CVE-2023-48000 to CVE-2023-48999
107 CVEs with public proof-of-concept exploits.
- CVE-2023-480032 PoCsAn open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted…
- CVE-2023-480111 PoCGPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a heap-use-after-free via the flush_ref_samples function at…
- CVE-2023-480131 PoCGPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a double free via the gf_filterpacket_del function at…
- CVE-2023-480141 PoCGPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a stack overflow via the hevc_parse_vps_extension function at…
- CVE-2023-480225 PoCsAnyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is…
- CVE-2023-480231 PoCAnyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated…
- CVE-2023-480341 PoCAn issue discovered in Acer Wireless Keyboard SK-9662 allows attacker in physical proximity to both decrypt wireless keystrokes and inject…
- CVE-2023-480391 PoCGPAC 2.3-DEV-rev617-g671976fcc-master is vulnerable to memory leak in gf_mpd_parse_string media_tools/mpd.c:75.
- CVE-2023-480491 PoCA SQL injection vulnerability in Cybrosys Techno Solutions Website Blog Search (aka website_search_blog) v. 13.0 through 13.0.1.0.1 allows…
- CVE-2023-480581 PoCDreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/run
- CVE-2023-480601 PoCDreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/add
- CVE-2023-480631 PoCAn issue was discovered in dreamer_cms 4.1.3. There is a CSRF vulnerability that can delete a theme project via /admin/category/delete.
- CVE-2023-480781 PoCSQL Injection vulnerability in add.php in Simple CRUD Functionality v1.0 allows attackers to run arbitrary SQL commands via the 'title'…
- CVE-2023-480844 PoCsNagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.
- CVE-2023-480901 PoCGPAC 2.3-DEV-rev617-g671976fcc-master is vulnerable to memory leaks in extract_attributes media_tools/m3u8.c:329.
- CVE-2023-481051 PoCAn heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial…
- CVE-2023-481061 PoCBuffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the…
- CVE-2023-481071 PoCBuffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the…
- CVE-2023-481221 PoCAn issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTTP GET method.
- CVE-2023-481231 PoCAn issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a…
- CVE-2023-481612 PoCsBuffer Overflow vulnerability in GifLib Project GifLib v.5.2.1 allows a local attacker to obtain sensitive information via the…
- CVE-2023-481711 PoCAn issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.
- CVE-2023-481921 PoCAn issue in TOTOlink A3700R v.9.1.2u.6134_B20201202 allows a local attacker to execute arbitrary code via the setTracerouteCfg function.
- CVE-2023-482011 PoCCross Site Scripting (XSS) vulnerability in Sunlight CMS v.8.0.1, allows remote authenticated attackers to execute arbitrary code and…
- CVE-2023-482021 PoCCross-Site Scripting (XSS) vulnerability in Sunlight CMS 8.0.1 allows an authenticated low-privileged user to escalate privileges via a…
- CVE-2023-482051 PoCJorani Leave Management System 1.0.2 allows a remote attacker to spoof a Host header associated with password reset emails.
- CVE-2023-482061 PoCA Cross Site Scripting (XSS) vulnerability in GaatiTrack Courier Management System 1.0 allows a remote attacker to inject JavaScript via…
- CVE-2023-482071 PoCAvailability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.
- CVE-2023-482233 PoCsfast-jwt JWT Algorithm Confusion
- CVE-2023-482251 PoCLaf env causes sensitive information disclosure
- CVE-2023-482261 PoCOpenReplay HTML Injection vulnerability
- CVE-2023-482383 PoCsJWT Algorithm Confusion in json-web-token library
- CVE-2023-482411 PoCXWiki exposed whole content of all documents of all wikis to anybody with view right on Solr suggest service
- CVE-2023-482921 PoCXWiki Admin Tools Application Run Shell Command allows CSRF RCE attacks
- CVE-2023-482942 PoCsBroken Access control on Graphs Feature in LibreNMS
- CVE-2023-482951 PoCCross-site Scripting at Device groups Deletion feature in LibreNMS
- CVE-2023-483091 PoCnext-auth vulnerable to possible user mocking that bypasses basic authentication
- CVE-2023-483122 PoCsAuthentication bypass using an empty token in capsule-proxy
- CVE-2023-484092 PoCsIn gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/mali_kbase_core_linux.c, there is a possible out…
- CVE-2023-487021 PoCJellyfin Possible Remote Code Execution via custom FFmpeg binary
- CVE-2023-487061 PoCVim has heap-use-after-free at /src/charset.c:1770:12 in skipwhite
- CVE-2023-487112 PoCsServer-Side Request Forgery (SSRF) Vulnerability in google-translate-api-browser
- CVE-2023-487282 PoCsA cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master…
- CVE-2023-487361 PoCIn International Color Consortium DemoIccMAX 3e7948b, CIccCLUT::Interp2d in IccTagLut.cpp in libSampleICC.a has an out-of-bounds read.
- CVE-2023-487772 PoCsWordPress Elementor plugin 3.3.0-3.18.1 - Arbitrary File Upload vulnerability
- CVE-2023-487883 PoCsKEVA improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through…
- CVE-2023-487958 PoCsThe SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to…
- CVE-2023-487992 PoCsTOTOLINK-X6000R Firmware-V9.4.0cu.852_B20230719 is vulnerable to Command Execution.
- CVE-2023-488002 PoCsIn TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_417338 function obtains fields from the front-end, connects them…
- CVE-2023-488012 PoCsIn TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains fields from the front-end, connects them…
- CVE-2023-488021 PoCIn TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The…
- CVE-2023-488031 PoCIn TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The…
- CVE-2023-488041 PoCIn TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The…
- CVE-2023-488051 PoCIn TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The…
- CVE-2023-488061 PoCIn TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The…
- CVE-2023-488071 PoCIn TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The…
- CVE-2023-488081 PoCIn TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The…
- CVE-2023-488101 PoCIn TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The…
- CVE-2023-488111 PoCIn TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The…
- CVE-2023-488121 PoCIn TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str…
- CVE-2023-488131 PoCSenayan Library Management Systems (Slims) 9 Bulian v9.6.1 is vulnerable to SQL Injection via…
- CVE-2023-488231 PoCA Blind SQL injection issue in ajax.php in GaatiTrack Courier Management System 1.0 allows an unauthenticated attacker to inject a payload…
- CVE-2023-488241 PoCBoidCMS 2.0.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the title, subtitle, footer, or keywords parameter in…
- CVE-2023-488251 PoCAvailability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
- CVE-2023-488261 PoCTime Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List.
- CVE-2023-488271 PoCTime Slots Booking Calendar 4.0 is vulnerable to Multiple HTML Injection issues via the name, plugin_sms_api_key, plugin_sms_country_code,…
- CVE-2023-488281 PoCTime Slots Booking Calendar 4.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key,…
- CVE-2023-488301 PoCShuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export.
- CVE-2023-488311 PoCA lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.
- CVE-2023-488331 PoCA lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion.
- CVE-2023-488341 PoCA lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion.
- CVE-2023-488351 PoCCar Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
- CVE-2023-488361 PoCCar Rental Script 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key,…
- CVE-2023-488371 PoCCar Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
- CVE-2023-488381 PoCAppointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code.
- CVE-2023-488401 PoCA lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.
- CVE-2023-488411 PoCAppointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
- CVE-2023-488421 PoCD-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi.
- CVE-2023-488491 PoCRuijie EG Series Routers version EG_3.0(1)B11P216 and before allows unauthenticated attackers to remotely execute arbitrary code due to…
- CVE-2023-488581 PoCA Cross-site scripting (XSS) vulnerability in login page php code in Armex ABO.CMS 5.9 allows remote attackers to inject arbitrary web…
- CVE-2023-488591 PoCTOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows attackers to bypass…
- CVE-2023-488601 PoCTOTOLINK N300RT version 3.2.4-B20180730.0906 has a post-authentication RCE due to incorrect access control, allows attackers can bypass…
- CVE-2023-488611 PoCDLL hijacking vulnerability in TTplayer version 7.0.2, allows local attackers to escalate privileges and execute arbitrary code via…
- CVE-2023-488631 PoCSEMCMS 3.9 is vulnerable to SQL Injection. Due to the lack of security checks on the input of the application, the attacker uses the…
- CVE-2023-488871 PoCA deserialization vulnerability in Jupiter v1.3.1 allows attackers to execute arbitrary commands via sending a crafted RPC request.
- CVE-2023-488931 PoCSLiMS (aka SENAYAN Library Management System) through 9.6.1 allows admin/modules/reporting/customs/staff_act.php SQL Injection via…
- CVE-2023-488941 PoCIncorrect Access Control vulnerability in jshERP V3.3 allows attackers to obtain sensitive information via the doFilter function.
- CVE-2023-489011 PoCA SQL injection vulnerability in tramyardg Autoexpress version 1.3.0, allows remote unauthenticated attackers to execute arbitrary SQL…
- CVE-2023-489021 PoCAn issue was discovered in tramyardg autoexpress version 1.3.0, allows unauthenticated remote attackers to escalate privileges, update car…
- CVE-2023-489031 PoCStored Cross-Site Scripting (XSS) vulnerability in tramyardg autoexpress 1.3.0, allows remote unauthenticated attackers to inject…
- CVE-2023-489101 PoCMicrocks up to 1.17.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download. This…
- CVE-2023-489281 PoCFranklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Open Redirect. The 'path' parameter of the…
- CVE-2023-489291 PoCFranklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Session Fixation. The 'sid' parameter in the…
- CVE-2023-489451 PoCA stack overflow in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
- CVE-2023-489461 PoCAn issue in the box_mpy function of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running…
- CVE-2023-489471 PoCAn issue in the cha_cmp function of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running…
- CVE-2023-489481 PoCAn issue in the box_div function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running…
- CVE-2023-489491 PoCAn issue in the box_add function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after running…
- CVE-2023-489501 PoCAn issue in the box_col_len function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after…
- CVE-2023-489511 PoCAn issue in the box_equal function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) after…
- CVE-2023-489521 PoCAn issue in the box_deserialize_reusing function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service…
- CVE-2023-489572 PoCsPureVPN Linux client 2.0.2-Productions fails to properly handle DNS queries, allowing them to bypass the VPN tunnel and be sent directly…
- CVE-2023-489581 PoCgpac 2.3-DEV-rev617-g671976fcc-master contains memory leaks in gf_mpd_resolve_url media_tools/mpd.c:4589.
- CVE-2023-489631 PoCTenda i6 V1.0.0.8(3856) is vulnerable to Buffer Overflow via /goform/wifiSSIDget.
- CVE-2023-489641 PoCTenda i6 V1.0.0.8(3856) is vulnerable to Buffer Overflow via /goform/WifiMacFilterSet.
- CVE-2023-489671 PoCSsolon <= 2.6.0 and <=2.5.12 is vulnerable to Deserialization of Untrusted Data.
- CVE-2023-489742 PoCsCross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted…