CVE-2023-45000 to CVE-2023-45999
82 CVEs with public proof-of-concept exploits.
- CVE-2023-450381 PoCMusic Station
- CVE-2023-451311 PoCUnauthenticated access to new private chat messages in Discourse
- CVE-2023-451361 PoCXWiki Platform web templates vulnerable to reflected XSS in the create document form if name validation is enabled
- CVE-2023-451392 PoCsfonttools XML External Entity Injection (XXE) Vulnerability
- CVE-2023-451521 PoCBlind Server Side Request Forgery (SSRF) in remote schedule import feature in Engelsystem
- CVE-2023-451581 PoCAn OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifySendHandler for…
- CVE-2023-451821 PoCIBM i Access Client Solutions information disclosure
- CVE-2023-451841 PoCIBM i Access Client Solutions
- CVE-2023-451851 PoCIBM i Access Client Solutions code execution
- CVE-2023-452081 PoCA command injection in the parsing_xml_stasurvey function inside libcgifunc.so of the D-Link DAP-X1860 repeater 1.00 through 1.01b05-01…
- CVE-2023-452091 PoCAn information disclosure vulnerability exists in the web interface /cgi-bin/download_config.cgi functionality of Peplink Smart Reader…
- CVE-2023-452492 PoCsKEVRemote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before…
- CVE-2023-452772 PoCsYamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows…
- CVE-2023-452781 PoCDirectory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via…
- CVE-2023-452791 PoCYamcs 5.8.6 allows XSS (issue 1 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file.…
- CVE-2023-452801 PoCYamcs 5.8.6 allows XSS (issue 2 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file.…
- CVE-2023-452811 PoCAn issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file.
- CVE-2023-452883 PoCsHTTP/2 CONTINUATION flood in net/http
- CVE-2023-453181 PoCA heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A…
- CVE-2023-453752 PoCsIn the module "PireosPay" (pireospay) before version 1.7.10 from 01generator.com for PrestaShop, a guest can perform SQL injection via…
- CVE-2023-453761 PoCIn the module "Carousels Pack - Instagram, Products, Brands, Supplier" (hicarouselspack) for PrestaShop up to version 1.5.0 from HiPresta…
- CVE-2023-453861 PoCIn the module extratabspro before version 2.2.8 from MyPresta.eu for PrestaShop, a guest can perform SQL injection via…
- CVE-2023-454631 PoCNetis N3Mv2-V1.0.1.865 was discovered to contain a buffer overflow via the hostName parameter in the FUN_0040dabc function. This…
- CVE-2023-454641 PoCNetis N3Mv2-V1.0.1.865 was discovered to contain a buffer overflow via the servDomain parameter. This vulnerability allows attackers to…
- CVE-2023-454651 PoCNetis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ddnsDomainName parameter in the Dynamic DNS…
- CVE-2023-454661 PoCNetis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the pin_host parameter in the WPS Settings.
- CVE-2023-454671 PoCNetis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ntpServIP parameter in the Time Settings.
- CVE-2023-454681 PoCNetis N3Mv2-V1.0.1.865 was discovered to contain a buffer overflow via the pingWdogIp. This vulnerability allows attackers to cause a…
- CVE-2023-454711 PoCThe QAD Search Server is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to, and including, 1.0.0.315 due to insufficient…
- CVE-2023-454982 PoCsVinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability.
- CVE-2023-454992 PoCsVinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials.
- CVE-2023-455031 PoCSQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denial of service…
- CVE-2023-455111 PoCA memory leak in tsMuxer version git-2539d07 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
- CVE-2023-455391 PoCHAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have…
- CVE-2023-455403 PoCsAn issue in Jorani Leave Management System 1.0.3 allows a remote attacker to execute arbitrary HTML code via a crafted script to the…
- CVE-2023-455422 PoCsCross Site Scripting vulnerability in mooSocial 3.1.8 allows a remote attacker to obtain sensitive information via a crafted script to the…
- CVE-2023-455541 PoCFile Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter…
- CVE-2023-455551 PoCFile Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the down_url function…
- CVE-2023-456128 PoCsIn JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE
- CVE-2023-456482 PoCsApache Tomcat: Trailer header parsing too lenient
- CVE-2023-456571 PoCWordPress Nexter Theme <= 2.0.3 is vulnerable to SQL Injection
- CVE-2023-456591 PoCSession is not expiring after password reset in Engelsystem
- CVE-2023-456701 PoCFrigate cross-site request forgery in `config_save` and `config_set` request handlers
- CVE-2023-456711 PoCFrigate reflected XSS through `/<camera_name>` API endpoints
- CVE-2023-456721 PoCFrigate unsafe deserialization in `load_config_with_no_duplicates` of `frigate/util/builtin.py`
- CVE-2023-456731 PoCArbitrary code execution on click of PDF links in Joplin
- CVE-2023-456851 PoCArbitrary file write via "zip slip" in Titan MFT and Titan SFTP servers
- CVE-2023-456861 PoCArbitrary file write via WebDAV path traversal in Titan MFT and Titan SFTP servers
- CVE-2023-456871 PoCAuthentication bypass via session fixation in Titan MFT and Titan SFTP servers
- CVE-2023-456881 PoCInformation leak via path traversal in Titan MFT and Titan SFTP servers
- CVE-2023-456891 PoCArbitrary file read via path traversal in Titan MFT and Titan SFTP servers
- CVE-2023-456901 PoCInformation leak via default file permissions on Titan MFT and Titan SFTP servers
- CVE-2023-457441 PoCA data integrity vulnerability exists in the web interface /cgi-bin/upload_config.cgi functionality of Peplink Smart Reader v1.2.0 (in…
- CVE-2023-457792 PoCsIn the APEX module framework of AOSP, there is a possible malicious update to platform components due to improperly used crypto. This…
- CVE-2023-458052 PoCsTrojan Lockfilein pdm
- CVE-2023-458061 PoCDiscourse vulnerable to DoS via Regexp Injection in Full Name
- CVE-2023-458112 PoCsPrototype pollution vulnerability leading to arbitrary code execution in synchrony deobfuscator
- CVE-2023-458131 PoCInefficient Regular Expression Complexity in TorBot
- CVE-2023-458202 PoCsDirectus crashes on invalid WebSocket message
- CVE-2023-458261 PoCAuthenticated SQL Injection in leantime
- CVE-2023-458271 PoCPrototype Pollution vulnerability in @clickbar/dot-diver
- CVE-2023-458281 PoCWordPress RumbleTalk Live Group Chat plugin <= 6.2.5 - Broken Access Control vulnerability
- CVE-2023-458381 PoCMultiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit…
- CVE-2023-458391 PoCMultiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit…
- CVE-2023-458401 PoCMultiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit…
- CVE-2023-458411 PoCMultiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit…
- CVE-2023-458421 PoCMultiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit…
- CVE-2023-458522 PoCsIn Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands…
- CVE-2023-458551 PoCqdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.
- CVE-2023-458573 PoCsAn issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header…
- CVE-2023-458669 PoCsBluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection,…
- CVE-2023-458671 PoCILIAS (2013-09-12 release) contains a medium-criticality Directory Traversal local file inclusion vulnerability in the ScormAicc module.…
- CVE-2023-458681 PoCThe Learning Module in ILIAS 7.25 (2023-09-12 release) allows an attacker (with basic user privileges) to achieve a high-impact Directory…
- CVE-2023-458691 PoCILIAS 7.25 (2023-09-12) allows any authenticated user to execute arbitrary operating system commands remotely, when a highly privileged…
- CVE-2023-4587812 PoCsGibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require…
- CVE-2023-458791 PoCGibbonEdu Gibbon version 25.0.0 allows HTML Injection via an IFRAME element to the Messager component.
- CVE-2023-458801 PoCGibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can create a new Asset…
- CVE-2023-458811 PoCGibbonEdu Gibbon through version 25.0.0 allows /modules/Planner/resources_addQuick_ajaxProcess.php file upload with resultant XSS. The…
- CVE-2023-458891 PoCA Universal Cross Site Scripting (UXSS) vulnerability in ClassLink OneClick Extension through 10.8 allows remote attackers to inject…
- CVE-2023-458971 PoCexfatprogs before 1.2.2 allows out-of-bounds memory access, such as in read_file_dentry_set.
- CVE-2023-459901 PoCInsecure Permissions vulnerability in WenwenaiCMS v.1.0 allows a remote attacker to escalate privileges.
- CVE-2023-459921 PoCA vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote,…