CVE-2023-52000 to CVE-2023-52999
35 CVEs with public proof-of-concept exploits.
- CVE-2023-520381 PoCAn issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.
- CVE-2023-520391 PoCAn issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.
- CVE-2023-520401 PoCAn issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.
- CVE-2023-520411 PoCAn issue discovered in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary code via the sub_410118 function of the…
- CVE-2023-520421 PoCAn issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the…
- CVE-2023-520591 PoCA cross-site scripting (XSS) vulnerability in Gestsup v3.2.46 allows attackers to execute arbitrary web scripts or HTML via a crafted…
- CVE-2023-520601 PoCA Cross-Site Request Forgery (CSRF) in Gestsup v3.2.46 allows attackers to arbitrarily edit user profile information via a crafted request.
- CVE-2023-520641 PoCWuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the $keywords parameter at /core/admin/copyfrom.php.
- CVE-2023-520721 PoCFlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/site/userconfig_updagte.
- CVE-2023-520731 PoCFlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /system/site/config_footer_updagte.
- CVE-2023-520741 PoCFlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component system/site/webconfig_updagte.
- CVE-2023-520763 PoCsRemote Code Execution Vulnerability in Atril's EPUB ebook parsing
- CVE-2023-520851 PoCWinter CMS Local File Inclusion through Server Side Template Injection
- CVE-2023-521372 PoCsGitHub Action tj-actions/verify-changed-files is vulnerable to command injection in output filenames
- CVE-2023-521381 PoCPath traversal via crafted cpio archives in Engrampa archivers
- CVE-2023-521531 PoCA SQL Injection vulnerability in /pmb/opac_css/includes/sessions.inc.php in PMB 7.4.7 and earlier allows remote unauthenticated attackers…
- CVE-2023-521541 PoCFile Upload vulnerability in pmb/camera_upload.php in PMB 7.4.7 and earlier allows attackers to run arbitrary code via upload of crafted…
- CVE-2023-521551 PoCA SQL Injection vulnerability in /admin/sauvegarde/run.php in PMB 7.4.7 and earlier allows remote authenticated attackers to execute…
- CVE-2023-521631 PoCKEVDigiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are…
- CVE-2023-522351 PoCSpaceX Starlink Wi-Fi router GEN 2 before 2023.53.0 and Starlink Dish before 07dd2798-ff15-4722-a9ee-de28928aed34 allow CSRF (e.g., for a…
- CVE-2023-522513 PoCsAn issue discovered in provectus kafka-ui 0.4.0 through 0.7.1 allows remote attackers to execute arbitrary code via the q parameter of…
- CVE-2023-522521 PoCUnified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the…
- CVE-2023-522571 PoCLogoBee 0.2 allows updates.php?id= XSS.
- CVE-2023-522681 PoCThe End-User Portal module before 1.0.65 for FreeScout sometimes allows an attacker to authenticate as an arbitrary user because a session…
- CVE-2023-522691 PoCMDaemon SecurityGateway through 9.0.3 allows XSS via a crafted Message Content Filtering rule. This might allow domain administrators to…
- CVE-2023-522711 PoCThe wsftprm.sys kernel driver 2.0.0.0 in Topaz Antifraud allows low-privileged attackers to kill any (Protected Process Light) process via…
- CVE-2023-522751 PoCGallery3d on Tecno Camon X CA7 devices allows attackers to view hidden images by navigating to…
- CVE-2023-522851 PoCExamSys 9150244 allows SQL Injection via the /Support/action/Pages.php s_score2 parameter.
- CVE-2023-523391 PoCIn libebml before 1.4.5, an integer overflow in MemIOCallback.cpp can occur when reading or writing. It may result in buffer overflows.
- CVE-2023-523551 PoCLibtiff: tiffrasterscanlinesize64 produce too-big size and could cause oom
- CVE-2023-524401 PoCksmbd: fix slub overflow in ksmbd_decode_ntlmssp_auth_blob()
- CVE-2023-525551 PoCIn mongo-express 1.0.2, /admin allows CSRF, as demonstrated by deletion of a Collection.
- CVE-2023-526541 PoCio_uring/af_unix: disable sending io_uring over sockets
- CVE-2023-529272 PoCsnetfilter: allow exp not to be removed in nf_ct_find_expectation
- CVE-2023-529721 PoCHuawei PCs have a vulnerability that allows low-privilege users to bypass SDDL permission checks . Successful exploitation this…