulnerability in Simple and Nice Shopping Cart Script v.1.0 allows a remote attacker to execute arbitrary code via the upload…
- CVE-2023-440881 PoCSQL Injection in Visual Console
- CVE-2023-442211 PoCKEVImproper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with…
- CVE-2023-442561 PoCA server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before…
- CVE-2023-442751 PoCOPNsense before 23.7.5 allows XSS via the index.php column_count parameter to the Lobby Dashboard.
- CVE-2023-442761 PoCOPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.
- CVE-2023-443521 PoCUnauthenticate Reflected XSS on Adobe Coldfusion 2018 - 2021 - 2023 last version
- CVE-2023-443531 PoCColdFusion WDDX Deserialization Gadgets
- CVE-2023-443932 PoCsPiwigo Reflected XSS vulnerability
- CVE-2023-444001 PoCUptime Kuma has Persistentent User Sessions
- CVE-2023-444511 PoCLinux Mint Xreader EPUB File Parsing Directory Traversal Remote Code Execution Vulnerability
- CVE-2023-444521 PoCLinux Mint Xreader CBT File Parsing Argument Injection Remote Code Execution Vulnerability
- CVE-2023-444661 PoCAn issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error, leading to a…
- CVE-2023-4448727 PoCsKEVThe HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly,…
- CVE-2023-447091 PoCPlutoSVG commit 336c02997277a1888e6ccbbbe674551a0582e5c4 and before was discovered to contain an integer overflow via the component…
- CVE-2023-447582 PoCsGDidees CMS 3.0 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted…
- CVE-2023-447602 PoCsMultiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS v.9.2.1 allow an attacker to execute arbitrary code via a crafted…
- CVE-2023-447612 PoCsMultiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS versions affected to 8.5.13 and below, and 9.0.0 through 9.2.1 allow a…
- CVE-2023-447622 PoCsA Cross Site Scripting (XSS) vulnerability in Concrete CMS from versions 9.2.0 to 9.2.2 allows an attacker to execute arbitrary code via a…
- CVE-2023-447632 PoCsConcrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cross-Site Scripting…
- CVE-2023-447642 PoCsA Cross Site Scripting (XSS) vulnerability in Concrete CMS before 9.2.3 exists via the Name parameter during installation (aka Site of…
- CVE-2023-447652 PoCsA Cross Site Scripting (XSS) vulnerability in Concrete CMS versions 8.5.12 and below, and 9.0 through 9.2.1 allows an attacker to execute…
- CVE-2023-447661 PoCA Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 allows an attacker to execute arbitrary code via a crafted script to…
- CVE-2023-447672 PoCsA File upload vulnerability in RiteCMS 3.0 allows a local attacker to upload a SVG file with XSS content.
- CVE-2023-447692 PoCsA Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted…
- CVE-2023-447702 PoCsA Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows an attacker to execute arbitrary code via a crafted script to…
- CVE-2023-447712 PoCsA Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted…
- CVE-2023-448071 PoCD-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the cancelPing function.
- CVE-2023-448081 PoCD-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_4507CC function.
- CVE-2023-448091 PoCD-Link device DIR-820L 1.05B03 is vulnerable to Insecure Permissions.
- CVE-2023-448111 PoCCross Site Request Forgery (CSRF) vulnerability in MooSocial v.3.1.8 allows a remote attacker to execute arbitrary code and obtain…
- CVE-2023-448122 PoCsCross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a crafted payload to…
- CVE-2023-448132 PoCsCross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a crafted payload to…
- CVE-2023-448211 PoCGifsicle through 1.94, if deployed in a way that allows untrusted input to affect Gif_Realloc calls, might allow a denial of service…
- CVE-2023-448241 PoCAn issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploaded to the…
- CVE-2023-448461 PoCAn issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ notify.php component.
- CVE-2023-448471 PoCAn issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ Weixin.php component.
- CVE-2023-448531 PoC\An issue was discovered in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to…
- CVE-2023-448571 PoCAn issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_21D24…
- CVE-2023-449541 PoCCross Site Scripting vulnerability in BigTree CMS v.4.5.7 allows a remote attacker to execute arbitrary code via the ID parameter in the…
- CVE-2023-449611 PoCSQL Injection vulnerability in Koha Library Software 23.0.5.04 and before allows a remote attacker to obtain sensitive information via the…
- CVE-2023-449622 PoCsFile Upload vulnerability in Koha Library Software 23.05.04 and before allows a remote attacker to read arbitrary files via the…
- CVE-2023-449821 PoCWordPress WP Retina 2x Plugin <= 6.4.5 is vulnerable to Sensitive Data Exposure