CVE-2023-46000 to CVE-2023-46999
111 CVEs with public proof-of-concept exploits.
- CVE-2023-460011 PoCBuffer Overflow vulnerability in gpac MP4Box v.2.3-DEV-rev573-g201320819-master allows a local attacker to cause a denial of service via…
- CVE-2023-460031 PoCI-doit pro 25 and below is vulnerable to Cross Site Scripting (XSS) via index.php.
- CVE-2023-460061 PoCSourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_user.php.
- CVE-2023-460091 PoCgifsicle-1.94 was found to have a floating point exception (FPE) vulnerability via resize_stream at src/xform.c.
- CVE-2023-460121 PoCBuffer Overflow vulnerability LINKSYS EA7500 3.0.1.207964 allows a remote attacker to execute arbitrary code via an HTTP request to the…
- CVE-2023-460142 PoCsSQL Injection vulnerability in hospitalLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via…
- CVE-2023-460151 PoCCross Site Scripting (XSS) vulnerability in index.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via 'msg'…
- CVE-2023-460161 PoCCross Site Scripting (XSS) in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'search' parameter in…
- CVE-2023-460171 PoCSQL Injection vulnerability in receiverLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via…
- CVE-2023-460181 PoCSQL injection vulnerability in receiverReg.php in Code-Projects Blood Bank 1.0 \allows attackers to run arbitrary SQL commands via…
- CVE-2023-460191 PoCCross Site Scripting (XSS) vulnerability in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'error'…
- CVE-2023-460201 PoCCross Site Scripting (XSS) in updateprofile.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'rename',…
- CVE-2023-460211 PoCSQL Injection vulnerability in cancel.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary commands via the 'reqid'…
- CVE-2023-460222 PoCsSQL Injection vulnerability in delete.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via the 'bid'…
- CVE-2023-460242 PoCsSQL Injection vulnerability in index.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to run arbitrary…
- CVE-2023-460251 PoCSQL Injection vulnerability in teacher-info.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to obtain…
- CVE-2023-460261 PoCCross Site Scripting (XSS) vulnerability in profile.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to…
- CVE-2023-460471 PoCAn issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function.…
- CVE-2023-460521 PoCSane 1.2.1 heap bounds overwrite in init_options() from backend/test.c via a long init_mode string in a configuration file. NOTE: this is…
- CVE-2023-460581 PoCCross Site Scripting (XSS) vulnerability in Geeklog-Core geeklog v.2.2.2 allows a remote attacker to execute arbitrary code via a crafted…
- CVE-2023-460591 PoCCross Site Scripting (XSS) vulnerability in Geeklog-Core geeklog v.2.2.2 allows a remote attacker to execute arbitrary code via a crafted…
- CVE-2023-460601 PoCA Buffer Overflow vulnerability in Tenda AC500 v.2.0.1.9 allows a remote attacker to cause a denial of service via the port parameter at…
- CVE-2023-461161 PoCRemote Code Execution via insufficiently sanitized call to shell.openExternal
- CVE-2023-461201 PoCRabbitMQ Java client's lack of message size limitation leads to remote DoS attack
- CVE-2023-461321 PoCCrosslinking transaction attack in hyperledger/fabric
- CVE-2023-461361 PoCWerkzeug vulnerable to high resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning
- CVE-2023-461971 PoCWordPress Popup by Supsystic plugin <= 1.10.19 - Unauthenticated Subscriber Email Addresses Disclosure
- CVE-2023-462142 PoCsRemote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing
- CVE-2023-462291 PoCLangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to…
- CVE-2023-462451 PoCKimai (Authenticated) SSTI to RCE by Uploading a Malicious Twig File
- CVE-2023-462461 PoCInteger Overflow in :history command in Vim
- CVE-2023-462561 PoCPX4-Autopilot Heap Buffer Overflow Bug
- CVE-2023-463041 PoCmodules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an…
- CVE-2023-463321 PoCWebAssembly wabt 1.0.33 contains an Out-of-Bound Memory Write in DataSegment::Drop(), which lead to segmentation fault.
- CVE-2023-463441 PoCA vulnerability in Solar-Log Base 15 Firmware 6.0.1 Build 161, and possibly other Solar-Log Base products, allows an attacker to escalate…
- CVE-2023-463471 PoCIn the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform…
- CVE-2023-463561 PoCIn the module "CSV Feeds PRO" (csvfeeds) before 2.6.1 from Bl Modules for PrestaShop, a guest can perform SQL injection. The method…
- CVE-2023-463591 PoCAn OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote…
- CVE-2023-463611 PoCArtifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_error at /jbig2dec/jbig2.c.
- CVE-2023-463621 PoCjbig2enc v0.28 was discovered to contain a heap-use-after-free via jbig2enc_auto_threshold_using_hash in src/jbig2enc.cc.
- CVE-2023-463631 PoCjbig2enc v0.28 was discovered to contain a SEGV via jbig2_add_page in src/jbig2enc.cc:512.
- CVE-2023-463711 PoCTP-Link device TL-WDR7660 2.0.30 and TL-WR886N 2.0.12 has a stack overflow vulnerability via the function upgradeInfoJsonToBin.
- CVE-2023-463751 PoCZenTao Biz version 4.1.3 and before is vulnerable to Cross Site Request Forgery (CSRF).
- CVE-2023-464021 PoCgit-urls 1.0.0 allows ReDOS (Regular Expression Denial of Service) in urls.go.
- CVE-2023-464041 PoCPCRS <= 3.11 (d0de1e) “Questions” page and “Code editor” page are vulnerable to remote code execution (RCE) by escaping Python sandboxing.
- CVE-2023-464261 PoCHeap-based Buffer Overflow vulnerability in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary…
- CVE-2023-464271 PoCAn issue was discovered in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary code, cause a…
- CVE-2023-464421 PoCAn infinite loop in the retrieveActiveBody function of Soot before v4.4.1 under Java 8 allows attackers to cause a Denial of Service (DoS).
- CVE-2023-464451 PoCAn issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a…
- CVE-2023-464461 PoCAn issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and…
- CVE-2023-464481 PoCReflected Cross-Site Scripting (XSS) vulnerability in dmpop Mejiro Commit Versions Prior To 3096393 allows attackers to run arbitrary code…
- CVE-2023-464492 PoCsSourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can…
- CVE-2023-464502 PoCsSourcecodester Free and Open Source inventory management system 1.0 is vulnerable to Cross Site Scripting (XSS) via the Add supplier…
- CVE-2023-464511 PoCBest Courier Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the change username field.
- CVE-2023-464531 PoCCertain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username…
- CVE-2023-464551 PoCIn GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN…
- CVE-2023-464681 PoCAn issue in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted file to the custom plugin function.
- CVE-2023-464741 PoCFile Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted PHP file…
- CVE-2023-464781 PoCAn issue in minCal v.1.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the customer_data parameter.
- CVE-2023-464901 PoCSQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actions() function in…
- CVE-2023-465011 PoCAn issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin…
- CVE-2023-465221 PoCTP-LINK device TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin and TL-WDR7660 2.0.30 were discovered to contain a stack overflow via the…
- CVE-2023-465271 PoCTP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin and TL-WDR7660 2.0.30 was discovered to contain a stack overflow via the…
- CVE-2023-465691 PoCAn out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32_fpu function of libr/arch/p/nds32/nds32-dis.h.
- CVE-2023-465701 PoCAn out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32 function of libr/arch/p/nds32/nds32-dis.h.
- CVE-2023-465743 PoCsAn issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the…
- CVE-2023-465801 PoCCross-Site Scripting (XSS) vulnerability in Inventory Management V1.0 allows attackers to execute arbitrary code via the pname parameter…
- CVE-2023-465811 PoCSQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary code via the name, uname and email…
- CVE-2023-465821 PoCSQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary SQL commands via the id paramter in…
- CVE-2023-465841 PoCSQL Injection vulnerability in PHPGurukul Nipah virus (NiV) " Testing Management System v.1.0 allows a remote attacker to escalate…
- CVE-2023-465891 PoCApache Tomcat: HTTP request smuggling via malformed trailer headers
- CVE-2023-466021 PoCIn International Color Consortium DemoIccMAX 79ecb74, there is a stack-based buffer overflow in the icFixXml function in…
- CVE-2023-466031 PoCIn International Color Consortium DemoIccMAX 79ecb74, there is an out-of-bounds read in the CIccPRMG::GetChroma function in…
- CVE-2023-4660440 PoCsKEVApache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code…
- CVE-2023-466151 PoCWordPress KD Coming Soon Plugin <= 1.7 is vulnerable to PHP Object Injection
- CVE-2023-466941 PoCVtenext 21.02 allows an authenticated attacker to upload arbitrary files, potentially enabling them to execute remote commands. This flaw…
- CVE-2023-467301 PoCServer-Side Request Forgery in groupoffice
- CVE-2023-467321 PoCReflected Cross-site scripting through revision parameter in content menu in XWiki Platform
- CVE-2023-467441 PoCStored Cross-site Scripting in Squidex
- CVE-2023-467451 PoCRate limiting Bypass on login page in libreNMS
- CVE-2023-4674716 PoCsKEVBIG-IP Configuration utility unauthenticated remote code execution vulnerability
- CVE-2023-467481 PoCKEVBIG-IP Configuration utility authenticated SQL injection vulnerability
- CVE-2023-4680511 PoCsKEVAn authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to…
- CVE-2023-468131 PoCAn issue was discovered in the Linux kernel before 6.5.9, exploitable by local users with userspace access to MMIO registers. Incorrect…
- CVE-2023-468172 PoCsAn issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized…
- CVE-2023-4681814 PoCsAn issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if…
- CVE-2023-468581 PoCMoodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ…
- CVE-2023-468641 PoCPeppermint Ticket Management through 0.2.4 allows remote attackers to read arbitrary files via a…
- CVE-2023-468652 PoCs/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing…
- CVE-2023-468661 PoCIn International Color Consortium DemoIccMAX 79ecb74, CIccCLUT::Interp3d in IccProfLib/IccTagLut.cpp in libSampleICC.a attempts to access…
- CVE-2023-468671 PoCIn International Color Consortium DemoIccMAX 79ecb74, CIccXformMatrixTRC::GetCurve in IccCmm.cpp in libSampleICC.a has a NULL pointer…
- CVE-2023-468701 PoCextcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAPI/*.py in Nordic Semiconductor nRF Sniffer for Bluetooth LE 3.0.0,…
- CVE-2023-468712 PoCsGPAC version 2.3-DEV-rev602-ged8424300-master in MP4Box contains a memory leak in NewSFDouble scenegraph/vrml_tools.c:300. This…
- CVE-2023-469161 PoCMaxima Max Pro Power 1.0 486A devices allow BLE traffic replay. An attacker can use GATT characteristic handle 0x0012 to perform…
- CVE-2023-469291 PoCAn issue discovered in GPAC 2.3-DEV-rev605-gfc9e29089-master in MP4Box in gf_avc_change_vui…
- CVE-2023-469441 PoCAn issue in GitKraken GitLens before v.14.0.0 allows an attacker to execute arbitrary code via a crafted file to the Visual Studio Codes…
- CVE-2023-469481 PoCA reflected Cross-Site Scripting (XSS) vulnerability was found on Temenos T24 Browser R19.40 that enables a remote attacker to execute…
- CVE-2023-469501 PoCCross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted…
- CVE-2023-469511 PoCCross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted…
- CVE-2023-469541 PoCSQL Injection vulnerability in Relativity ODA LLC RelativityOne v.12.1.537.3 Patch 2 and earlier allows a remote attacker to execute…
- CVE-2023-469741 PoCCross Site Scripting vulnerability in Best Courier Management System v.1.000 allows a remote attacker to execute arbitrary code via a…
- CVE-2023-469761 PoCTOTOLINK A3300R 17.0.0cu.557_B20221024 contains a command injection via the file_name parameter in the UploadFirmwareFile function.
- CVE-2023-469771 PoCTOTOLINK LR1200GB V9.1.0u.6619_B20230130 was discovered to contain a stack overflow via the password parameter in the function loginAuth.
- CVE-2023-469781 PoCTOTOLINK X6000R V9.4.0cu.852_B20230719 is vulnerable to Incorrect Access Control.Attackers can reset login password & WIFI passwords…
- CVE-2023-469791 PoCTOTOLINK X6000R V9.4.0cu.852_B20230719 was discovered to contain a command injection vulnerability via the enable parameter in the…
- CVE-2023-469801 PoCAn issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted…
- CVE-2023-469871 PoCSeaCMS v12.9 was discovered to contain a remote code execution (RCE) vulnerability via the component /augap/adminip.php.
- CVE-2023-469882 PoCsPath Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating…
- CVE-2023-469921 PoCTOTOLINK A3300R V17.0.0cu.557_B20221024 is vulnerable to Incorrect Access Control. Attackers are able to reset serveral critical passwords…
- CVE-2023-469931 PoCIn TOTOLINK A3300R V17.0.0cu.557_B20221024 when dealing with setLedCfg request, there is no verification for the enable parameter, which…
- CVE-2023-469981 PoCCross Site Scripting vulnerability in BootBox Bootbox.js v.3.2 through 6.0 allows a remote attacker to execute arbitrary code via a…