CVE-2023-53000 to CVE-2023-53999
130 CVEs with public proof-of-concept exploits.
- CVE-2023-531551 PoCgoform/formTest in EmbedThis GoAhead 2.5 allows HTML injection via the name parameter.
- CVE-2023-537341 PoCdawa-pharma-1.0 - SQL Injection via Email Parameter
- CVE-2023-537351 PoCWEBIGniter 28.7.23 Cross-Site Scripting (XSS) in User Creation Process
- CVE-2023-537391 PoCTinycontrol LAN Controller v3 LK3 1.58a Unauthenticated Configuration Backup Disclosure
- CVE-2023-537401 PoCScreen SFT DAB 1.9.3 Authentication Bypass via Admin Password Change
- CVE-2023-537411 PoCScreen SFT DAB 1.9.3 Authentication Bypass via IP Session Management
- CVE-2023-537701 PoCMiniDVBLinux 5.4 Unauthenticated Configuration Download via Backup Endpoint
- CVE-2023-537711 PoCMiniDVBLinux 5.4 Unauthenticated Root Password Change via System Setup
- CVE-2023-537721 PoCMiniDVBLinux 5.4 Arbitrary File Read Vulnerability via About Page
- CVE-2023-537731 PoCMiniDVBLinux 5.4 Unauthenticated Live Stream Disclosure via tv_action.sh
- CVE-2023-537741 PoCMiniDVBLinux 5.4 Simple VideoDiskRecorder Protocol Remote Code Execution
- CVE-2023-537751 PoCScreen SFT DAB 1.9.3 Authentication Bypass via Session Management Weakness
- CVE-2023-537761 PoCScreen SFT DAB 1.9.3 Authentication Bypass via Session Management Weakness
- CVE-2023-538681 PoCCoppermine Gallery 1.6.25 Remote Code Execution via Plugin Upload
- CVE-2023-538691 PoCWEBIGniter 28.7.23 Unrestricted File Upload Remote Code Execution
- CVE-2023-538701 PoCJorani 1.0.3 Cross-Site Scripting Vulnerability via Language Parameter
- CVE-2023-538711 PoCSoosyze 2.0.0 Unrestricted File Upload via Broken Upload Logic
- CVE-2023-538721 PoCWp2Fac 1.0 OS Command Injection via send.php Endpoint
- CVE-2023-538731 PoCSyncBreeze 15.2.24 Denial of Service via Login Endpoint Overflow
- CVE-2023-538741 PoCGOM Player 2.3.90.5360 Buffer Overflow via Equalizer Preset Name
- CVE-2023-538751 PoCGOM Player 2.3.90.5360 Remote Code Execution via Insecure IE Component
- CVE-2023-538761 PoCAcademy LMS 6.1 Arbitrary File Upload Vulnerability via Profile Settings
- CVE-2023-538771 PoCBus Reservation System 1.1 Multiple SQL Injection via pickup_id Parameter
- CVE-2023-538781 PoCMember Login Script 3.3 Client-Side Request Desynchronization Vulnerability
- CVE-2023-538791 PoCNVClient 5.0 Stack Buffer Overflow Vulnerability via User Configuration
- CVE-2023-538801 PoCLucee 5.4.2.17 Authenticated Reflected Cross-Site Scripting via Admin Interfaces
- CVE-2023-538811 PoCReyeeOS 1.204.1614 Man-in-the-Middle Remote Code Execution via CWMP
- CVE-2023-538821 PoCJLex GuestBook 1.6.4 Reflected Cross-Site Scripting via URL Parameter
- CVE-2023-538831 PoCWebedition CMS v2.9.8.8 Remote Code Execution via PHP Page Creation
- CVE-2023-538841 PoCWebedition CMS v2.9.8.8 Stored Cross-Site Scripting via SVG Upload
- CVE-2023-538851 PoCWebutler v3.2 Remote Code Execution via Arbitrary File Upload
- CVE-2023-538861 PoCXlight FTP Server 3.9.3.6 Stack Buffer Overflow Vulnerability via Execute Program
- CVE-2023-538871 PoCZomplog 3.9 Cross-Site Scripting Vulnerability via Page Creation
- CVE-2023-538881 PoCZomplog 3.9 Remote Code Execution via Authenticated File Manipulation
- CVE-2023-538891 PoCPerch CMS 3.2 Remote Code Execution via Unrestricted File Upload
- CVE-2023-538901 PoCPerch CMS 3.2 Stored Cross-Site Scripting via SVG File Upload
- CVE-2023-538911 PoCBlackcat CMS 1.4 Stored Cross-Site Scripting via Page Modification
- CVE-2023-538921 PoCBlackcat CMS 1.4 Remote Code Execution via Jquery Plugin Manager
- CVE-2023-538931 PoCAteme TITAN File 3.9 Authenticated Server-Side Request Forgery Vulnerability
- CVE-2023-538941 PoCphpfm 1.7.9 Authentication Bypass via Type Juggling Vulnerability
- CVE-2023-538951 PoCPimpMyLog 1.7.14 Improper Access Control via Account Creation Endpoint
- CVE-2023-538961 PoCD-Link DAP-1325 Hardware A1 Unauthenticated Configuration Download
- CVE-2023-538971 PoCRukovoditel 3.4.1 Multiple Stored Cross-Site Scripting via Comments
- CVE-2023-538981 PoCRukovoditel 3.4.1 Multiple Stored Cross-Site Scripting via Configuration
- CVE-2023-538991 PoCPodcastGenerator 3.2.9 Blind Server-Side Request Forgery via XML Injection
- CVE-2023-539001 PoCSpip 4.1.10 Admin Account Spoofing via Malicious SVG Upload
- CVE-2023-539011 PoCWBCE CMS 1.6.1 Cross-Site Scripting and Open Redirect Vulnerability
- CVE-2023-539021 PoCWebsiteBaker 2.13.3 Directory Traversal via Media Delete Endpoint
- CVE-2023-539031 PoCWebsiteBaker 2.13.3 Stored Cross-Site Scripting via SVG File Upload
- CVE-2023-539041 PoCXenforo 2.2.13 Authenticated Stored Cross-Site Scripting via Smilie Categories
- CVE-2023-539051 PoCProjectSend r1605 CSV Injection via User Account Export Functionality
- CVE-2023-539061 PoCProjectSend r1605 Stored Cross-Site Scripting via Custom Assets Page
- CVE-2023-539071 PoCBludit 3.13.1 Authenticated Arbitrary File Download via Backup Plugin
- CVE-2023-539081 PoCHiSecOS 04.0.01 Privilege Escalation via User Role Modification
- CVE-2023-539091 PoCWBCE CMS 1.6.1 SVG File Content Cross-Site Scripting
- CVE-2023-539101 PoCWBCE CMS 1.6.1 Stored Cross-Site Scripting via Page Content
- CVE-2023-539111 PoCTextpattern CMS 4.8.8 Authenticated Stored Cross-Site Scripting via Article Excerpt
- CVE-2023-539121 PoCUSB Flash Drives Control 4.1.0.0 Unquoted Service Path Privilege Escalation
- CVE-2023-539131 PoCRukovoditel 3.3.1 CSV Injection via User Account Export
- CVE-2023-539141 PoCUliCMS 2023.1 Authentication Bypass via Mass Assignment Vulnerability
- CVE-2023-539151 PoCZenphoto 1.6 Stored Cross-Site Scripting via Album Description
- CVE-2023-539161 PoCZenphoto 1.6 Stored Cross-Site Scripting via User Postal Code Field
- CVE-2023-539171 PoCAffiliate Me 5.0.1 SQL Injection Vulnerability via Admin Panel
- CVE-2023-539181 PoCPodcastGenerator Stored Cross-Site Scripting via Episode Title Field
- CVE-2023-539191 PoCPodcastGenerator Stored Cross-Site Scripting via Freebox Content Field
- CVE-2023-539201 PoCPodcastGenerator Stored Cross-Site Scripting via Podcast Title Field
- CVE-2023-539211 PoCSitemagicCMS 4.4.3 Remote Code Execution via Unrestricted File Upload
- CVE-2023-539221 PoCTinyWebGallery v2.5 Remote Code Execution via Unrestricted File Upload
- CVE-2023-539231 PoCUliCMS 2023.1 Privilege Escalation via Unauthenticated Admin Account Creation
- CVE-2023-539241 PoCUliCMS 2023.1-sniffing-vicuna Remote Code Execution via Avatar Upload
- CVE-2023-539251 PoCUliCMS 2023.1 Stored Cross-Site Scripting via SVG File Upload
- CVE-2023-539261 PoCPHPJabbers Simple CMS 5.0 SQL Injection via Column Parameter
- CVE-2023-539271 PoCPHPJabbers Simple CMS 5.0 Stored Cross-Site Scripting via Section Creation
- CVE-2023-539281 PoCPHPFusion 9.10.30 Stored Cross-Site Scripting via File Manager Upload
- CVE-2023-539291 PoCphpMyFAQ 3.1.12 CSV Injection via User Profile Export
- CVE-2023-539301 PoCProjectSend r1605 Insecure Direct Object Reference File Download Vulnerability
- CVE-2023-539311 PoCRevive Adserver 5.4.1 Cross-Site Scripting via Banner Advanced Settings
- CVE-2023-539321 PoCSerendipity 2.4.0 Stored Cross-Site Scripting via Admin Entry Creation
- CVE-2023-539331 PoCSerendipity 2.4.0 Authenticated Remote Code Execution via File Upload
- CVE-2023-539351 PoCWBiz Desk 1.2 SQL Injection Vulnerability via ticket.php Parameter
- CVE-2023-539361 PoCCameleon CMS 2.7.4 Authenticated Persistent Cross-Site Scripting via Post Creation
- CVE-2023-539371 PoCHubstaff 1.6.14 DLL Search Order Hijacking via wow64log Library
- CVE-2023-539381 PoCRockMongo 1.1.7 Stored Cross-Site Scripting Vulnerability via Multiple Parameters
- CVE-2023-539391 PoCTinyWebGallery v2.5 Stored Cross-Site Scripting via Folder Name Parameter
- CVE-2023-539401 PoCCodigo Markdown Editor 1.0.1 Electron Arbitrary Code Execution via Markdown File
- CVE-2023-539411 PoCEasyPHP Webserver 14.1 Remote Code Execution
- CVE-2023-539421 PoCFile Thingie 2.5.7 Authenticated Arbitrary File Upload Remote Code Execution
- CVE-2023-539431 PoCGLPI 9.5.7 Username Enumeration Vulnerability via Lost Password Endpoint
- CVE-2023-539441 PoCEasyPHP Webserver 14.1 Path Traversal via Directory Traversal Sequences
- CVE-2023-539451 PoCBrainyCP 1.0 Remote Code Execution via Authenticated Crontab Manipulation
- CVE-2023-539461 PoCArcsoft PhotoStudio 6.0.0.172 Unquoted Service Path Privilege Escalation
- CVE-2023-539471 PoCOCS Inventory NG 2.3.0.0 Unquoted Service Path Privilege Escalation
- CVE-2023-539481 PoCLilac-Reloaded for Nagios 2.0.8 Remote Code Execution via Autodiscovery
- CVE-2023-539491 PoCAspEmail 5.6.0.2 Local Privilege Escalation via Binary Permission Vulnerability
- CVE-2023-539501 PoCInnovaStudio WYSIWYG Editor 5.4 Unrestricted File Upload via Filename Manipulation
- CVE-2023-539511 PoCEver Gauzy v0.281.9 JWT Authentication Weakness via HMAC Secret
- CVE-2023-539521 PoCDotclear 2.25.3 Authenticated Remote Code Execution via File Upload
- CVE-2023-539531 PoCWebsiteBaker 2.13.3 Stored Cross-Site Scripting via Page Creation
- CVE-2023-539541 PoCActFax 10.10 Unquoted Path Services Privilege Escalation Vulnerability
- CVE-2023-539551 PoCSOUND4 IMPACT/FIRST/PULSE/Eco v2.x Authorization Bypass via Insecure Object References
- CVE-2023-539561 PoCFlatnux 2021-03.25 Authenticated File Upload Remote Code Execution
- CVE-2023-539571 PoCKimai 1.30.10 SameSite Cookie Vulnerability Session Hijacking
- CVE-2023-539581 PoCLDAP Tool Box Self Service Password 1.5.2 Account Takeover via HTTP Host Header
- CVE-2023-539591 PoCFileZilla Client 3.63.1 DLL Hijacking via Missing TextShaping.dll
- CVE-2023-539601 PoCSOUND4 IMPACT/FIRST/PULSE/Eco v2.x SQL Injection via Authentication Bypass
- CVE-2023-539611 PoCSOUND4 IMPACT/FIRST/PULSE/Eco v2.x Cross-Site Request Forgery
- CVE-2023-539621 PoCSOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Directory Traversal File Write
- CVE-2023-539631 PoCSOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Remote Command Injection
- CVE-2023-539641 PoCSOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Factory Reset Vulnerability
- CVE-2023-539651 PoCSOUND4 Server Service 4.1.102 Local Privilege Escalation via Unquoted Service Path
- CVE-2023-539661 PoCSOUND4 LinkAndShare Transmitter 1.1.2 Format String Stack Buffer Overflow
- CVE-2023-539671 PoCScreen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Admin Password Change
- CVE-2023-539681 PoCScreen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Erase Account
- CVE-2023-539691 PoCScreen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Password Change
- CVE-2023-539701 PoCScreen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Reset Board Config
- CVE-2023-539711 PoCWebTareas 2.4 Authenticated Remote Code Execution via File Upload
- CVE-2023-539721 PoCWebTareas 2.4 Unauthenticated SQL Injection via Session Cookie Parameter
- CVE-2023-539731 PoCZillya Total Security 3.0.2367.0 Local Privilege Escalation via Quarantine Module
- CVE-2023-539741 PoCD-Link DSL-124 ME_1.00 Backup Configuration File Disclosure via Unauthenticated Request
- CVE-2023-539751 PoCAtom CMS 2.0 Unauthenticated SQL Injection via Admin Index Page
- CVE-2023-539761 PoCmyBB Forums 1.8.26 Stored Cross-Site Scripting via Template Management
- CVE-2023-539771 PoCmyBB Forums 1.8.26 Stored Cross-Site Scripting via Forum Management
- CVE-2023-539781 PoCmyBB Forums 1.8.26 Stored Cross-Site Scripting via Forum Announcements
- CVE-2023-539791 PoCMyBB 1.8.32 Authenticated Remote Code Execution via Chained Vulnerabilities
- CVE-2023-539801 PoCProjectSend r1605 Remote Code Execution via File Extension Manipulation
- CVE-2023-539811 PoCPhotoShow 3.0 Remote Code Execution via Exiftran Path Injection
- CVE-2023-539821 PoCPMB 7.4.6 SQL Injection Vulnerability via Unsanitized Storage Parameter
- CVE-2023-539831 PoCAnevia Flamingo XL/XS 3.6.20 Default Credentials Authentication Bypass
- CVE-2023-539841 PoCHotKey Clipboard 2.1.0.6 - Privilege Escalation Unquoted Service Path
- CVE-2023-539852 PoCsZstore 6.5.4 - Reflected Cross-Site Scripting (XSS)