CVE-2023-51000 to CVE-2023-51999
98 CVEs with public proof-of-concept exploits.
- CVE-2023-510061 PoCAn issue in the openFile method of Chinese Perpetual Calendar v9.0.0 allows attackers to read any file via unspecified vectors.
- CVE-2023-510101 PoCAn issue in the export component AdSdkH5Activity of com.sdjictec.qdmetro v4.2.2 allows attackers to open a crafted URL without any…
- CVE-2023-510591 PoCAn issue in MOKO TECHNOLOGY LTD MOKOSmart MKGW1 BLE Gateway v.1.1.1 and before allows a remote attacker to escalate privileges via the…
- CVE-2023-510621 PoCAn unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0 allows attackers…
- CVE-2023-510631 PoCQStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based Reflected Cross Site Scripting (XSS)…
- CVE-2023-510641 PoCQStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based reflected XSS vulnerability within the…
- CVE-2023-510651 PoCIncorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to obtain system…
- CVE-2023-510661 PoCAn authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to…
- CVE-2023-510671 PoCAn unauthenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows…
- CVE-2023-510681 PoCAn authenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows…
- CVE-2023-510701 PoCAn access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily…
- CVE-2023-510711 PoCAn access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily…
- CVE-2023-510731 PoCAn issue in Buffalo LS210D v.1.78-0.03 allows a remote attacker to execute arbitrary code via the Firmware Update Script at…
- CVE-2023-510741 PoCjson-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.
- CVE-2023-510751 PoChutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function. This vulnerability allows…
- CVE-2023-510791 PoCA long execution time can occur in the ParseTools.subCompileExpression method in MVEL 2.5.0.Final because of many Java class lookups.…
- CVE-2023-510841 PoChyavijava v6.0.07.1 was discovered to contain a stack overflow via the ResultConverter.convert2Xml method.
- CVE-2023-510901 PoCTenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formGetWeiXinConfig.
- CVE-2023-510911 PoCTenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function R7WebsSecurityHandler.
- CVE-2023-510921 PoCTenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function upgrade.
- CVE-2023-510931 PoCTenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function fromSetLocalVlanInfo.
- CVE-2023-510941 PoCTenda M3 V1.0.0.12(4856) was discovered to contain a Command Execution vulnerability via the function TendaTelnet.
- CVE-2023-510951 PoCTenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formDelWlRfPolicy.
- CVE-2023-510971 PoCTenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formSetAutoPing.
- CVE-2023-510981 PoCTenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formSetDiagnoseInfo .
- CVE-2023-510991 PoCTenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formexeCommand .
- CVE-2023-511001 PoCTenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formGetDiagnoseInfo .
- CVE-2023-511011 PoCTenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formSetUplinkInfo.
- CVE-2023-511021 PoCTenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formWifiMacFilterSet.
- CVE-2023-511231 PoCAn issue discovered in D-Link dir815 v.1.01SSb08.bin allows a remote attacker to execute arbitrary code via a crafted POST request to the…
- CVE-2023-511261 PoCCommand injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value…
- CVE-2023-511271 PoCFLIR AX8 thermal sensor cameras up to and including 1.46.16 are vulnerable to Directory Traversal due to improper access restriction. This…
- CVE-2023-511411 PoCAn issue in ZKTeko BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information via the Authentication &…
- CVE-2023-511421 PoCAn issue in ZKTeco BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information.
- CVE-2023-511461 PoCBuffer Overflow vulnerability in TRENDnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via…
- CVE-2023-511471 PoCBuffer Overflow vulnerability in TRENDnet Trendnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary…
- CVE-2023-511481 PoCAn issue in TRENDnet Trendnet AC1200 Dual Band PoE Indoor Wireless Access Point TEW-821DAP v.3.00b06 allows an attacker to execute…
- CVE-2023-511571 PoCCross Site Scripting vulnerability in ZKTeco WDMS v.5.1.3 Pro allows a remote attacker to execute arbitrary code and obtain sensitive…
- CVE-2023-512521 PoCPublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is provided, pdf…
- CVE-2023-512541 PoCCross Site Scripting vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the…
- CVE-2023-512771 PoCnbviewer-app (aka Jupyter Notebook Viewer) before 0.1.6 has the get-task-allow entitlement for release builds.
- CVE-2023-512811 PoCCross Site Scripting vulnerability in Customer Support System v.1.0 allows a remote attacker to escalate privileges via a crafted script…
- CVE-2023-5138524 PoCsIn ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is…
- CVE-2023-513871 PoCExpression Injection Vulnerability in Hertzbeat
- CVE-2023-514094 PoCsWordPress AI Engine plugin <= 1.9.98 - Unauthenticated Arbitrary File Upload vulnerability
- CVE-2023-514422 PoCsAuthentication bypass vulnerability in navidrome's subsonic endpoint
- CVE-2023-514431 PoCFreeSWITCH susceptible to Denial of Service via DTLS Hello packets during call initiation
- CVE-2023-514442 PoCsGeoServer arbitrary file upload vulnerability in REST Coverage Store API
- CVE-2023-514452 PoCsGeoServer Stored Cross-Site Scripting (XSS) vulnerability in REST Resources API
- CVE-2023-514481 PoCSQL Injection vulnerability when managing SNMP Notification Receivers
- CVE-2023-514492 PoCsMake the `/file` secure against file traversal attacks
- CVE-2023-5146720 PoCsApache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
- CVE-2023-515041 PoCWordPress Dan's Embedder for Google Calendar Plugin <= 1.2 is vulnerable to Cross Site Scripting (XSS)
- CVE-2023-515181 PoCApache James server: Privilege escalation via JMX pre-authentication deserialisation
- CVE-2023-516501 PoCUnauthorized access vulnerability on three interfaces
- CVE-2023-516612 PoCsFilesystem sandbox not enforced in wasmer-cli
- CVE-2023-516642 PoCstj-actions/changed-files command injection in output filenames
- CVE-2023-516982 PoCsAtril's CBT comic book parsing vulnerable to Remote Code Execution
- CVE-2023-517131 PoCmake_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of…
- CVE-2023-517482 PoCsScaleFusion 10.5.2 does not properly limit users to the Edge application because Ctrl-O and Ctrl-S can be used. This is fixed in 10.5.7 by…
- CVE-2023-517492 PoCsScaleFusion 10.5.2 does not properly limit users to the Edge application because a search can be made from a tooltip. NOTE: the vendor's…
- CVE-2023-517644 PoCsPostfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and…
- CVE-2023-517701 PoCApache DolphinScheduler: Arbitrary File Read Vulnerability
- CVE-2023-517711 PoCIn MicroHttpServer (aka Micro HTTP Server) through a8ab029, _ParseHeader in lib/server.c allows a one-byte recv buffer overflow via a long…
- CVE-2023-517902 PoCsCross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the lang parameter in…
- CVE-2023-518001 PoCCross Site Scripting (XSS) vulnerability in School Fees Management System v.1.0 allows a remote attacker to execute arbitrary code via a…
- CVE-2023-518011 PoCSQL Injection vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary code via a crafted…
- CVE-2023-518021 PoCCross Site Scripting (XSS) vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary code…
- CVE-2023-518061 PoCFile Upload vulnerability in Ujcms v.8.0.2 allows a local attacker to execute arbitrary code via a crafted file.
- CVE-2023-518101 PoCSQL injection vulnerability in StackIdeas EasyDiscuss v.5.0.5 and fixed in v.5.0.10 allows a remote attacker to obtain sensitive…
- CVE-2023-518131 PoCCross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute…
- CVE-2023-518202 PoCsAn issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate attackers to execute arbitrary code.
- CVE-2023-518281 PoCA SQL Injection vulnerability in /admin/convert/export.class.php in PMB 7.4.7 and earlier versions allows remote unauthenticated attackers…
- CVE-2023-519391 PoCAn issue in the cp_bbs_sig function in relic/src/cp/relic_cp_bbs.c of Relic relic-toolkit 0.6.0 allows a remote attacker to obtain…
- CVE-2023-519491 PoCVerydows v2.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /protected/controller/backend/role_controller
- CVE-2023-519512 PoCsSQL Injection vulnerability in Stock Management System 1.0 allows a remote attacker to execute arbitrary code via the id parameter in the…
- CVE-2023-519521 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.
- CVE-2023-519531 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.
- CVE-2023-519541 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv.
- CVE-2023-519551 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.
- CVE-2023-519561 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv
- CVE-2023-519571 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv.
- CVE-2023-519581 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.
- CVE-2023-519591 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv.
- CVE-2023-519601 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv.
- CVE-2023-519611 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.
- CVE-2023-519621 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo.
- CVE-2023-519631 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo.
- CVE-2023-519641 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo.
- CVE-2023-519651 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function setIptvInfo.
- CVE-2023-519661 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo.
- CVE-2023-519671 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function getIptvInfo.
- CVE-2023-519681 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function getIptvInfo.
- CVE-2023-519691 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function getIptvInfo.
- CVE-2023-519701 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.
- CVE-2023-519711 PoCTenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function getIptvInfo.
- CVE-2023-519721 PoCTenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp.
- CVE-2023-519871 PoCD-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator accounts with…