CVE-2023-49000 to CVE-2023-49999
164 CVEs with public proof-of-concept exploits.
- CVE-2023-490021 PoCAn issue in Xenom Technologies (sinous) Phone Dialer-voice Call Dialer v.1.2.5 allows an attacker to bypass intended access restrictions…
- CVE-2023-490062 PoCsCross Site Request Forgery (CSRF) vulnerability in Phpsysinfo version 3.4.3 allows a remote attacker to obtain sensitive information via a…
- CVE-2023-490071 PoCIn Netgear Orbi RBR750 firmware before V7.2.6.21, there is a stack-based buffer overflow in /usr/sbin/httpd.
- CVE-2023-490311 PoCDirectory Traversal (Local File Inclusion) vulnerability in Tikit (now Advanced) eMarketing platform 6.8.3.0 allows a remote attacker to…
- CVE-2023-490341 PoCCross Site Scripting (XSS) vulnerability in ProjeQtOr 11.0.2 allows a remote attacker to execute arbitrary code via a crafted script to…
- CVE-2023-490401 PoCAn issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the adslPwd parameter in the…
- CVE-2023-490421 PoCHeap Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the schedStartTime parameter…
- CVE-2023-490431 PoCBuffer Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the wpapsk_crypto parameter…
- CVE-2023-490441 PoCStack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the ssid parameter in the…
- CVE-2023-490461 PoCStack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the devName parameter in the…
- CVE-2023-490471 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the devName parameter in the function formSetDeviceName.
- CVE-2023-490522 PoCsFile Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload…
- CVE-2023-4907012 PoCsPre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
- CVE-2023-490761 PoCPimcore missing token/header to prevent CSRF
- CVE-2023-490781 PoCCross-Site Scripting vulnerability in raptor-web 0.4.4
- CVE-2023-490811 PoCaiohttp's ClientSession is vulnerable to CRLF injection via version
- CVE-2023-490822 PoCsaiohttp's ClientSession is vulnerable to CRLF injection via method
- CVE-2023-490832 PoCscryptography vulnerable to NULL-dereference when loading PKCS7 certificates
- CVE-2023-490841 PoCLocal File Inclusion (RCE) in Cacti
- CVE-2023-490851 PoCCacti SQL Injection vulnerability
- CVE-2023-490861 PoCCacti is vulnerable to cross-Site scripting (XSS) DOM
- CVE-2023-490881 PoCCacti has incomplete fix for CVE-2023-39515
- CVE-2023-490911 PoCJwttoken in Cosmos server never expires after password changed and logging out
- CVE-2023-490932 PoCsHtmlUnit vulnerable to Remote Code Execution (RCE) via XSTL
- CVE-2023-491036 PoCsKEVAn issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party…
- CVE-2023-491051 PoCKEVAn issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without…
- CVE-2023-491091 PoCRemote Code Execution in Apache Dolphinscheduler
- CVE-2023-491142 PoCsLocal Privilege Escalation via DLL Hijacking
- CVE-2023-491473 PoCsAn issue was discovered in PDF24 Creator 11.14.0. The configuration of the msi installer file was found to produce a visible cmd.exe…
- CVE-2023-492101 PoCThe openssl (aka node-openssl) NPM package through 2.0.0 was characterized as "a nonsense wrapper with no real purpose" by its author, and…
- CVE-2023-492301 PoCAn issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows attackers to modify…
- CVE-2023-492751 PoCWazuh vulnerable to NULL Pointer Dereference in wazuh-analysisd
- CVE-2023-492762 PoCsAttribute Injection leading to XSS(Cross-Site-Scripting) in uptime-kuma
- CVE-2023-492872 PoCsBuffer overflow vulnerabilities in tinydir
- CVE-2023-492901 PoCMalicious parameters can cause a denial of service in lestrrat-go/jwx
- CVE-2023-492911 PoCImproper Sanitization of Branch Name Leads to Arbitrary Code Injection
- CVE-2023-492933 PoCsCross-site Scripting in `server.transformIndexHtml` via URL payload in vite
- CVE-2023-492972 PoCsUnsafe YAML deserialization in PyDrive2
- CVE-2023-493131 PoCA dylib injection vulnerability in XMachOViewer 0.04 allows attackers to compromise integrity. By exploiting this, unauthorized code can…
- CVE-2023-493141 PoCAsana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code…
- CVE-2023-493391 PoCEllucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the…
- CVE-2023-493561 PoCA stack buffer overflow vulnerability in MP3Gain v1.6.2 allows an attacker to cause a denial of service via the WriteMP3GainAPETag…
- CVE-2023-493671 PoCAn issue in user interface in Kyocera Command Center RX EXOSYS M5521cdn allows remote to obtain sensitive information via inspecting sent…
- CVE-2023-493711 PoCRuoYi up to v4.6 was discovered to contain a SQL injection vulnerability via /system/dept/edit.
- CVE-2023-493721 PoCJFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/slide/save.
- CVE-2023-493731 PoCJFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/slide/delete.
- CVE-2023-493741 PoCJFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/slide/update.
- CVE-2023-493751 PoCJFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/update.
- CVE-2023-493761 PoCJFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/delete.
- CVE-2023-493771 PoCJFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/update.
- CVE-2023-493781 PoCJFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/form/save.
- CVE-2023-493791 PoCJFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /admin/friend_link/save.
- CVE-2023-493801 PoCJFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/delete.
- CVE-2023-493811 PoCJFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/update.
- CVE-2023-493821 PoCJFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/delete.
- CVE-2023-493831 PoCJFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/save.
- CVE-2023-493911 PoCAn issue was discovered in free5GC version 3.3.0, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) on…
- CVE-2023-493951 PoCJFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/update.
- CVE-2023-493961 PoCJFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/save.
- CVE-2023-493971 PoCJFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/updateStatus.
- CVE-2023-493981 PoCJFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/delete.
- CVE-2023-494021 PoCTenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg.
- CVE-2023-494031 PoCTenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setFixTools.
- CVE-2023-494041 PoCTenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formAdvancedSetListSet.
- CVE-2023-494051 PoCTenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function UploadCfg.
- CVE-2023-494061 PoCTenda W30E V16.01.0.12(4843) was discovered to contain a Command Execution vulnerability via the function /goform/telnet.
- CVE-2023-494081 PoCTenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the function set_device_name.
- CVE-2023-494091 PoCTenda AX3 V16.03.12.11 was discovered to contain a Command Execution vulnerability via the function /goform/telnet.
- CVE-2023-494101 PoCTenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function via the function set_wan_status.
- CVE-2023-494111 PoCTenda W30E V16.01.0.12(4843) contains a stack overflow vulnerability via the function formDeleteMeshNode.
- CVE-2023-494171 PoCTOTOLink A7000R V9.1.0u.6115_B20201022 has a stack overflow vulnerability via setOpModeCfg.
- CVE-2023-494181 PoCTOTOLink A7000R V9.1.0u.6115_B20201022has a stack overflow vulnerability via setIpPortFilterRules.
- CVE-2023-494241 PoCTenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.
- CVE-2023-494251 PoCTenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCfg .
- CVE-2023-494261 PoCTenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.
- CVE-2023-494281 PoCTenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.
- CVE-2023-494311 PoCTenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.
- CVE-2023-494321 PoCTenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' parameter at /goform/setMacFilterCfg.
- CVE-2023-494331 PoCTenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetVirtualServerCfg.
- CVE-2023-494351 PoCTenda AX9 V22.03.01.46 is vulnerable to command injection.
- CVE-2023-494361 PoCTenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at…
- CVE-2023-494371 PoCTenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at…
- CVE-2023-494382 PoCsAn open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspecting users to…
- CVE-2023-494402 PoCsAhnLab EPP 1.0.15 is vulnerable to SQL Injection via the "preview parameter."
- CVE-2023-494461 PoCJFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/save.
- CVE-2023-494471 PoCJFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/update.
- CVE-2023-494481 PoCJFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/nav/delete.
- CVE-2023-494601 PoClibheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::decode_uncompressed_image.
- CVE-2023-494621 PoClibheif v1.17.5 was discovered to contain a segmentation violation via the component /libheif/exif.cc.
- CVE-2023-494631 PoClibheif v1.17.5 was discovered to contain a segmentation violation via the function find_exif_tag at /libheif/exif.cc.
- CVE-2023-494641 PoClibheif v1.17.5 was discovered to contain a segmentation violation via the function…
- CVE-2023-494651 PoCLibde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function at…
- CVE-2023-494671 PoCLibde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_combined_bipredictive_merging_candidates…
- CVE-2023-494681 PoCLibde265 v1.0.14 was discovered to contain a global buffer overflow vulnerability in the read_coding_unit function at slice.cc.
- CVE-2023-494711 PoCBlind Server-Side Request Forgery (SSRF) vulnerability in karlomikus Bar Assistant before version 3.2.0 does not validate a parameter…
- CVE-2023-494841 PoCDreamer CMS v4.1.3 was discovered to contain a cross-site scripting (XSS) vulnerability in the article management department.
- CVE-2023-494891 PoCReflective Cross Site Scripting (XSS) vulnerability in KodExplorer version 4.51, allows attackers to obtain sensitive information and…
- CVE-2023-494921 PoCDedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the imgstick parameter at…
- CVE-2023-494931 PoCDedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the v parameter at selectimages.php.
- CVE-2023-494942 PoCsDedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component…
- CVE-2023-495012 PoCsBuffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output…
- CVE-2023-495021 PoCBuffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the…
- CVE-2023-495281 PoCBuffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial…
- CVE-2023-495391 PoCBook Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/category.…
- CVE-2023-495401 PoCBook Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/history. This…
- CVE-2023-495431 PoCIncorrect access control in Book Store Management System v1 allows attackers to access unauthorized pages and execute administrative…
- CVE-2023-495441 PoCA local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via…
- CVE-2023-495451 PoCA directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the…
- CVE-2023-495461 PoCCustomer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php.
- CVE-2023-495471 PoCCustomer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at…
- CVE-2023-495481 PoCCustomer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at…
- CVE-2023-495491 PoCAn issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_getretvalpos function in the msj.c file.
- CVE-2023-495501 PoCAn issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508 component.
- CVE-2023-495511 PoCAn issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_parse function in the msj.c file.
- CVE-2023-495521 PoCAn Out of Bounds Write in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_stringify function…
- CVE-2023-495531 PoCAn issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_destroy function in the msj.c file.
- CVE-2023-495541 PoCUse After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_directive function in…
- CVE-2023-495551 PoCAn issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in the…
- CVE-2023-495561 PoCBuffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_delete_term…
- CVE-2023-495571 PoCAn issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the…
- CVE-2023-495581 PoCAn issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in the…
- CVE-2023-495631 PoCCross Site Scripting (XSS) in Voltronic Power SNMP Web Pro v.1.1 allows an attacker to execute arbitrary code via a crafted script within…
- CVE-2023-496062 PoCsA use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted…
- CVE-2023-496931 PoCNETGEAR ProSAFE Network Management System RCE via Unprotected Access to Java Debug Wire Protocol
- CVE-2023-496941 PoCNETGEAR ProSAFE Network Management System Privilege Escalation Via MySQL Server
- CVE-2023-497811 PoCNocoDB Vulnerable to Stored Cross-Site Scripting in Formula.vue
- CVE-2023-497852 PoCsNextChat vulnerable to Server-Side Request Forgery and Cross-site Scripting
- CVE-2023-497862 PoCsAsterisk susceptible to Denial of Service via DTLS Hello packets during call initiation
- CVE-2023-497932 PoCsPath traversal in `CodeChecker server` in the endpoint of `CodeChecker store`
- CVE-2023-497941 PoCThe logic of get apk path in KernelSU module can be bypassed
- CVE-2023-497992 PoCsServer-Side Request Forgery in nuxt-api-party
- CVE-2023-498002 PoCsDenial of service by abusing `fetchOptions.retry` in nuxt-api-party
- CVE-2023-498051 PoCUptime Kuma Missing Origin Validation in WebSockets
- CVE-2023-498101 PoCA login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit…
- CVE-2023-499501 PoCThe Jinja templating in Logpoint SIEM 6.10.0 through 7.x before 7.3.0 does not correctly sanitize log data being displayed when using a…
- CVE-2023-499541 PoCThe CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search string, or email…
- CVE-2023-499651 PoCSpaceX Starlink Wi-Fi router Gen 2 before 2023.48.0 allows XSS via the ssid and password parameters on the Setup Page.
- CVE-2023-499671 PoCTypecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc.
- CVE-2023-499681 PoCCustomer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at…
- CVE-2023-499691 PoCCustomer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at…
- CVE-2023-499701 PoCCustomer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at…
- CVE-2023-499711 PoCA cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2023-499731 PoCA cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2023-499741 PoCA cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2023-499761 PoCA cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2023-499771 PoCA cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2023-499781 PoCIncorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions…
- CVE-2023-499791 PoCA directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the…
- CVE-2023-499801 PoCA directory listing vulnerability in Best Student Result Management System v1.0 allows attackers to list directories and sensitive files…
- CVE-2023-499811 PoCA directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within…
- CVE-2023-499821 PoCBroken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate…
- CVE-2023-499831 PoCA cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to…
- CVE-2023-499841 PoCA cross-site scripting (XSS) vulnerability in the component /management/settings of School Fees Management System v1.0 allows attackers to…
- CVE-2023-499851 PoCA cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to…
- CVE-2023-499861 PoCA cross-site scripting (XSS) vulnerability in the component /admin/parent of School Fees Management System 1.0 allow attackers to execute…
- CVE-2023-499871 PoCA cross-site scripting (XSS) vulnerability in the component /management/term of School Fees Management System v1.0 allows attackers to…
- CVE-2023-499881 PoCHotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the npss parameter at rooms.php.
- CVE-2023-499891 PoCHotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at update.php.
- CVE-2023-499901 PoCEspeak-ng 1.52-dev was discovered to contain a buffer-overflow via the function SetUpPhonemeTable at synthdata.c.
- CVE-2023-499911 PoCEspeak-ng 1.52-dev was discovered to contain a Stack Buffer Underflow via the function CountVowelPosition at synthdata.c.
- CVE-2023-499921 PoCEspeak-ng 1.52-dev was discovered to contain a Stack Buffer Overflow via the function RemoveEnding at dictionary.c.
- CVE-2023-499931 PoCEspeak-ng 1.52-dev was discovered to contain a Buffer Overflow via the function ReadClause at readclause.c.
- CVE-2023-499941 PoCEspeak-ng 1.52-dev was discovered to contain a Floating Point Exception via the function PeaksToHarmspect at wavegen.c.
- CVE-2023-499991 PoCTenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setUmountUSBPartition.