CVE-2023-5000 to CVE-2023-5999
369 CVEs with public proof-of-concept exploits.
- CVE-2023-50021 PoCPgadmin4: remote code execution by an authenticated user
- CVE-2023-50032 PoCsActive Directory Integration < 4.1.10 - Unauthenticated Log Disclosure
- CVE-2023-50051 PoCAutocomplete Location field Contact Form 7 < 3.0 - Admin+ Store Cross-Site Scripting
- CVE-2023-50061 PoCWP Discord Invite < 2.5.1 - Arbitrary Settings Update via CSRF
- CVE-2023-50091 PoCIncorrect Authorization in GitLab
- CVE-2023-50131 PoCPluck CMS Installation install.php cross site scripting
- CVE-2023-50141 PoCSakshi2610 Food Ordering Website categoryfood.php sql injection
- CVE-2023-50151 PoCUCMS cross site scripting
- CVE-2023-50161 PoCspider-flow API DataSourceController.java DriverManager.getConnection deserialization
- CVE-2023-50191 PoCTongda OA delete.php sql injection
- CVE-2023-50201 PoC07FLY CRM Administrator Login Page sql injection
- CVE-2023-50231 PoCTongda OA delete.php sql injection
- CVE-2023-50242 PoCsPlanno Comment cross site scripting
- CVE-2023-50251 PoCKOHA MARC search.pl cross site scripting
- CVE-2023-50261 PoCTongda OA cross site scripting
- CVE-2023-50271 PoCSourceCodester Simple Membership System club_validator.php sql injection
- CVE-2023-50281 PoCChina Unicom TEWA-800G debug log file
- CVE-2023-50291 PoCmccms 1 sql injection
- CVE-2023-50301 PoCTongda OA delete.php sql injection
- CVE-2023-50311 PoCOpenRapid RapidCMS article-add.php sql injection
- CVE-2023-50321 PoCOpenRapid RapidCMS article-edit-run.php sql injection
- CVE-2023-50331 PoCOpenRapid RapidCMS cate-edit-run.php sql injection
- CVE-2023-50341 PoCSourceCodester My Food Recipe Image Upload index.php unrestricted upload
- CVE-2023-50361 PoCCross-Site Request Forgery (CSRF) in usememos/memos
- CVE-2023-50411 PoCTrack The Click < 0.3.12 - Author+ Time-Based Blind SQL Injection
- CVE-2023-50431 PoCIngress nginx annotation injection causes arbitrary command execution
- CVE-2023-50444 PoCsCode injection via nginx.ingress.kubernetes.io/permanent-redirect annotation
- CVE-2023-50571 PoCActivityPub for WordPress < 1.0.0 - Contributor+ Stored XSS
- CVE-2023-50601 PoCCross-site Scripting (XSS) - DOM in librenms/librenms
- CVE-2023-50611 PoCMissing Authorization in GitLab
- CVE-2023-50701 PoCSocial Media Share Buttons & Social Sharing Icons <= 2.8.5 - Information Exposure
- CVE-2023-50743 PoCsAuthentication Bypass in D-Link D-View 8
- CVE-2023-50821 PoCHistory Log by click5 < 1.0.13 - Admin+ Time-Based Blind SQL Injection
- CVE-2023-50841 PoCCross-site Scripting (XSS) - Reflected in hestiacp/hestiacp
- CVE-2023-50871 PoCPageLayer < 1.7.8 - Author+ Stored XSS
- CVE-2023-50893 PoCsDefender Security < 4.1.0 - Protection Bypass (Hidden Login Page)
- CVE-2023-50981 PoCCampaign Monitor Forms < 2.5.6 - Subscriber+ Arbitrary Options Update
- CVE-2023-51041 PoCImproper Input Validation in nocodb/nocodb
- CVE-2023-51051 PoCFrontend File Manager < 22.6 - Editor+ Arbitrary File Download
- CVE-2023-51081 PoCEasy Newsletter Signups <= 1.0.4 - Admin+ SQLi
- CVE-2023-51191 PoCForminator and Forminator Pro < 1.27.0 - Admin+ Stored Cross-Site Scripting
- CVE-2023-51241 PoCPageLayer < 1.8.0 - Author+ Stored XSS
- CVE-2023-51331 PoCUser Activity Log Pro < 2.3.4 - IP Spoofing
- CVE-2023-51371 PoCSimply Excerpts <= 1.4 - Admin+ Stored XSS
- CVE-2023-51392 PoCsPotential buffer overflow vulnerability in the Zephyr STM32 Crypto driver
- CVE-2023-51401 PoCBonus for Woo < 5.8.3 - Reflected Cross-Site Scripting
- CVE-2023-51411 PoCBSK Contact Form 7 Blacklist <= 1.0.1 - Reflected Cross-Site Scripting
- CVE-2023-51431 PoCD-Link DAR-7000 webmailattach.php Privilege Escalation
- CVE-2023-51441 PoCD-Link DAR-7000/DAR-8000 updateos.php unrestricted upload
- CVE-2023-51451 PoCD-Link DAR-7000 licence.php unrestricted upload
- CVE-2023-51461 PoCD-Link DAR-7000/DAR-8000 updatelib.php unrestricted upload
- CVE-2023-51471 PoCD-Link DAR-7000 updateos.php unrestricted upload
- CVE-2023-51481 PoCD-Link DAR-7000/DAR-8000 uploadfile.php unrestricted upload
- CVE-2023-51491 PoCD-Link DAR-7000 userattestation.php unrestricted upload
- CVE-2023-51501 PoCD-Link DAR-7000/DAR-8000 web.php unrestricted upload
- CVE-2023-51511 PoCD-Link DAR-8000 autheditpwd.php sql injection
- CVE-2023-51521 PoCD-Link DAR-7000/DAR-8000 importexport.php sql injection
- CVE-2023-51531 PoCD-Link DAR-8000 querysql.php sql injection
- CVE-2023-51541 PoCD-Link DAR-8000 changelogo.php unrestricted upload
- CVE-2023-51671 PoCUser Activity Log Pro < 2.3.4 - Unauthenticated Stored Cross-Site Scripting via User Agent
- CVE-2023-51771 PoCVrm 360 3D Model Viewer <= 1.2.1 - Full Path Disclosure
- CVE-2023-51781 PoCKernel: use after free in nvmet_tcp_free_crypto in nvme
- CVE-2023-51811 PoCWP Discord Invite < 2.5.2 - Admin+ Stored Cross Site Scripting
- CVE-2023-51842 PoCsPotential signed to unsigned conversion errors and buffer overflow vulnerabilities in the Zephyr IPM driver
- CVE-2023-51921 PoCExcessive Data Query Operations in a Large Data Table in pimcore/demo
- CVE-2023-51981 PoCIncorrect Authorization in GitLab
- CVE-2023-52032 PoCsWP Sessions Time Monitoring Full Automatic < 1.0.9 - Unauthenticated SQL injection
- CVE-2023-52043 PoCsAI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via qc_wpbo_search_response
- CVE-2023-52071 PoCExecution with Unnecessary Privileges in GitLab
- CVE-2023-52091 PoCBookly < 22.5 - Admin+ Stored XSS
- CVE-2023-52101 PoCAMP+ Plus <= 3.0 - Reflected Cross Site Scripting
- CVE-2023-52111 PoCFattura24 < 6.2.8 - Reflected Cross-Site Scripting
- CVE-2023-52175 PoCsKEVHeap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to…
- CVE-2023-52211 PoCForU CMS index.php code injection
- CVE-2023-52223 PoCsViessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password
- CVE-2023-52231 PoCHimitZH HOJ Topic sandbox
- CVE-2023-52261 PoCImproper Control of Generation of Code ('Code Injection') in GitLab
- CVE-2023-52281 PoCUser Registration < 3.0.4.2 - Admin+ Stored XSS
- CVE-2023-52291 PoCE2Pdf < 1.20.20 - Admin+ Stored Cross-Site Scriping
- CVE-2023-52351 PoCOvic Responsive WPBakery < 1.2.9 - Subscriber+ Option Update
- CVE-2023-52372 PoCsMemberlite Shortcodes < 1.3.9 - Contributor+ Stored XSS via Shortcode
- CVE-2023-52381 PoCEventPrime < 3.2.0 - Reflected HTML Injection on keyword parameter
- CVE-2023-52391 PoCSecurity & Malware scan by CleanTalk < 2.121 - IP Spoofing
- CVE-2023-52431 PoCLogin screen manager <= 3.5.2 - Admin+ Stored XSS
- CVE-2023-52441 PoCCross-site Scripting (XSS) - Reflected in microweber/microweber
- CVE-2023-52451 PoCUsing MLeap for loading a saved model (zip archive) can lead to path traversal/arbitrary file creation and possibly remote code execution.
- CVE-2023-52571 PoCWhiteHSBG JNDIExploit HTTPServer.java handleFileRequest path traversal
- CVE-2023-52581 PoCOpenRapid RapidCMS addgood.php sql injection
- CVE-2023-52591 PoCForU CMS cms_admin.php denial of service
- CVE-2023-52601 PoCSourceCodester Simple Membership System group_validator.php sql injection
- CVE-2023-52611 PoCTongda OA 2017 delete.php sql injection
- CVE-2023-52621 PoCOpenRapid RapidCMS uploadicon.php isImg unrestricted upload
- CVE-2023-52631 PoCZZZCMS Database Backup File save.php restore permission
- CVE-2023-52641 PoChuakecms cms_content.php sql injection
- CVE-2023-52651 PoCTongda OA 2017 delete.php sql injection
- CVE-2023-52661 PoCDedeBIZ tags_main.php sql injection
- CVE-2023-52671 PoCTongda OA 2017 delete.php sql injection
- CVE-2023-52681 PoCDedeBIZ makehtml_taglist_action.php sql injection
- CVE-2023-52691 PoCSourceCodester Best Courier Management System GET Parameter parcel_list.php sql injection
- CVE-2023-52701 PoCSourceCodester Best Courier Management System view_parcel.php sql injection
- CVE-2023-52711 PoCSourceCodester Best Courier Management System edit_parcel.php sql injection
- CVE-2023-52721 PoCSourceCodester Best Courier Management System GET Parameter edit_parcel.php sql injection
- CVE-2023-52731 PoCSourceCodester Best Courier Management System manage_parcel_status.php cross site scripting
- CVE-2023-52771 PoCSourceCodester Engineers Online Portal student_avatar.php unrestricted upload
- CVE-2023-52781 PoCSourceCodester Engineers Online Portal login.php sql injection
- CVE-2023-52791 PoCSourceCodester Engineers Online Portal my_classmates.php sql injection
- CVE-2023-52801 PoCSourceCodester Engineers Online Portal my_students.php sql injection
- CVE-2023-52811 PoCSourceCodester Engineers Online Portal remove_inbox_message.php sql injection
- CVE-2023-52821 PoCSourceCodester Engineers Online Portal seed_message_student.php sql injection
- CVE-2023-52831 PoCSourceCodester Engineers Online Portal teacher_signup.php sql injection
- CVE-2023-52841 PoCSourceCodester Engineers Online Portal upload_save_student.php unrestricted upload
- CVE-2023-52851 PoCTongda OA 2017 delete.php sql injection
- CVE-2023-52861 PoCSourceCodester Expense Tracker App Category add_category.php cross site scripting
- CVE-2023-52871 PoCBEECMS cross site scripting
- CVE-2023-52891 PoCAllocation of Resources Without Limits or Throttling in ikus060/rdiffweb
- CVE-2023-52931 PoCECshop leancloud.php sql injection
- CVE-2023-52941 PoCECshop order.php sql injection
- CVE-2023-52961 PoCXinhu RockOA Password password recovery
- CVE-2023-52971 PoCXinhu RockOA start backup
- CVE-2023-52981 PoCTongda OA 2017 delete.php sql injection
- CVE-2023-53001 PoCTTSPlanning sql injection
- CVE-2023-53011 PoCDedeCMS album_add.php AddMyAddon os command injection
- CVE-2023-53022 PoCsSourceCodester Best Courier Management System Manage Account Page cross site scripting
- CVE-2023-53072 PoCsPhotos and Files Contest Gallery – Contact Form < 21.2.8.1 - Unauthenticated Stored XSS via HTTP Headers
- CVE-2023-53111 PoCWP EXtra <= 6.2 - Missing Authorization to .htaccess File Modification
- CVE-2023-53131 PoCphpkobo Ajax Poll Script ajax-poll.php improper enforcement of a single, unique action
- CVE-2023-53221 PoCD-Link DAR-7000 edit_manageadmin.php sql injection
- CVE-2023-53241 PoCeeroOS Ethernet Interface denial of service
- CVE-2023-53251 PoCWoocommerce Vietnam Checkout < 2.0.6 - Unauthenticated Stored XSS
- CVE-2023-53261 PoCSATO CL4NX-J Plus WebConfig improper authentication
- CVE-2023-53271 PoCSATO CL4NX-J Plus path traversal
- CVE-2023-53281 PoCSATO CL4NX-J Plus Cookie improper authentication
- CVE-2023-53291 PoCField Logic DataCube4 Web API improper authentication
- CVE-2023-53401 PoCFive Star Restaurant Menu and Food Ordering < 2.4.11 - Unauthenticated PHP Object Injection
- CVE-2023-53431 PoCPopup Box < 3.7.9 - Admin+ Stored XSS
- CVE-2023-53441 PoCHeap-based Buffer Overflow in vim/vim
- CVE-2023-53453 PoCsUse-after-free in Linux kernel's fs/smb/client component
- CVE-2023-53473 PoCsUnauthenticated Firmware Upgrade
- CVE-2023-53481 PoCProduct Catalog Enquiry for WooCommerce < 5.0.3 - Unauthenticated Stored XSS via Arbitrary Setting Update
- CVE-2023-53502 PoCsSQL Injection in salesagility/suitecrm
- CVE-2023-53511 PoCCross-site Scripting (XSS) - Stored in salesagility/suitecrm
- CVE-2023-53521 PoCAwesome Support < 6.1.5 - Insufficient permission check in wpas_edit_reply
- CVE-2023-53531 PoCImproper Access Control in salesagility/suitecrm
- CVE-2023-53541 PoCAwesome Support < 6.1.5 - Reflected Cross-Site Scripting
- CVE-2023-53551 PoCAwesome Support < 6.1.5 - Submitter+ Arbitrary File Deletion
- CVE-2023-53561 PoCIncorrect Authorization in GitLab
- CVE-2023-53591 PoCW3 Total Cache <= 2.7.5 - Sensitive Credentials Stored in Plaintext
- CVE-2023-536013 PoCsRoyal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
- CVE-2023-53731 PoCSourceCodester Online Computer and Laptop Store Master.php register sql injection
- CVE-2023-53741 PoCSourceCodester Online Computer and Laptop Store products.php sql injection
- CVE-2023-53752 PoCsOpen Redirect in mosparo/mosparo
- CVE-2023-53763 PoCsTFTP Without Authentication
- CVE-2023-53771 PoCOut-of-bounds Read in gpac/gpac
- CVE-2023-54121 PoCImage horizontal reel scroll slideshow <= 13.2 - Authenticated (Subscriber+) SQL Injection via Shortcode
- CVE-2023-54271 PoCMali GPU Kernel Driver allows improper GPU processing operations
- CVE-2023-54411 PoCNULL Pointer Dereference in vim/vim
- CVE-2023-54481 PoCWP Register Profile With Shortcode <= 3.5.9 - Cross-Site Request Forgery to User Password Reset
- CVE-2023-54521 PoCCross-site Scripting (XSS) - Stored in snipe/snipe-it
- CVE-2023-54541 PoCTemplately < 2.2.6 - Arbitrary post trashing via Missing Authorization
- CVE-2023-54581 PoCCITS Support svg, webp Media and TTF,OTF File Upload < 3.0 - Author+ Stored XSS via SVG
- CVE-2023-54591 PoCDelta Electronics DVP32ES2 PLC Password Transmission denial of service
- CVE-2023-54601 PoCDelta Electronics WPLSoft Modbus Data Packet heap-based overflow
- CVE-2023-54611 PoCDelta Electronics WPLSoft Modbus cleartext transmission
- CVE-2023-54621 PoCXINJE XD5E-30R-E Modbus denial of service
- CVE-2023-54631 PoCXINJE XDPPro cfgmgr32.dll uncontrolled search path
- CVE-2023-54711 PoCcodeprojects Farmacia index.php sql injection
- CVE-2023-54881 PoCByzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform updatelib.php unrestricted upload
- CVE-2023-54891 PoCByzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform uploadfile.php unrestricted upload
- CVE-2023-54901 PoCByzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform userattestation.php unrestricted upload
- CVE-2023-54911 PoCByzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform updatelib.php unrestricted upload
- CVE-2023-54921 PoCByzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform licence.php unrestricted upload
- CVE-2023-54931 PoCByzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform web.php unrestricted upload
- CVE-2023-54941 PoCByzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform download.php os command injection
- CVE-2023-54951 PoCQDocs Smart School HTTP POST Request sql injection
- CVE-2023-54961 PoCTranslator PoqDev Add-On Select Text cross site scripting
- CVE-2023-54971 PoCTongda OA 2017 delete.php sql injection
- CVE-2023-54981 PoCCross-Site Request Forgery (CSRF) in chiefonboarding/chiefonboarding
- CVE-2023-55091 PoCmyStickymenu < 2.6.5 - Subscriber+ Arbitrary Form Leads Deletion
- CVE-2023-55111 PoCCross-Site Request Forgery (CSRF) in snipe/snipe-it
- CVE-2023-55121 PoCImproper Control of Generation of Code ('Code Injection') in GitLab
- CVE-2023-55191 PoCEventPrime < 3.2.0 - Booking Creation via CSRF
- CVE-2023-55201 PoCOut-of-bounds Read in gpac/gpac
- CVE-2023-55212 PoCsIncorrect Authorization in tiann/kernelsu
- CVE-2023-55251 PoCLimit Login Attempts Reloaded < 2.25.26 - Admin+ Missing Authorization to Toggle Plugin Auto-Update
- CVE-2023-55291 PoCAdvanced Page Visit Counter <= 8.0.6 - Admin+ Stored XSS
- CVE-2023-55301 PoCNinja Forms < 3.6.34 - Admin+ Stored XSS
- CVE-2023-55351 PoCUse After Free in vim/vim
- CVE-2023-55381 PoCMpOperationLogs <= 1.0.1 - Unauthenticated Stored Cross-Site Scripting
- CVE-2023-55461 PoCMoodle: stored xss in quiz grading report via user id number
- CVE-2023-55551 PoCCross-site Scripting (XSS) - Generic in frappe/lms
- CVE-2023-55562 PoCsCross-site Scripting (XSS) - Reflected in structurizr/onpremises
- CVE-2023-55582 PoCsLearnPress < 4.2.5.5 - Reflected Cross-Site Scripting
- CVE-2023-55592 PoCs10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option Deletion
- CVE-2023-55601 PoCWP-UserOnline < 2.88.3 - Unauthenticated Stored XSS
- CVE-2023-55617 PoCsWordPress < 6.3.2 - Unauthenticated Post Author Email Disclosure
- CVE-2023-55641 PoCCross-site Scripting (XSS) - Stored in froxlor/froxlor
- CVE-2023-55711 PoCImproper Input Validation in vriteio/vrite
- CVE-2023-55721 PoCServer-Side Request Forgery (SSRF) in vriteio/vrite
- CVE-2023-55731 PoCAllocation of Resources Without Limits or Throttling in vriteio/vrite
- CVE-2023-55791 PoCyhz66 Sandbox User Data information disclosure
- CVE-2023-55801 PoCSourceCodester Library System index.php sql injection
- CVE-2023-55811 PoCSourceCodester Medicine Tracker System index.php cross site scripting
- CVE-2023-55821 PoCZZZCMS Personal Profile Page cross site scripting
- CVE-2023-55861 PoCNULL Pointer Dereference in gpac/gpac
- CVE-2023-55871 PoCSourceCodester Free Hospital Management System for Small Practices Parameter doctors.php sql injection
- CVE-2023-55891 PoCSourceCodester Judging Management System login.php sql injection
- CVE-2023-55901 PoCNULL Pointer Dereference in seleniumhq/selenium
- CVE-2023-55951 PoCDenial of Service in gpac/gpac
- CVE-2023-56001 PoCMissing Authorization in GitLab
- CVE-2023-56011 PoCWooCommerce Ninja Forms Product Add-ons < 1.7.1 - Unauthenticated Arbitrary File Upload
- CVE-2023-56041 PoCAsgaros Forum < 2.7.1 - Unauthenticated Arbitrary File Upload
- CVE-2023-56051 PoCURL Shortify < 1.7.9.1 - Admin+ Stored XSS
- CVE-2023-56091 PoCSeraphinite Accelerator < 2.20.29 - Reflected XSS
- CVE-2023-56101 PoCSeraphinite Accelerator < 2.20.29 - Authenticated Arbitrary Redirect
- CVE-2023-56111 PoCSeraphinite Accelerator < 2.20.32 - Unauthorised Settings Reset/Import
- CVE-2023-56124 PoCsMissing Authorization in GitLab
- CVE-2023-56181 PoCModern Footnotes <= 1.4.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
- CVE-2023-56201 PoCWebpushr < 4.35.0 - Unauthenticated Stored XSS
- CVE-2023-56261 PoCCross-Site Request Forgery (CSRF) in pkp/ojs
- CVE-2023-56401 PoCArticle Analytics <= 1.0 - Unauthenticated SQL injection
- CVE-2023-56411 PoCMartins Free & Easy SEO Link buildings < 1.2.30 - Reflected XSS
- CVE-2023-56421 PoCAdvantech R-SeeNet Unauthenticated Read/Write
- CVE-2023-56441 PoCWP Mail Log < 1.1.3 – Incorrect Authorization in REST API Endpoints
- CVE-2023-56451 PoCWP Mail Log < 1.1.3 – Contributor+ SQL Injection in wml_logs endpoint
- CVE-2023-56511 PoCWP Hotel Booking < 2.0.8 - Subscriber+ Arbitrary Post Deletion
- CVE-2023-56522 PoCsWP Hotel Booking < 2.0.8 - Unauthenticated SQLi
- CVE-2023-56531 PoCWassUp Real Time Analytics <= 1.9.4.5 - Unauthenticated Stored XSS
- CVE-2023-56721 PoCWP Mail Log < 1.1.3 – Contributor+ LFI in wml_logs/send_mail endpoint
- CVE-2023-56731 PoCWP Mail Log < 1.1.3 – Contributor+ Arbitrary File Upload to RCE
- CVE-2023-56741 PoCWP Mail Log < 1.1.3 – Contributor+ SQL Injection in wml_logs/send_mail endpoint
- CVE-2023-56811 PoCNetentsec NS-ASG Application Security Gateway list_addr_fwresource_ip.php sql injection
- CVE-2023-56821 PoCTongda OA delete.php sql injection
- CVE-2023-56831 PoCByzoro Smart S85F Management Platform importconf.php os command injection
- CVE-2023-56841 PoCByzoro Smart S85F Management Platform importexport.php os command injection
- CVE-2023-56861 PoCHeap-based Buffer Overflow in radareorg/radare2
- CVE-2023-56871 PoCCross-Site Request Forgery (CSRF) in mosparo/mosparo
- CVE-2023-56881 PoCCross-site Scripting (XSS) - DOM in modoboa/modoboa
- CVE-2023-56891 PoCCross-site Scripting (XSS) - DOM in modoboa/modoboa
- CVE-2023-56901 PoCCross-Site Request Forgery (CSRF) in modoboa/modoboa
- CVE-2023-56921 PoCWordPress Core <= 6.4.3 - Sensitive Information Exposure via redirect_guess_404_permalink
- CVE-2023-56931 PoCCodeAstro Internet Banking System pages_reset_pwd.php sql injection
- CVE-2023-56941 PoCCodeAstro Internet Banking System pages_system_settings.php cross site scripting
- CVE-2023-56951 PoCCodeAstro Internet Banking System pages_reset_pwd.php cross site scripting
- CVE-2023-56961 PoCCodeAstro Internet Banking System pages_transfer_money.php cross site scripting
- CVE-2023-56971 PoCCodeAstro Internet Banking System pages_withdraw_money.php cross site scripting
- CVE-2023-56981 PoCCodeAstro Internet Banking System pages_deposit_money.php cross site scripting
- CVE-2023-56991 PoCCodeAstro Internet Banking System pages_view_client.php cross site scripting
- CVE-2023-57001 PoCNetentsec NS-ASG Application Security Gateway uploadiscgwrouteconf.php sql injection
- CVE-2023-57011 PoCvnotex vnote Markdown File cross site scripting
- CVE-2023-57022 PoCsViessmann Vitogate 300 direct request
- CVE-2023-57171 PoCOut-of-bounds write in Linux kernel's Linux Kernel Performance Events (perf) component
- CVE-2023-57181 PoCThe Vue.js Devtools extension was found to leak screenshot data back to a malicious web page via the standard `postMessage()` API. By…
- CVE-2023-57371 PoCWordPress Backup & Migration < 1.4.4 - Subscriber+ Plugin Settings Update
- CVE-2023-57381 PoCWordPress Backup & Migration < 1.4.5 - Subscriber+ Stored XSS
- CVE-2023-57491 PoCEmbedPress < 3.9.2 - Reflected XSS
- CVE-2023-57501 PoCEmbedPress < 3.9.2 - Reflected XSS
- CVE-2023-57531 PoCPotential buffer overflow vulnerabilities in the Zephyr Bluetooth subsystem
- CVE-2023-57571 PoCWP Crowdfunding < 2.1.8 - Admin+ Stored XSS
- CVE-2023-57621 PoCFilr – Secure document library < 1.2.3.6 - Author+ RCE via file upload with phar ext
- CVE-2023-57721 PoCDebug Log Manager <= 2.2.0 - Cross-Site Request Forgery
- CVE-2023-57741 PoCAnimated Counters <= 1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
- CVE-2023-57791 PoCcan: out of bounds in remove_rx_filter function
- CVE-2023-57801 PoCTongda OA 2017 delete.php sql injection
- CVE-2023-57811 PoCTongda OA 2017 delete_webmail.php DELETE_STR sql injection
- CVE-2023-57821 PoCTongda OA 2017 General News delete_query.php sql injection
- CVE-2023-57831 PoCTongda OA 2017 delete.php sql injection
- CVE-2023-57841 PoCNetentsec NS-ASG Application Security Gateway uploadfirewall.php sql injection
- CVE-2023-57851 PoCNetentsec NS-ASG Application Security Gateway addaddress_interpret.php sql injection
- CVE-2023-57861 PoCGeoServer GeoWebCache rest.html direct request
- CVE-2023-57871 PoCShaanxi Chanming Education Technology Score Query System sql injection
- CVE-2023-57891 PoCDragon Path 707GR1 Ping Diagnostics cross site scripting
- CVE-2023-57901 PoCSourceCodester File Manager App add-file.php unrestricted upload
- CVE-2023-57911 PoCSourceCodester Sticky Notes App add-note.php cross site scripting
- CVE-2023-57921 PoCSourceCodester Sticky Notes App delete-note.php sql injection
- CVE-2023-57931 PoCflusity CMS Dashboard customblock.php loadCustomBlocCreateForm cross site scripting
- CVE-2023-57951 PoCCodeAstro POS System Profile Picture profil unrestricted upload
- CVE-2023-57961 PoCCodeAstro POS System Logo setting unrestricted upload
- CVE-2023-57981 PoCAssistant < 1.4.4 - Editor+ SSRF
- CVE-2023-57991 PoCWP Hotel Booking < 2.0.9 - Contributor+ Arbitrary Post Deletion
- CVE-2023-58051 PoCSourceCodester Simple Real Estate Portal System view_estate.php sql injection
- CVE-2023-58081 PoCSystem Management Unit (SMU) versions prior to 14.8.7825.01, used to manage Hitachi Vantara NAS products are susceptible to unintended…
- CVE-2023-58091 PoCPopup box < 3.8.6 - Admin+ Stored XSS in Categories
- CVE-2023-58101 PoCflusity CMS posts.php loadPostAddForm cross site scripting
- CVE-2023-58111 PoCflusity CMS posts.php loadPostAddForm cross site scripting
- CVE-2023-58121 PoCflusity CMS upload.php handleFileUpload unrestricted upload
- CVE-2023-58151 PoCNews & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Remote Code Execution via Local File Inclusion
- CVE-2023-58251 PoCLoop with Unreachable Exit Condition ('Infinite Loop') in GitLab
- CVE-2023-58261 PoCNetentsec NS-ASG Application Security Gateway list_onlineuser.php sql injection
- CVE-2023-58271 PoCShanghai CTI Navigation CTI Monitoring and Early Warning System UserEdit.aspx sql injection
- CVE-2023-58281 PoCNanning Ontall Longxing Industrial Development Zone Project Construction and Installation Management System login.aspx sql injection
- CVE-2023-58291 PoCcode-projects Admission Management System student_avatar.php unrestricted upload
- CVE-2023-58301 PoCColumbiaSoft Document Locator WebTools login improper authentication
- CVE-2023-58321 PoCImproper Input Validation in mintplex-labs/anything-llm
- CVE-2023-58371 PoCAlexanderLivanov FotosCMS2 Cookie profile.php cross site scripting
- CVE-2023-58381 PoCInsufficient Session Expiration in linkstackorg/linkstack
- CVE-2023-58391 PoCPrivilege Chaining in hestiacp/hestiacp
- CVE-2023-58401 PoCWeak Password Recovery Mechanism for Forgotten Password in linkstackorg/linkstack
- CVE-2023-58411 PoCOpenEXR Heap Overflow in Scanline Deep Data Parsing
- CVE-2023-58421 PoCCross-site Scripting (XSS) - Stored in dolibarr/dolibarr
- CVE-2023-58451 PoCSimple Social Buttons < 5.1.1 - Unauthenticated Password Protected Post Access
- CVE-2023-58611 PoCCross-site Scripting (XSS) - Stored in microweber/microweber
- CVE-2023-58621 PoCMissing Authorization in hamza417/inure
- CVE-2023-58632 PoCsCross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq
- CVE-2023-58641 PoCCross-site Scripting (XSS) - Stored in thorsten/phpmyfaq
- CVE-2023-58651 PoCInsufficient Session Expiration in thorsten/phpmyfaq
- CVE-2023-58661 PoCSensitive Cookie in HTTPS Session Without 'Secure' Attribute in thorsten/phpmyfaq
- CVE-2023-58731 PoCCross-site Scripting (XSS) - Stored in pimcore/pimcore
- CVE-2023-58741 PoCPopup box < 3.8.6 - Admin+ Stored XSS in Popup Settings
- CVE-2023-58771 PoCaffiliate-toolkit < 3.4.3 - Unauthenticated SSRF
- CVE-2023-58821 PoCWP All Export (Free < 1.4.1, Pro < 1.8.6) - Remote Code Execution via CSRF
- CVE-2023-58841 PoCWord Balloon < 4.20.3 - Avatar Removal via CSRF
- CVE-2023-58861 PoCWP All Export (Free < 1.4.1, Pro < 1.8.6) - Author+ PHAR Deserialization via CSRF
- CVE-2023-58891 PoCInsufficient Session Expiration in pkp/pkp-lib
- CVE-2023-58901 PoCCross-site Scripting (XSS) - Stored in pkp/pkp-lib
- CVE-2023-58911 PoCCross-site Scripting (XSS) - Reflected in pkp/pkp-lib
- CVE-2023-58921 PoCCross-site Scripting (XSS) - Stored in pkp/pkp-lib
- CVE-2023-58931 PoCCross-Site Request Forgery (CSRF) in pkp/pkp-lib
- CVE-2023-58941 PoCCross-site Scripting (XSS) - Stored in pkp/ojs
- CVE-2023-58951 PoCCross-site Scripting (XSS) - DOM in pkp/pkp-lib
- CVE-2023-58981 PoCCross-Site Request Forgery (CSRF) in pkp/pkp-lib
- CVE-2023-58991 PoCCross-Site Request Forgery (CSRF) in pkp/pkp-lib
- CVE-2023-59001 PoCCross-Site Request Forgery in pkp/pkp-lib
- CVE-2023-59011 PoCCross-site Scripting in pkp/pkp-lib
- CVE-2023-59051 PoCDeMomentSomTres WordPress Export Posts With Images <= 20220825 - Subscriber+ unauthorized data export
- CVE-2023-59061 PoCJob Manager & Career < 1.4.4 - Directory listing to Sensitive Data Exposure
- CVE-2023-59071 PoCFile Manager < 6.3 - Admin+ Arbitrary OS File/Folder Access + Path Traversal
- CVE-2023-59101 PoCPopojiCMS Web Config install.php cross site scripting
- CVE-2023-59111 PoCWP Custom Cursors <= 3.2 - Admin+ Stored XSS
- CVE-2023-59141 PoCCross-site scripting (XSS)
- CVE-2023-59161 PoCLissy93 Dashy Configuration save access control
- CVE-2023-59191 PoCSourceCodester Company Website CMS Create Blog Page createblog unrestricted upload
- CVE-2023-59221 PoCRoyal Elementor Addons and Templates < 1.3.81 - Unauthenticated Arbitrary Post Read
- CVE-2023-59231 PoCCampcodes Simple Student Information System index.php sql injection
- CVE-2023-59241 PoCCampcodes Simple Student Information System view_course.php sql injection
- CVE-2023-59251 PoCCampcodes Simple Student Information System Master.php sql injection
- CVE-2023-59261 PoCCampcodes Simple Student Information System update_status.php sql injection
- CVE-2023-59271 PoCCampcodes Simple Student Information System manage_course.php sql injection
- CVE-2023-59281 PoCCampcodes Simple Student Information System manage_department.php sql injection
- CVE-2023-59291 PoCCampcodes Simple Student Information System manage_academic.php sql injection
- CVE-2023-59301 PoCCampcodes Simple Student Information System manage_academic.php cross site scripting
- CVE-2023-59311 PoCrtMedia for WordPress, BuddyPress and bbPress < 4.6.16 - Subscriber+ RCE
- CVE-2023-59321 PoCTravelpayouts < 1.1.14 - Reflected XSS
- CVE-2023-59331 PoCImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLab
- CVE-2023-59341 PoCTravelpayouts < 1.1.13 - Settings Update via CSRF
- CVE-2023-59391 PoCrtMedia for WordPress, BuddyPress and bbPress < 4.6.16 - Admin+ RCE
- CVE-2023-59401 PoCWP Not Login Hide <= 1.0 - Admin+ Stored XSS
- CVE-2023-59421 PoCMedialist < 1.4.1 - Contributor+ Stored XSS
- CVE-2023-59431 PoCWp-Adv-Quiz < 1.0.3 - Admin+ Stored XSS
- CVE-2023-59481 PoCImproper Authorization in teamamaze/amazefileutilities
- CVE-2023-59491 PoCSmartCrawl WordPress SEO checker < 3.8.3 - Unauthenticated Password Protected Post Disclosure
- CVE-2023-59511 PoCWelcart e-Commerce < 2.9.5 - Reflected XSS
- CVE-2023-59521 PoCWelcart e-Commerce < 2.9.5 - Unauthenticated PHP Object Injection
- CVE-2023-59531 PoCWelcart e-Commerce < 2.9.5 - Subscriber+ Arbitrary File Upload
- CVE-2023-59551 PoCContact Form Email < 1.3.44 - Editor+ Stored Cross-Site Scripting
- CVE-2023-59561 PoCWp-Adv-Quiz <= 1.0.2 - Admin+ Stored XSS in Quiz Overview
- CVE-2023-59571 PoCNi Purchase Order(PO) For WooCommerce <= 1.2.1 - Admin+ File Upload to Remote Code Execution
- CVE-2023-59581 PoCPOST SMTP Mailer < 2.7.1 - Unauthenticated Cross-site Scripting
- CVE-2023-59591 PoCByzoro Smart S85F Management Platform login.php password recovery
- CVE-2023-59611 PoCioLogik E1200 Series: Cross-Site Request Forgery (CSRF) Vulnerability
- CVE-2023-59651 PoCUnrestricted Upload of File with Dangerous Type in EspoCRM
- CVE-2023-59661 PoCUnrestricted Upload of File with Dangerous Type in EspoCRM
- CVE-2023-59711 PoCSave as PDF < 3.2.0 - Admin+ Stored XSS
- CVE-2023-59742 PoCsWPB Show Core <= 2.2 - Unauthenticated Server Side Request Forgery
- CVE-2023-59791 PoCeCommerce Product Catalog Plugin for WordPress < 3.3.26 - Products Deletion via CSRF
- CVE-2023-59801 PoCBSK Forms Blacklist < 3.7 - Admin+ Stored Cross-Site Scripting
- CVE-2023-59901 PoCFunnelforms Free < 3.4.2 - Form Deletion/Duplication via CSRF
- CVE-2023-59912 PoCsHotel Booking Lite < 4.8.5 - Unauthenticated Arbitrary File Download & Deletion
- CVE-2023-59951 PoCIncorrect Authorization in GitLab
- CVE-2023-59981 PoCOut-of-bounds Read in gpac/gpac