CVE-2023-4000 to CVE-2023-4999
345 CVEs with public proof-of-concept exploits.
- CVE-2023-40041 PoCKernel: netfilter: use-after-free due to improper element removal in nft_pipapo_remove()
- CVE-2023-40131 PoCGDPR Cookie Compliance < 4.12.5 - License Update/Deactivation via CSRF
- CVE-2023-40181 PoCDirect Request ('Forced Browsing') in GitLab
- CVE-2023-40191 PoCMedia from FTP < 11.17 - Author+ Arbitrary File Access
- CVE-2023-40221 PoCHerd Effects < 5.2.3 - Admin+ Stored XSS
- CVE-2023-40231 PoCAll Users Messenger <= 1.24 - Subscriber+ Message Deletion via IDOR
- CVE-2023-40351 PoCSimple Blog Card < 1.31 - Contributor+ Stored XSS via Shortcode
- CVE-2023-40361 PoCSimple Blog Card < 1.32 - Subscriber+ Arbitrary Post Access
- CVE-2023-40391 PoCGCC's-fstack-protector fails to guard dynamically-sized local variables on AArch64
- CVE-2023-40591 PoCProfile Builder < 3.9.8 - Unauthenticated Plugin's Pages Creation
- CVE-2023-40601 PoCWP Adminify < 3.1.6 - Admin+ Stored XSS
- CVE-2023-41091 PoCNinja Forms < 3.6.26 - Admin+ Stored HTML Injection
- CVE-2023-41102 PoCsPHP Jabbers Availability Booking Calendar index.php cross site scripting
- CVE-2023-41112 PoCsPHP Jabbers Bus Reservation System index.php cross site scripting
- CVE-2023-41123 PoCsPHP Jabbers Shuttle Booking Software index.php cross site scripting
- CVE-2023-41133 PoCsPHP Jabbers Service Booking Script index.php cross site scripting
- CVE-2023-41142 PoCsPHP Jabbers Night Club Booking Software index.php cross site scripting
- CVE-2023-41153 PoCsPHP Jabbers Cleaning Business index.php cross site scripting
- CVE-2023-41163 PoCsPHP Jabbers Taxi Booking index.php cross site scripting
- CVE-2023-41172 PoCsPHP Jabbers Rental Property Booking index.php cross site scripting
- CVE-2023-41181 PoCCute Http File Server Search cross site scripting
- CVE-2023-41191 PoCAcademy LMS courses cross site scripting
- CVE-2023-41201 PoCByzoro Smart S85F Management Platform importhtml.php command injection
- CVE-2023-41211 PoCByzoro Smart S85F Management Platform unrestricted upload
- CVE-2023-41241 PoCMissing Authorization in answerdev/answer
- CVE-2023-41251 PoCWeak Password Requirements in answerdev/answer
- CVE-2023-41261 PoCInsufficient Session Expiration in answerdev/answer
- CVE-2023-41271 PoCRace Condition within a Thread in answerdev/answer
- CVE-2023-41301 PoCksmbd: fix wrong next length validation of ea buffer in smb2_set_ea()
- CVE-2023-41361 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Crafter Engine
- CVE-2023-41381 PoCAllocation of Resources Without Limits or Throttling in ikus060/rdiffweb
- CVE-2023-41451 PoCCross-site Scripting (XSS) - Stored in pimcore/customer-data-framework
- CVE-2023-41471 PoCKernel: netfilter: nf_tables_newrule when adding a rule with nfta_rule_chain_id leads to use-after-free
- CVE-2023-41482 PoCsDitty < 3.1.25 - Reflected XSS
- CVE-2023-41501 PoCUser Activity Tracking and Log < 4.0.9 - License Update/Deactivation via CSRF
- CVE-2023-41512 PoCsStore Locator WordPress < 1.4.13 - Reflected XSS
- CVE-2023-41571 PoCImproper Neutralization of Special Elements in Output Used by a Downstream Component in omeka/omeka-s
- CVE-2023-41581 PoCCross-site Scripting (XSS) - Stored in omeka/omeka-s
- CVE-2023-41591 PoCUnrestricted Upload of File with Dangerous Type in omeka/omeka-s
- CVE-2023-41653 PoCsTongda OA delete_seal.php sql injection
- CVE-2023-41664 PoCsTongda OA delete_log.php sql injection
- CVE-2023-41671 PoCMedia Browser Emby Server cross site scripting
- CVE-2023-41683 PoCsTemplatecookie Adlisting Redirect ad-list information disclosure
- CVE-2023-41694 PoCsRuijie RG-EW1200G Administrator Password set_passwd access control
- CVE-2023-41701 PoCDedeBIZ Article cross site scripting
- CVE-2023-41711 PoCChengdu Flash Flood Disaster Monitoring and Warning System FileDownload.ashx path traversal
- CVE-2023-41721 PoCChengdu Flash Flood Disaster Monitoring and Warning System FileHandler.ashx absolute path traversal
- CVE-2023-41733 PoCsmooSocial mooStore index cross site scripting
- CVE-2023-41744 PoCsmooSocial mooStore cross site scripting
- CVE-2023-41761 PoCSourceCodester Hospital Management System appointmentapproval.php sql injection
- CVE-2023-41791 PoCSourceCodester Free Hospital Management System for Small Practices sql injection
- CVE-2023-41801 PoCSourceCodester Free Hospital Management System for Small Practices login.php sql injection
- CVE-2023-41811 PoCSourceCodester Free Hospital Management System for Small Practices Redirect behavioral workflow
- CVE-2023-41851 PoCSourceCodester Online Hospital Management System patientlogin.php sql injection
- CVE-2023-41861 PoCSourceCodester Pharmacy Management System manage_website.php unrestricted upload
- CVE-2023-41871 PoCCross-site Scripting (XSS) - Stored in instantsoft/icms2
- CVE-2023-41881 PoCSQL Injection in instantsoft/icms2
- CVE-2023-41891 PoCCross-site Scripting (XSS) - Reflected in instantsoft/icms2
- CVE-2023-41901 PoCInsufficient Session Expiration in admidio/admidio
- CVE-2023-41911 PoCSourceCodester Resort Reservation System index.php file inclusion
- CVE-2023-41921 PoCSourceCodester Resort Reservation System manage_user.php sql injection
- CVE-2023-41931 PoCSourceCodester Resort Reservation System view_fee.php sql injection
- CVE-2023-41951 PoCPHP Remote File Inclusion in cockpit-hq/cockpit
- CVE-2023-41961 PoCCross-site Scripting (XSS) - Stored in cockpit-hq/cockpit
- CVE-2023-41972 PoCsDolibarr ERP CRM (<= 18.0.1) Improper Input Sanitization Authenticated RCE
- CVE-2023-41981 PoCDolibarr ERP CRM (<= 17.0.3) Improper Access Control
- CVE-2023-41991 PoCSourceCodester Inventory Management System catagory_data.php sql injection
- CVE-2023-42001 PoCSourceCodester Inventory Management System product_data.php. sql injection
- CVE-2023-42011 PoCSourceCodester Inventory Management System ex_catagory_data.php sql injection
- CVE-2023-42021 PoCStored Cross-Site Scripting
- CVE-2023-42031 PoCStored Cross-Site Scripting
- CVE-2023-42091 PoCPOEditor < 0.9.8 - Settings Reset via CSRF
- CVE-2023-42161 PoCOrders Tracking for WooCommerce < 1.2.6 - Admin+ Arbitrary File Access/Read
- CVE-2023-42191 PoCSourceCodester Doctors Appointment System login.php sql injection
- CVE-2023-422034 PoCsChamilo LMS Unauthenticated Big Upload File Remote Code Execution
- CVE-2023-42211 PoCChamilo LMS Learning Path PPT2LP Command Injection Vulnerability
- CVE-2023-42221 PoCChamilo LMS Learning Path PPT2LP Command Injection Vulnerability
- CVE-2023-42231 PoCChamilo LMS File Upload Functionality Remote Code Execution
- CVE-2023-42241 PoCChamilo LMS File Upload Functionality Remote Code Execution
- CVE-2023-42251 PoCChamilo LMS File Upload Functionality Remote Code Execution
- CVE-2023-42263 PoCsChamilo LMS File Upload Functionality Remote Code Execution
- CVE-2023-42351 PoCOfono: sms decoder stack-based buffer overflow remote code execution vulnerability within the decode_deliver_report() function
- CVE-2023-42381 PoCPrevent files / folders access < 2.5.2 - Admin+ Arbitrary File Upload
- CVE-2023-42431 PoCFULL - Customer <= 2.2.3 - Authenticated(Subscriber+) Improper Authorization to Arbitrary Plugin Installation
- CVE-2023-42441 PoCUse-after-free in Linux kernel's netfilter: nf_tables component
- CVE-2023-42501 PoCEventPrime < 3.2.0 - Reflected XSS
- CVE-2023-42511 PoCEventPrime < 3.2.0 - Booking Creation via CSRF
- CVE-2023-42521 PoCEventPrime <= 3.2.9 - Booking Pricing Bypass
- CVE-2023-42531 PoCChatbot < 4.7.8 - Admin+ Stored XSS in FAQ Builder
- CVE-2023-42541 PoCChatbot < 4.7.8 - Admin+ Stored XSS in Language Settings
- CVE-2023-42551 PoCW3m: out-of-bounds write in function checktype() in etc.c (incomplete fix for cve-2022-38223)
- CVE-2023-42561 PoCTcpreplay: tcprewrite: double free in tcpedit_dlt_cleanup() in plugins/dlt_plugins.c
- CVE-2023-42572 PoCsUnchecked user input length in the Zephyr WiFi shell module
- CVE-2023-42591 PoCPotential buffer overflow vulnerabilities in the Zephyr eS-WiFi driver
- CVE-2023-42601 PoCPotential off-by-one buffer overflow vulnerability in the Zephyr FS subsystem
- CVE-2023-42641 PoCPotential buffer overflow vulnerabilities in the Zephyr Bluetooth subsystem
- CVE-2023-42652 PoCsBuffer overflow in Zephyr USB
- CVE-2023-42691 PoCUser Activity Log < 1.6.6 - Subscriber+ Log Export
- CVE-2023-42701 PoCMin Max Control < 4.6 - Reflected XSS
- CVE-2023-42783 PoCsMasterStudy LMS < 3.0.18 - Unauthenticated Instructor Account Creation
- CVE-2023-42792 PoCsUser Activity Log < 1.6.7 - IP Spoofing
- CVE-2023-42812 PoCsActivity Log < 2.8.8 - IP Spoofing
- CVE-2023-42842 PoCsPost Timeline < 2.2.6 - Reflected XSS
- CVE-2023-42891 PoCWP Matterport Shortcode < 2.1.8 - Contributor+ Stored XSS via shortcode
- CVE-2023-42901 PoCWP Matterport Shortcode < 2.1.7 - Reflected XSS
- CVE-2023-42942 PoCsURL Shortify < 1.7.6 - Unauthenticated Stored XSS via referer header
- CVE-2023-42971 PoCMmm Simple File List <= 2.3 - Subscriber+ Arbitrary Directory Listing
- CVE-2023-42981 PoC123.chat < 1.3.1 - Admin+ Stored XSS
- CVE-2023-43002 PoCsImport XML and RSS Feeds < 2.1.4 - Admin+ Arbitrary File Upload
- CVE-2023-43041 PoCBusiness Logic Errors in froxlor/froxlor
- CVE-2023-43071 PoCLock User Account <= 1.0.3 - Arbitrary Account Lock/Unlock via CSRF
- CVE-2023-43111 PoCVrm 360 3D Model Viewer <= 1.2.1 - Contributor+ Arbitrary File Upload Leading to RCE
- CVE-2023-43141 PoCwpDataTables < 2.1.66 - Admin+ PHP Object Injection
- CVE-2023-43171 PoCIncorrect Authorization in GitLab
- CVE-2023-43181 PoCHerd Effects < 5.2.4 - Effect Deletion via CSRF
- CVE-2023-43211 PoCCross-site Scripting (XSS) - Stored in cockpit-hq/cockpit
- CVE-2023-43221 PoCHeap-based Buffer Overflow in radareorg/radare2
- CVE-2023-43471 PoCCross-site Scripting (XSS) - Reflected in librenms/librenms
- CVE-2023-43501 PoCInappropriate implementation in Fullscreen in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to potentially…
- CVE-2023-43577 PoCsInsufficient validation of untrusted input in XML in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to bypass file access…
- CVE-2023-43761 PoCSerial Codes Generator and Validator with WooCommerce Support < 2.4.15 - Admin+ Stored XSS
- CVE-2023-43781 PoCInsertion of Sensitive Information Into Sent Data in GitLab
- CVE-2023-43822 PoCstdevs Hyip Rio Profile Settings settings cross site scripting
- CVE-2023-43831 PoCMicroWorld eScan Anti-Virus runasroot incorrect execution-assigned permissions
- CVE-2023-43841 PoCMaximaTech Portal Executivo Cookie missing encryption
- CVE-2023-43881 PoCEventON < 2.2 - Admin+ Stored XSS
- CVE-2023-43901 PoCPopup box < 3.7.2 - Admin+ Stored Cross-Site Scripting
- CVE-2023-43921 PoCControl iD Gerencia Web Cookie cleartext storage
- CVE-2023-43951 PoCCross-site Scripting (XSS) - Stored in cockpit-hq/cockpit
- CVE-2023-44072 PoCsCodecanyon Credit Lite POST Request account_statement sql injection
- CVE-2023-44091 PoCNBS&HappySoftWeChat unrestricted upload
- CVE-2023-44101 PoCTOTOLINK EX1200L setDiagnosisCfg os command injection
- CVE-2023-44111 PoCTOTOLINK EX1200L setTracerouteCfg os command injection
- CVE-2023-44121 PoCTOTOLINK EX1200L setWanCfg os command injection
- CVE-2023-44141 PoCByzoro Smart S85F Management Platform decodmail.php command injection
- CVE-2023-44155 PoCsRuijie RG-EW1200G login improper authentication
- CVE-2023-44272 PoCsOut of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory…
- CVE-2023-44321 PoCCross-site Scripting (XSS) - Reflected in cockpit-hq/cockpit
- CVE-2023-44331 PoCCross-site Scripting (XSS) - Stored in cockpit-hq/cockpit
- CVE-2023-44341 PoCMissing Authorization in hamza417/inure
- CVE-2023-44351 PoCImproper Input Validation in hamza417/inure
- CVE-2023-44361 PoCSourceCodester Inventory Management System edit_update.php sql injection
- CVE-2023-44371 PoCSourceCodester Inventory Management System search_sell_paymen_report.php sql injection
- CVE-2023-44381 PoCSourceCodester Inventory Management System search_sales_report.php sql injection
- CVE-2023-44401 PoCSourceCodester Free Hospital Management System for Small Practices appointment.php sql injection
- CVE-2023-44421 PoCSourceCodester Free Hospital Management System for Small Practices booking-complete.php sql injection
- CVE-2023-44431 PoCSourceCodester Free Hospital Management System for Small Practices edit-doc.php sql injection
- CVE-2023-44441 PoCSourceCodester Free Hospital Management System for Small Practices edit-user.php sql injection
- CVE-2023-44451 PoCMini-Tmall sql injection
- CVE-2023-44461 PoCOpenRapid RapidCMS category.php sql injection
- CVE-2023-44471 PoCOpenRapid RapidCMS article-chat.php sql injection
- CVE-2023-44481 PoCOpenRapid RapidCMS run-movepass.php password recovery
- CVE-2023-44491 PoCSourceCodester Free and Open Source Inventory Management System sql injection
- CVE-2023-44504 PoCsjeecgboot JimuReport Template injection
- CVE-2023-44512 PoCsCross-site Scripting (XSS) - Reflected in cockpit-hq/cockpit
- CVE-2023-44531 PoCCross-site Scripting (XSS) - Reflected in pimcore/pimcore
- CVE-2023-44541 PoCCross-Site Request Forgery (CSRF) in wallabag/wallabag
- CVE-2023-44551 PoCCross-Site Request Forgery (CSRF) in wallabag/wallabag
- CVE-2023-44603 PoCsUploading SVG, WEBP and ICO files <= 1.2.1 - Author+ Stored XSS via SVG
- CVE-2023-44621 PoCPoly VVX 601 Web Configuration Application random values
- CVE-2023-44631 PoCPoly CCX 400/CCX 600/Trio 8800/Trio C60 HTTP Header denial of service
- CVE-2023-44641 PoCPoly VVX 601 Diagnostic Telnet Mode os command injection
- CVE-2023-44651 PoCPoly VVX 601 Configuration File Import unverified password change
- CVE-2023-44661 PoCPoly CCX 400/CCX 600/Trio 8800/Trio C60 Web Interface protection mechanism
- CVE-2023-44671 PoCPoly Trio 8800 Test Automation Mode backdoor
- CVE-2023-44681 PoCPoly Trio 8500/Trio 8800/Trio C60 Poly Lens Management Cloud Registration authorization
- CVE-2023-44761 PoCLocatoraid Store Locator < 3.9.24 - Reflected XSS
- CVE-2023-44902 PoCsWP Job Portal < 2.0.6 - Unauthenticated SQLi
- CVE-2023-45021 PoCTranslate WordPress with GTranslate < 3.0.4 - Admin+ Stored XSS
- CVE-2023-45043 PoCsOpenPrinting CUPS/libppd Postscript Parsing Heap Overflow
- CVE-2023-45051 PoCStaff / Employee Business Directory for Active Directory <= 1.2.3 - Authenticated (Admin+) LDAP Passback
- CVE-2023-45061 PoCActive Directory Integration / LDAP Integration <= 4.1.10 - LDAP Passback
- CVE-2023-45081 PoCDenial of Service in Gerbv
- CVE-2023-45121 PoCUncontrolled Recursion in Wireshark
- CVE-2023-45131 PoCMissing Release of Memory after Effective Lifetime in Wireshark
- CVE-2023-45141 PoCMmm Simple File List <= 2.3 - Contributor+ Stored XSS
- CVE-2023-45171 PoCCross-site Scripting (XSS) - Stored in hestiacp/hestiacp
- CVE-2023-45212 PoCsImport XML and RSS Feeds < 2.1.5 - Unauthenticated RCE
- CVE-2023-45221 PoCImproper Validation of Specified Type of Input in GitLab
- CVE-2023-45321 PoCIncorrect Authorization in GitLab
- CVE-2023-45341 PoCNeoMind Fusion Platform Link cross site scripting
- CVE-2023-45361 PoCMy Account Page Editor < 1.3.2 - Subscriber+ Arbitrary File Upload
- CVE-2023-45423 PoCsD-Link DAR-8000-10 sys1.php os command injection
- CVE-2023-45431 PoCIBOS OA export&contactids=x sql injection
- CVE-2023-45441 PoCByzoro Smart S85F Management Platform php.ini direct request
- CVE-2023-45451 PoCIBOS OA export&checkids=x sql injection
- CVE-2023-45461 PoCByzoro Smart S85F Management Platform licence.php access control
- CVE-2023-45473 PoCsSPA-Cart eCommerce CMS search cross site scripting
- CVE-2023-45482 PoCsSPA-Cart eCommerce CMS GET Parameter search sql injection
- CVE-2023-45492 PoCsDoLogin Security < 3.7 - Unauthenticated Stored Cross-Site Scripting
- CVE-2023-45551 PoCSourceCodester Inventory Management System suppliar_data.php cross site scripting
- CVE-2023-45561 PoCSourceCodester Online Graduate Tracer System sexit.php mysqli_query sql injection
- CVE-2023-45571 PoCSourceCodester Inventory Management System search_purchase_paymen_report.php sql injection
- CVE-2023-45581 PoCSourceCodester Inventory Management System staff_data.php sql injection
- CVE-2023-45601 PoCImproper Authorization of Index Containing Sensitive Information in omeka/omeka-s
- CVE-2023-45611 PoCCross-site Scripting (XSS) - Stored in omeka/omeka-s
- CVE-2023-45683 PoCsPaperCut NG Unauthenticated XMLRPC
- CVE-2023-45901 PoCBuffer Overflow vulnerability in Frhed
- CVE-2023-45965 PoCsForminator <= 1.24.6 - Unauthenticated Arbitrary File Upload
- CVE-2023-46201 PoCBooking Calendar < 9.7.3.1 - Unauthenticated Stored XSS
- CVE-2023-46221 PoCUse-after-free in Linux kernel's af_unix component
- CVE-2023-46241 PoCServer-Side Request Forgery (SSRF) in bookstackapp/bookstack
- CVE-2023-46312 PoCsDoLogin Security < 3.7 - IP Spoofing
- CVE-2023-46346 PoCsMedia Library Assistant <= 3.09 - Unauthenticated Local/Remote File Inclusion & Remote Code Execution
- CVE-2023-46361 PoCWordPress File Sharing Plugin <= 2.0.3 - Authenticated (Admin+) Stored Cross-Site Scripting
- CVE-2023-46421 PoCkk Star Ratings < 5.4.6 - Rating Tampering via Race Condition
- CVE-2023-46431 PoCEnable Media Replace < 4.1.3 - Author+ PHP Object Injection
- CVE-2023-46461 PoCSimple Posts Ticker < 1.1.6 - Contributor+ Stored XSS
- CVE-2023-46491 PoCSession Fixation in instantsoft/icms2
- CVE-2023-46501 PoCImproper Access Control in instantsoft/icms2
- CVE-2023-46511 PoCServer-Side Request Forgery (SSRF) in instantsoft/icms2
- CVE-2023-46521 PoCCross-site Scripting (XSS) - Stored in instantsoft/icms2
- CVE-2023-46531 PoCCross-site Scripting (XSS) - Stored in instantsoft/icms2
- CVE-2023-46541 PoCSensitive Cookie in HTTPS Session Without 'Secure' Attribute in instantsoft/icms2
- CVE-2023-46551 PoCCross-site Scripting (XSS) - Reflected in instantsoft/icms2
- CVE-2023-46581 PoCIncorrect Authorization in GitLab
- CVE-2023-46662 PoCsForm-Maker < 1.15.20 - Unauthenticated Arbitrary File Upload
- CVE-2023-46781 PoCDivide By Zero in gpac/gpac
- CVE-2023-46811 PoCNULL Pointer Dereference in gpac/gpac
- CVE-2023-46821 PoCHeap-based Buffer Overflow in gpac/gpac
- CVE-2023-46832 PoCsNULL Pointer Dereference in gpac/gpac
- CVE-2023-46871 PoCPageLayer < 1.7.7 - Unauthenticated Stored XSS
- CVE-2023-46911 PoCBookly < 22.4 - Admin+ SQLi
- CVE-2023-46941 PoCCertain HP OfficeJet Pro printers are potentially vulnerable to a Denial of Service when sending a SOAP message to the service on TCP port…
- CVE-2023-46961 PoCImproper Access Control in usememos/memos
- CVE-2023-46971 PoCImproper Privilege Management in usememos/memos
- CVE-2023-46982 PoCsImproper Input Validation in usememos/memos
- CVE-2023-47001 PoCMissing Authorization in GitLab
- CVE-2023-47031 PoCAll in One B2B for WooCommerce <= 1.0.3 - Unauthenticated Privilege Escalation
- CVE-2023-47081 PoCInfosoftbd Clcknshop GET Parameter all sql injection
- CVE-2023-47111 PoCD-Link DAR-8000-10 decodmail.php os command injection
- CVE-2023-47121 PoCXintian Smart Table Integrated Management System AddUpdateRole.aspx sql injection
- CVE-2023-47131 PoCIBOS OA addcomment addComment sql injection
- CVE-2023-47142 PoCsPlayTube Redirect information disclosure
- CVE-2023-47201 PoCFloating Point Comparison with Incorrect Operator in gpac/gpac
- CVE-2023-47211 PoCOut-of-bounds Read in gpac/gpac
- CVE-2023-47221 PoCInteger Overflow or Wraparound in gpac/gpac
- CVE-2023-47241 PoCWP All Export (Free < 1.4.0, Pro < 1.8.6) - Admin+ RCE
- CVE-2023-47251 PoCSimple Posts Ticker < 1.1.6 - Admin+ Stored XSS
- CVE-2023-47331 PoCUse After Free in vim/vim
- CVE-2023-47341 PoCInteger Overflow or Wraparound in vim/vim
- CVE-2023-47351 PoCOut-of-bounds Write in vim/vim
- CVE-2023-47361 PoCUntrusted Search Path in vim/vim
- CVE-2023-47381 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2023-47391 PoCByzoro Smart S85F Management Platform updateos.php unrestricted upload
- CVE-2023-47401 PoCIBOS OA Delete Draft delDraft&archiveId=0 sql injection
- CVE-2023-47412 PoCsIBOS OA Delete Logs del sql injection
- CVE-2023-47421 PoCIBOS OA export&uid=X sql injection
- CVE-2023-47431 PoCDreamer CMS file access
- CVE-2023-47441 PoCTenda AC8 formSetDeviceName stack-based overflow
- CVE-2023-47451 PoCByzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform importexport.php sql injection
- CVE-2023-47461 PoCTOTOLINK N200RE V5 Validity_check format string
- CVE-2023-47471 PoCDedeCMS tags.php sql injection
- CVE-2023-47481 PoCYongyou UFIDA-NC PrintTemplateFileServlet.java path traversal
- CVE-2023-47491 PoCSourceCodester Inventory Management System index.php file inclusion
- CVE-2023-47501 PoCUse After Free in vim/vim
- CVE-2023-47511 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2023-47521 PoCUse After Free in vim/vim
- CVE-2023-47541 PoCOut-of-bounds Write in gpac/gpac
- CVE-2023-47551 PoCUse After Free in gpac/gpac
- CVE-2023-47561 PoCStack-based Buffer Overflow in gpac/gpac
- CVE-2023-47571 PoCStaff / Employee Business Directory for Active Directory < 1.2.3 - Improper escaping of LDAP entries
- CVE-2023-47581 PoCBuffer Over-read in gpac/gpac
- CVE-2023-47623 PoCsKEVType Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page.…
- CVE-2023-47711 PoCCross-Site Scripting vulnerability in CKSource CKEditor
- CVE-2023-47761 PoCWPSchoolPress < 2.2.5 - Teacher+ SQLi
- CVE-2023-47781 PoCOut-of-bounds Read in gpac/gpac
- CVE-2023-47811 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2023-47831 PoCMagee Shortcodes <= 2.1.1 - Contributor+ Stored XSS via shortcode
- CVE-2023-47951 PoCTestimonial Slider Shortcode < 1.1.9 - Contributor+ Stored XSS
- CVE-2023-47971 PoCNewsletter Lite < 4.9.3 - Admin+ Command Injection
- CVE-2023-47981 PoCUser Avatar - Reloaded < 1.2.2 - Contributor+ Stored XSS
- CVE-2023-47991 PoCMagic Embeds < 3.1.2 - Contributor+ Stored XSS via shortcode
- CVE-2023-48002 PoCsDoLogin Security < 3.7.1 - Subscriber+ IP Address leak
- CVE-2023-48051 PoCTutor LMS < 2.3.0 - Subscriber+ Stored Cross-Site Scripting
- CVE-2023-48081 PoCWP Post Popup <= 3.7.3 - Admin+ Stored XSS
- CVE-2023-48101 PoCResponsive Pricing Table < 5.1.8 - Admin+ Stored Cross-Site Scriping
- CVE-2023-48111 PoCWordPress File Upload < 4.23.3 - Author+ Stored Cross-Site Scripting
- CVE-2023-48121 PoCIncorrect Authorization in GitLab
- CVE-2023-48131 PoCGlibc: potential use-after-free in gaih_inet()
- CVE-2023-48151 PoCMissing Authentication for Critical Function in answerdev/answer
- CVE-2023-48181 PoCPAX A920 device allows to downgrade bootloader due to a bug in its version check. The signature is correctly checked and only bootloader…
- CVE-2023-48191 PoCShared Files < 1.7.6 - Unauthenticated Stored Cross-Site Scripting
- CVE-2023-48201 PoCPowerPress Podcasting < 11.0.12 - Contributor+ Stored XSS
- CVE-2023-48211 PoCDrag and Drop Multiple File Upload < 1.1.1 - Unauthenticated Stored Cross-Site Scripting
- CVE-2023-48231 PoCWP Meta and Date Remover < 2.2.0 - Subscriber+ Stored XSS
- CVE-2023-48241 PoCWooHoo Newspaper Magazine Theme <= 2.5.3 - Settings Update via CSRF
- CVE-2023-48261 PoCSocialdriver < 2024 - Prototype Pollution to XSS
- CVE-2023-48271 PoCFile Manager Pro < 1.8 - Remote Code Execution via CSRF
- CVE-2023-48291 PoCCross-site Scripting (XSS) - Stored in froxlor/froxlor
- CVE-2023-48362 PoCsWordPress File Sharing Plugin < 2.0.5 - Subscriber+ Sensitive Data and Files Exposure via IDOR
- CVE-2023-48441 PoCSourceCodester Simple Membership System club_edit_query.php sql injection
- CVE-2023-48451 PoCSourceCodester Simple Membership System account_edit_query.php sql injection
- CVE-2023-48461 PoCSourceCodester Simple Membership System delete_member.php sql injection
- CVE-2023-48471 PoCSourceCodester Simple Book Catalog App Update Book Form cross site scripting
- CVE-2023-48481 PoCSourceCodester Simple Book Catalog App delete_book.php sql injection
- CVE-2023-48491 PoCIBOS OA trash&op=del sql injection
- CVE-2023-48501 PoCIBOS OA del sql injection
- CVE-2023-48511 PoCIBOS OA edit&op=member sql injection
- CVE-2023-48521 PoCIBOS OA optimize sql injection
- CVE-2023-48582 PoCsWP Simple Table Manager Plugin <= 1.5.6 - Admin+ Stored Cross-Site Scripting
- CVE-2023-48612 PoCsFile Manager Pro < 1.8.1 - Admin+ Remote Code Execution
- CVE-2023-48621 PoCFile Manager Pro < 1.8.1 - Admin+ Stored Cross-Site Scripting
- CVE-2023-486311 PoCsKEVHeap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of…
- CVE-2023-48641 PoCSourceCodester Take-Note App index.php cross site scripting
- CVE-2023-48651 PoCSourceCodester Take-Note App cross-site request forgery
- CVE-2023-48661 PoCSourceCodester Online Tours & Travels Management System booking.php exec sql injection
- CVE-2023-48671 PoCXintian Smart Table Integrated Management System Added Site Page AddUpdateSites.aspx sql injection
- CVE-2023-48681 PoCSourceCodester Contact Manager App add.php cross-site request forgery
- CVE-2023-48691 PoCSourceCodester Contact Manager App update.php cross-site request forgery
- CVE-2023-48701 PoCSourceCodester Contact Manager App Contact Information index.php cross site scripting
- CVE-2023-48711 PoCSourceCodester Contact Manager App delete.php sql injection
- CVE-2023-48721 PoCSourceCodester Contact Manager App add.php sql injection
- CVE-2023-48731 PoCByzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform importexport.php os command injection
- CVE-2023-48781 PoCServer-Side Request Forgery (SSRF) in instantsoft/icms2
- CVE-2023-48791 PoCCross-site Scripting (XSS) - Stored in instantsoft/icms2
- CVE-2023-48951 PoCMissing Authorization in GitLab
- CVE-2023-48971 PoCRelative Path Traversal in mintplex-labs/anything-llm
- CVE-2023-48981 PoCAuthentication Bypass by Primary Weakness in mintplex-labs/anything-llm
- CVE-2023-48991 PoCSQL Injection in mintplex-labs/anything-llm
- CVE-2023-491126 PoCsKEVGlibc: buffer overflow in ld.so leading to privilege escalation
- CVE-2023-49121 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2023-49221 PoCWPB Show Core <= 2.2 - Unauthenticated Local File Inclusion
- CVE-2023-49251 PoCEasy Forms for Mailchimp <= 6.8.10 - Admin+ Stored Cross-Site Scripting
- CVE-2023-49281 PoCSQL Injection in instantsoft/icms2
- CVE-2023-49301 PoCFront End PM < 11.4.3 - Sensitive Data Exposure via Directory Listing
- CVE-2023-49331 PoCWP Job Openings < 3.4.3 - Sensitive Data Exposure via Directory Listing
- CVE-2023-49501 PoCFunnelforms Free < 3.4 Unauthenticated Stored Cross-Site Scripting
- CVE-2023-49651 PoCphpipam Header redirect
- CVE-2023-496619 PoCsKEVUnauthenticated sensitive information disclosure
- CVE-2023-49691 PoCGPU kernel implementations susceptible to memory leak
- CVE-2023-49701 PoCPubyDoc <= 2.0.6 - Admin+ Stored XSS
- CVE-2023-49711 PoCWeaver Xtreme Theme Support < 6.3.1 - Admin+ PHP Object Injection
- CVE-2023-49732 PoCsAcademy LMS GET Parameter filter cross site scripting
- CVE-2023-49741 PoCAcademy LMS GET Parameter filter sql injection
- CVE-2023-49771 PoCCode Injection in librenms/librenms
- CVE-2023-49781 PoCCross-site Scripting (XSS) - DOM in librenms/librenms
- CVE-2023-49791 PoCCross-site Scripting (XSS) - Reflected in librenms/librenms
- CVE-2023-49801 PoCCross-site Scripting (XSS) - Generic in librenms/librenms
- CVE-2023-49811 PoCCross-site Scripting (XSS) - DOM in librenms/librenms
- CVE-2023-49821 PoCCross-site Scripting (XSS) - Stored in librenms/librenms
- CVE-2023-49841 PoCdidi KnowSearch 1 credentials storage
- CVE-2023-49851 PoCSupcon InPlant SCADA Project.xml improper authentication
- CVE-2023-49861 PoCSupcon InPlant SCADA Project.xml unknown vulnerability
- CVE-2023-49871 PoCinfinitietech taskhub GET Parameter get_tasks_list sql injection