CVE-2023-47000 to CVE-2023-47999
84 CVEs with public proof-of-concept exploits.
- CVE-2023-470041 PoCBuffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary…
- CVE-2023-470141 PoCA Cross-Site Request Forgery (CSRF) vulnerability in Sourcecodester Sticky Notes App Using PHP with Source Code v.1.0 allows a local…
- CVE-2023-470162 PoCsradare2 5.8.9 has an out-of-bounds read in r_bin_object_set_items in libr/bin/bobj.c, causing a crash in r_read_le32 in…
- CVE-2023-470251 PoCAn issue in Free5gc v.3.3.0 allows a local attacker to cause a denial of service via the free5gc-compose component.
- CVE-2023-471022 PoCsUrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message confirms that a username is not valid.
- CVE-2023-471051 PoCexec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd parameter without…
- CVE-2023-471061 PoCIncorrect processing of fragment in the URL leads to Authorization Bypass in Traefik
- CVE-2023-471081 PoCDoS vulnerability in otelgrpc (uncontrolled resource consumption) due to unbound cardinality metrics
- CVE-2023-471153 PoCsLabel Studio XSS Vulnerability on Avatar Upload
- CVE-2023-471161 PoCLabel Studio SSRF on Import Bypassing `SSRF_PROTECTION_ENABLED` Protections
- CVE-2023-471173 PoCsObject Relational Mapper Leak Vulnerability in Filtering Task in Label Studio
- CVE-2023-471191 PoCHTML injection in oneboxed links
- CVE-2023-471251 PoCBy-passing Cross-Site Scripting Protection in HTML Sanitizer
- CVE-2023-471282 PoCspiccolo SQL Injection via named transaction savepoints
- CVE-2023-471291 PoCStatamic CMS remote code execution via front-end form uploads
- CVE-2023-471711 PoCAn information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev…
- CVE-2023-471791 PoCWordPress WooODT Lite plugin <= 2.4.6 - Arbitrary Site Option Update vulnerability
- CVE-2023-472111 PoCA directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP…
- CVE-2023-472184 PoCsQTS, QuTS hero, QuTScloud
- CVE-2023-472465 PoCsKEVIn SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat…
- CVE-2023-472481 PoCPyArrow, PyArrow: Arbitrary code execution when loading a malicious data file
- CVE-2023-472491 PoCIn International Color Consortium DemoIccMAX 79ecb74, a CIccXmlArrayType:::ParseText function (for unsigned short) in IccUtilXml.cpp in…
- CVE-2023-472502 PoCsIn mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, broken Access Control on X11 server sockets allows authenticated…
- CVE-2023-472512 PoCsIn mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, a Directory Traversal in the print function of the VNC service allows…
- CVE-2023-472534 PoCsQualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the…
- CVE-2023-472541 PoCAn OS Command Injection in the CLI interface on DrayTek Vigor167 version 5.2.2, allows remote attackers to execute arbitrary system…
- CVE-2023-472681 PoCIn libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrary code on a host…
- CVE-2023-473201 PoCSilverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only…
- CVE-2023-473211 PoCSilverpeas Core 6.3.1 is vulnerable to Incorrect Access Control via the "Porlet Deployer" which allows administrators to deploy .WAR…
- CVE-2023-473221 PoCThe "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If…
- CVE-2023-473231 PoCThe notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker…
- CVE-2023-473241 PoCSilverpeas Core 6.3.1 is vulnerable to Cross Site Scripting (XSS) via the message/notification feature.
- CVE-2023-473251 PoCSilverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate…
- CVE-2023-473261 PoCSilverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) via the Domain SQL Create function.
- CVE-2023-473271 PoCThe "Create a Space" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access…
- CVE-2023-473451 PoCBuffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP message with malformed PFCP…
- CVE-2023-473461 PoCBuffer Overflow vulnerability in free5gc 3.3.0, UPF 1.2.0, and SMF 1.2.0 allows attackers to cause a denial of service via crafted PFCP…
- CVE-2023-473471 PoCBuffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP messages whose Sequence…
- CVE-2023-473551 PoCThe com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broadcast receivers…
- CVE-2023-474301 PoCStack-buffer-overflow vulnerability in ReadyMedia (MiniDLNA) v1.3.3 allows attackers to cause a denial of service via via the…
- CVE-2023-474371 PoCA vulnerability has been identified in Pachno 1.0.6 allowing an authenticated attacker to execute a cross-site scripting (XSS) attack. The…
- CVE-2023-474451 PoCPre-School Enrollment version 1.0 is vulnerable to SQL Injection via the username parameter in preschool/admin/ page.
- CVE-2023-474461 PoCPre-School Enrollment version 1.0 is vulnerable to Cross Site Scripting (XSS) on the profile.php page via fullname parameter.
- CVE-2023-474521 PoCAn Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in…
- CVE-2023-474531 PoCAn Untrusted search path vulnerability in Sohu Video Player 7.0.15.0 allows local users to gain escalated privileges through the…
- CVE-2023-474541 PoCAn Untrusted search path vulnerability in NetEase CloudMusic 2.10.4 for Windows allows local users to gain escalated privileges through…
- CVE-2023-474551 PoCTenda AX1806 V1.0.0.1 contains a heap overflow vulnerability in setSchedWifi function, in which the src and v12 are directly obtained from…
- CVE-2023-474561 PoCTenda AX1806 V1.0.0.1 contains a stack overflow vulnerability in function sub_455D4, called by function fromSetWirelessRepeat.
- CVE-2023-474591 PoCAn issue in Knovos Discovery v.22.67.0 allows a remote attacker to obtain sensitive information via the…
- CVE-2023-474601 PoCSQL injection vulnerability in Knovos Discovery v.22.67.0 allows a remote attacker to execute arbitrary code via the…
- CVE-2023-474642 PoCsInsecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via the…
- CVE-2023-474661 PoCTagLib before 2.0 allows a segmentation violation and application crash during tag writing via a crafted WAV file in which an id3 chunk is…
- CVE-2023-474731 PoCDirectory Traversal vulnerability in fuwushe.org iFair versions 23.8_ad0 and before allows an attacker to obtain sensitive information via…
- CVE-2023-475031 PoCAn issue in jflyfox jfinalCMS v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp component…
- CVE-2023-475041 PoCWordPress Elementor plugin <= 3.16.4 - Auth. Arbitrary Attachment Read vulnerability
- CVE-2023-475291 PoCWordPress Cloud Templates & Patterns collection Plugin <= 1.2.2 is vulnerable to Sensitive Data Exposure
- CVE-2023-475641 PoCQsync Central
- CVE-2023-476191 PoCAudiobookshelf Server-Side Request Forgery and Arbitrary File Read Vulnerability
- CVE-2023-476201 PoCScrypted reflected Cross-site Scripting vulnerability
- CVE-2023-476231 PoCScrypted reflected Cross-site Scripting vulnerability
- CVE-2023-476241 PoCAudiobookshelf Arbitrary File Read Vulnerability
- CVE-2023-476251 PoCGlobal Buffer Overflow leading to denial of service in PX4-Autopilot
- CVE-2023-476271 PoCRequest smuggling in aiohttp
- CVE-2023-476281 PoCSession Expiration Misconfiguration in datahub
- CVE-2023-476331 PoCUncontrolled Resource Consumption in Traefik
- CVE-2023-476372 PoCsSQL Injection in Admin Grid Filter API in Pimcore
- CVE-2023-476411 PoCInconsistent interpretation of `Content-Length` vs. `Transfer-Encoding` in aiohttp
- CVE-2023-476432 PoCsSuiteCRM has Unauthenticated Graphql Introspection Enabled
- CVE-2023-476682 PoCsWordPress Restrict Content Plugin <= 3.2.7 is vulnerable to Sensitive Data Exposure
- CVE-2023-476841 PoCWordPress Essential Grid Plugin <= 3.1.0 is vulnerable to Cross Site Scripting (XSS)
- CVE-2023-478001 PoCNatus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account,…
- CVE-2023-478401 PoCWordPress Qode Essential Addons Plugin <= 1.5.2 is vulnerable to Remote Code Execution (RCE)
- CVE-2023-478561 PoCA stack-based buffer overflow vulnerability exists in the boa set_RadvdPrefixParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A…
- CVE-2023-478611 PoCA cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit…
- CVE-2023-478731 PoCWordPress WP Child Theme Generator plugin <= 1.0.9 - Arbitrary File Upload vulnerability
- CVE-2023-478821 PoCThe Kami Vision YI IoT com.yunyi.smartcamera application through 4.1.9_20231127 for Android allows a remote attacker to execute arbitrary…
- CVE-2023-478831 PoCThe com.altamirano.fabricio.tvbrowser TV browser application through 4.5.1 for Android is vulnerable to JavaScript code execution via an…
- CVE-2023-478901 PoCpyLoad 0.5.0 is vulnerable to Unrestricted File Upload.
- CVE-2023-479921 PoCAn integer overflow vulnerability in FreeImageIO.cpp::_MemoryReadProc in FreeImage 3.18.0 allows attackers to obtain sensitive…
- CVE-2023-479931 PoCA Buffer out-of-bound read vulnerability in Exif.cpp::ReadInt32 in FreeImage 3.18.0 allows attackers to cause a denial-of-service.
- CVE-2023-479941 PoCAn integer overflow vulnerability in LoadPixelDataRLE4 function in PluginBMP.cpp in Freeimage 3.18.0 allows attackers to obtain sensitive…
- CVE-2023-479951 PoCMemory Allocation with Excessive Size Value discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 allows attackers…
- CVE-2023-479961 PoCAn integer overflow vulnerability in Exif.cpp::jpeg_read_exif_dir in FreeImage 3.18.0 allows attackers to obtain information and cause a…
- CVE-2023-479971 PoCAn issue discovered in BitmapAccess.cpp::FreeImage_AllocateBitmap in FreeImage 3.18.0 leads to an infinite loop and allows attackers to…