CVE-2023-6000 to CVE-2023-6999
281 CVEs with public proof-of-concept exploits.
- CVE-2023-60005 PoCsPopup Builder < 4.2.3 - Unauthenticated Stored XSS
- CVE-2023-60051 PoCEventON (Free < 2.2.7, Premium < 4.5.5) - Admin+ Stored Cross-Site Scripting
- CVE-2023-60131 PoCH2O Local File Include
- CVE-2023-60141 PoCMLflow Authentication Bypass
- CVE-2023-60151 PoCMLflow Arbitrary File Upload
- CVE-2023-60161 PoCH2O Remote Code Execution via POJO Model Import
- CVE-2023-60171 PoCH2O S3 Bucket Takeover
- CVE-2023-60181 PoCMLflow Arbitrary File Write
- CVE-2023-60195 PoCsRay Command Injection in cpu_profile Parameter
- CVE-2023-60202 PoCsRay Static File Local File Include
- CVE-2023-60211 PoCRay Log File Local File Include
- CVE-2023-60232 PoCsModelDB Local File Include
- CVE-2023-60291 PoCEazyDocs < 2.3.6 - Unauthenticated Arbitrary Posts Deletion and Document Management
- CVE-2023-60302 PoCsLogDash Activity Log < 1.1.4 - Unauthenticated SQLi
- CVE-2023-60331 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2023-60351 PoCEazyDocs < 2.3.4 - Subscriber + SQLi
- CVE-2023-60362 PoCsWeb3 – Crypto wallet Login & NFT token gating < 3.0.0 - Authentication Bypass
- CVE-2023-60371 PoCWP TripAdvisor Review Slider < 11.9 - Admin+ Stored XSS
- CVE-2023-60381 PoCLocal File Inclusion in h2oai/h2o-3
- CVE-2023-60421 PoCGetwid < 2.0.3 - Unauthenticated Arbitrary Email Sending to Admin
- CVE-2023-60461 PoCEventON < 2.2 - Admin+ Stored HTML Injection
- CVE-2023-60481 PoCEstatik Real Estate Plugin < 4.1.1 - Subscriber+ Arbitrary Option Update
- CVE-2023-60491 PoCEstatik Real Estate Plugin < 4.1.1 - Unauthenticated PHP Object Injection
- CVE-2023-60501 PoCEstatik Real Estate Plugin < 4.1.1 - Reflected XSS
- CVE-2023-60511 PoCImproper Control of Generation of Code ('Code Injection') in GitLab
- CVE-2023-60521 PoCTongda OA 2017 delete.php sql injection
- CVE-2023-60531 PoCTongda OA 2017 delete.php sql injection
- CVE-2023-60541 PoCTongda OA 2017 lock.php sql injection
- CVE-2023-60639 PoCsWP Fastest Cache < 1.2.2 - Unauthenticated SQL Injection
- CVE-2023-60641 PoCPayHere Payment Gateway < 2.2.12 - Unauthenticated Log Data Disclosure
- CVE-2023-60652 PoCsQuttera Web Malware Scanner < 3.4.2.1 - Directory Listing to Sensitive Data Exposure
- CVE-2023-60661 PoCWP Custom Widget Area <= 1.2.5 - Subscriber+ Menus Creation/Deletion/Update
- CVE-2023-60671 PoCWP User Profile Avatar <= 1.0.1 - Contributor+ Stored XSS
- CVE-2023-60771 PoCSlider - Ultimate Responsive Image Slider < 3.5.12 - Subscriber+ Arbitrary Post Access
- CVE-2023-60811 PoCChart.js for WordPress <= 2023.2 - Editor+ Stored Cross-Site Scripting in New Chart
- CVE-2023-60821 PoCChart.js for WordPress <= 2023.2 - Editor+ Stored Cross-Site Scripting
- CVE-2023-60841 PoCTongda OA 2017 delete.php sql injection
- CVE-2023-60991 PoCShenzhen Youkate Industrial Facial Love Cloud Payment System Account SystemMng.ashx privileges management
- CVE-2023-61031 PoCIntelbras RX 1500 SSID WiFi.html cross site scripting
- CVE-2023-61051 PoCManageEngine Information Disclosure in Multiple Products
- CVE-2023-61111 PoCUse-after-free in Linux kernel's netfilter: nf_tables component
- CVE-2023-61132 PoCsWP Staging (Free < 3.1.3, Pro < 5.1.3) - Unauthenticated Backup Download
- CVE-2023-61142 PoCsDuplicator < 1.5.7.1; Duplicator Pro < 4.5.14.2 - Unauthenticated Sensitive Data Exposure
- CVE-2023-61241 PoCServer-Side Request Forgery (SSRF) in salesagility/suitecrm
- CVE-2023-61251 PoCCode Injection in salesagility/suitecrm
- CVE-2023-61271 PoCUnrestricted Upload of File with Dangerous Type in salesagility/suitecrm
- CVE-2023-61391 PoCEssential Real Estate < 4.4.0 - Subscriber+ Denial of Service via Arbitrary Option Update
- CVE-2023-61401 PoCEssential Real Estate < 4.4 - Subscriber+ Arbitrary File Upload
- CVE-2023-61411 PoCEssential Real Estate < 4.4.0 - Subscriber+ Stored XSS
- CVE-2023-61522 PoCsA user changing their email after signing up and verifying it can change it without verification in profile settings.The configuration…
- CVE-2023-61551 PoCQuiz Maker < 6.4.9.5 - Unauthenticated Email Address Disclosure
- CVE-2023-61591 PoCInefficient Regular Expression Complexity in GitLab
- CVE-2023-61611 PoCWP Crowdfunding < 2.1.9 - Reflected XSS
- CVE-2023-61631 PoCWP Crowdfunding < 2.1.10 - Admin+ Stored XSS
- CVE-2023-61651 PoCRestrict Usernames Emails Characters Plugin < 3.1.4 - Admin+ Stored XSS
- CVE-2023-61661 PoCQuiz Maker < 6.4.9.5 - Reflected Cross-Site Scripting
- CVE-2023-61881 PoCGetSimpleCMS theme-edit.php code injection
- CVE-2023-61951 PoCServer-Side Request Forgery (SSRF) in GitLab
- CVE-2023-61993 PoCsBook Stack v23.10.2 - LFR via Blind SSRF
- CVE-2023-62031 PoCThe Events Calendar < 6.2.8.1 - Unauthenticated Arbitrary Password Protected Post Read
- CVE-2023-62221 PoCQuttera Web Malware Scanner < 3.4.2.1 - Admin+ Path Traversal
- CVE-2023-62413 PoCsMali GPU Kernel Driver allows improper GPU memory processing operations
- CVE-2023-62468 PoCsGlibc: heap-based buffer overflow in __vsyslog_internal()
- CVE-2023-62501 PoCBestWebSoft's Like & Share < 2.74 - Unauthenticated Password Protected Post Read
- CVE-2023-62533 PoCsSaved Uninstall Key in Digital Guardian Agent Uninstaller
- CVE-2023-62571 PoCInline Related Posts < 3.6.0 - Subscriber+ Password Protected Post Read
- CVE-2023-62651 PoCDrayTek Vigor2960 mainfunction.cgi dumpSyslog 'option' directory traversal
- CVE-2023-62661 PoCBackup Migration <= 1.3.6 - Unauthenticated Arbitrary Backup Download to Sensitive Information Exposure
- CVE-2023-62681 PoCJSON Content Importer < 1.5.4 - Reflected XSS
- CVE-2023-62691 PoCArgument injection vulnerability in Atos Unify OpenScape Session Border Controller, Atos Unify OpenScape Branch and Atos Unify OpenScape BCF
- CVE-2023-62712 PoCsBackup Migration Staging < 1.3.6 - Sensitive Data Exposure
- CVE-2023-62721 PoCTheme My Login 2FA < 1.2 - Lack of Rate Limiting
- CVE-2023-62741 PoCByzoro Smart S80 PHP File updatelib.php unrestricted upload
- CVE-2023-62753 PoCsTOTVS Fluig Platform mobileredir openApp.jsp cross site scripting
- CVE-2023-62761 PoCTongda OA 2017 delete.php sql injection
- CVE-2023-62771 PoCLibtiff: out-of-memory in tiffopen via a craft file
- CVE-2023-62781 PoCBiteship for WooCommerce < 2.2.25 - Reflected Cross-Site Scripting
- CVE-2023-62791 PoCWoostify Sites Library < 1.4.8 - Subscriber+ Arbitrary Options Update to DoS
- CVE-2023-62892 PoCsSwift Performance Lite <= 2.3.6.14 - Unauthenticated Configuration Export
- CVE-2023-62901 PoCWP SEO Press < 7.3 - Admin+ Stored XSS
- CVE-2023-62921 PoCEcwid Ecommerce Shopping Cart < 6.12.5 - Arbitrary Plugin Settings Change via CSRF
- CVE-2023-62931 PoCPrototype Pollution in robinbuschmann/sequelize-typescript
- CVE-2023-62941 PoCpopup-builder < 4.2.6 - Admin+ SSRF & File Read
- CVE-2023-62951 PoCso-widgets-bundle < 1.51.0 - Admin+ Local File Inclusion
- CVE-2023-62971 PoCPHPGurukul Nipah Virus Testing Management System Search Report Page patient-search-report.php cross site scripting
- CVE-2023-62981 PoCApryse iText PdfDocument.java main array index
- CVE-2023-62991 PoCApryse iText Reference Table PdfDocument.java memory leak
- CVE-2023-63001 PoCSourceCodester Best Courier Management System cross site scripting
- CVE-2023-63011 PoCSourceCodester Best Courier Management System GET Parameter parcel_list.php cross site scripting
- CVE-2023-63021 PoCCSZCMS File Manager Page templates permission
- CVE-2023-63031 PoCCSZCMS Site Settings Page cross site scripting
- CVE-2023-63041 PoCTecno 4G Portable WiFi TR118 Ping Tool goform_get_cmd_process os command injection
- CVE-2023-63051 PoCSourceCodester Free and Open Source Inventory Management System suppliar_data.php sql injection
- CVE-2023-63061 PoCSourceCodester Free and Open Source Inventory Management System member_data.php sql injection
- CVE-2023-63071 PoCjeecgboot JimuReport image path traversal
- CVE-2023-63081 PoCXiamen Four-Faith Video Surveillance Management System Apache Struts unrestricted upload
- CVE-2023-63091 PoCmoses-smt mosesdecoder trans_result.php os command injection
- CVE-2023-63101 PoCSourceCodester Loan Management System deleteBorrower.php delete_borrower sql injection
- CVE-2023-63111 PoCSourceCodester Loan Management System Loan Type Page delete_ltype.php delete_ltype sql injection
- CVE-2023-63121 PoCSourceCodester Loan Management System Users Page deleteUser.php delete_user sql injection
- CVE-2023-63131 PoCSourceCodester URL Shortener Long URL cross site scripting
- CVE-2023-63191 PoCCommand injection in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service
- CVE-2023-63294 PoCsControl iD iDSecure passwordCustom Authentication Bypass
- CVE-2023-63501 PoCUse after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2023-63604 PoCsThe 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from' and 'to'…
- CVE-2023-63711 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2023-63731 PoCArtPlacer Widget < 2.20.7 - Editor+ SQLi
- CVE-2023-63791 PoCCross-site Scripting in Alkacon Software OpenCms
- CVE-2023-63801 PoCOpen Redirect in Alkacon Software OpenCms
- CVE-2023-63831 PoCDebug Log Manager < 2.3.0 - Sensitive Logs Exposure
- CVE-2023-63841 PoCWP User Profile Avatar < 1.0.1 - Author+ Avatar Deletion/Update via IDOR
- CVE-2023-63851 PoCWordPress Ping Optimizer <= 2.35.1.3.0 - Log Clearing via CSRF
- CVE-2023-63861 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2023-63892 PoCsWordPress Toolbar <= 2.2.6 - Open Redirect
- CVE-2023-63901 PoCWordPress Users <= 1.4 - Settings Update via CSRF
- CVE-2023-63911 PoCCustom User CSS <= 0.2 - Settings Update via CSRF
- CVE-2023-64011 PoCNotePad++ dbghelp.exe uncontrolled search path
- CVE-2023-64021 PoCPHPGurukul Nipah Virus Testing Management System add-phlebotomist.php sql injection
- CVE-2023-64213 PoCsDownload Manager < 3.2.83 - Unauthenticated Protected File Download Password Leak
- CVE-2023-64251 PoCCross-site Scripting vulnerability in BigProf products
- CVE-2023-64381 PoCThecosy IceCMS Like improper enforcement of a single, unique action
- CVE-2023-64391 PoCZenTao PMS cross site scripting
- CVE-2023-64401 PoCSourceCodester Book Borrower System add-book.php cross site scripting
- CVE-2023-64421 PoCPHPGurukul Nipah Virus Testing Management System add-phlebotomist.php cross site scripting
- CVE-2023-64443 PoCsSeriously Simple Podcasting < 3.0.0 - Unauthenticated Administrator Email Disclosure
- CVE-2023-64471 PoCEventPrime < 3.3.6 - Unauthenticated Event Access
- CVE-2023-64481 PoCKEVUnitronics VisiLogic uses a default administrative password
- CVE-2023-64561 PoCWP Review Slider < 13.0 - Admin+ Stored XSS
- CVE-2023-64611 PoCCross-site Scripting (XSS) - Reflected in viliusle/minipaint
- CVE-2023-64621 PoCSourceCodester User Registration and Login System delete-user.php cross site scripting
- CVE-2023-64631 PoCSourceCodester User Registration and Login System add-user.php cross site scripting
- CVE-2023-64641 PoCSourceCodester User Registration and Login System add-user.php sql injection
- CVE-2023-64651 PoCPHPGurukul Nipah Virus Testing Management System registered-user-testing.php cross site scripting
- CVE-2023-64661 PoCThecosy IceCMS User Comment planet cross site scripting
- CVE-2023-64671 PoCThecosy IceCMS Comment Like improper enforcement of a single, unique action
- CVE-2023-64721 PoCPHPEMS Content Section api.cls.php cross site scripting
- CVE-2023-64731 PoCSourceCodester Online Quiz System take-quiz.php cross site scripting
- CVE-2023-64741 PoCPHPGurukul Nipah Virus Testing Management System manage-phlebotomist.php cross-site request forgery
- CVE-2023-64771 PoCIncorrect Privilege Assignment in GitLab
- CVE-2023-64851 PoCHtml5 Video Player < 2.5.19 - Subscriber+ Stored XSS
- CVE-2023-64891 PoCInefficient Regular Expression Complexity in GitLab
- CVE-2023-64991 PoClasTunes <= 3.6.1 - Settings Update via CSRF
- CVE-2023-65011 PoCSplashscreen <= 0.20 - Settings Update via CSRF
- CVE-2023-65021 PoCInefficient Regular Expression Complexity in GitLab
- CVE-2023-65031 PoCWP Plugin Lister <= 2.1.0 - Settings Update to Stored XSS via CSRF
- CVE-2023-65052 PoCsPrime Mover < 1.9.3 - Directory Listing to Sensitive Data Exposure
- CVE-2023-65281 PoCSlider Revolution < 6.6.19 - Author+ Insecure Deserialization leading to RCE
- CVE-2023-65291 PoCWP VR < 8.3.15 - Unauthenticated Plugin Downgrade leading to XSS
- CVE-2023-65302 PoCsTJ Shortcodes <= 0.1.3 - Contributor+ Stored XSS via Shortcodes
- CVE-2023-65321 PoCWP Blogs' Planetarium <= 1.0 - Settings Update via CSRF
- CVE-2023-65382 PoCsSystem Management Unit (SMU) versions prior to 14.8.7825.01, used to manage Hitachi Vantara NAS products is susceptible to unintended…
- CVE-2023-65411 PoCAllow SVG < 1.2.0 - Author+ Stored XSS via SVG
- CVE-2023-65463 PoCsKernel: gsm multiplexing race condition leads to privilege escalation
- CVE-2023-65491 PoCKEVImproper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated…
- CVE-2023-655310 PoCsBackup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
- CVE-2023-65551 PoCEmail Subscription Popup < 1.2.20 - Reflected XSS
- CVE-2023-65672 PoCsLearnPress <= 4.2.5.7 - Unauthenticated SQL Injection via order_by
- CVE-2023-65682 PoCsReflected XSS via Content-Type Header in mlflow/mlflow
- CVE-2023-65741 PoCByzoro Smart S20 HTTP POST Request updateos.php unrestricted upload
- CVE-2023-65751 PoCByzoro S210 HTTP POST Request repair.php sql injection
- CVE-2023-65761 PoCByzoro S210 HTTP POST Request uploadfile.php unrestricted upload
- CVE-2023-65771 PoCByzoro PatrolFlow 2530Pro mailsendview.php path traversal
- CVE-2023-65791 PoCosCommerce POST Parameter shopping-cart sql injection
- CVE-2023-65801 PoCD-Link DIR-846 QoS POST deserialization
- CVE-2023-65811 PoCD-Link DAR-7000 workidajax.php sql injection
- CVE-2023-65841 PoCJobSearch WP Job Board < 2.3.4 - Authentication Bypass
- CVE-2023-65851 PoCJobSearch WP Job Board < 2.3.4 - Arbitrary File Upload to RCE
- CVE-2023-65911 PoCPopup Box Pro < 20.9.0 - Admin+ Stored XSS
- CVE-2023-65923 PoCsFastDup – Fastest WordPress Migration & Duplicator < 2.2 - Directory Listing to Account Takeover and Sensitive Data Exposure
- CVE-2023-65951 PoCWhatsUp Gold Unauthenticated Access to an API Endpoint
- CVE-2023-65991 PoCMissing Standardized Error Handling Mechanism in microweber/microweber
- CVE-2023-66071 PoCTongda OA 2017 delete.php sql injection
- CVE-2023-66081 PoCTongda OA 2017 delete.php sql injection
- CVE-2023-66111 PoCTongda OA 2017 delete.php sql injection
- CVE-2023-66121 PoCTotolink X5000R cstecgi.cgi setWizardCfg os command injection
- CVE-2023-66131 PoCTypecho Logo options-theme.php cross site scripting
- CVE-2023-66141 PoCTypecho Page manage-pages.php backdoor
- CVE-2023-66151 PoCTypecho manage-users.php information disclosure
- CVE-2023-66161 PoCSourceCodester Simple Student Attendance System index.php cross site scripting
- CVE-2023-66171 PoCSourceCodester Simple Student Attendance System attendance.php sql injection
- CVE-2023-66181 PoCSourceCodester Simple Student Attendance System index.php file inclusion
- CVE-2023-66191 PoCSourceCodester Simple Student Attendance System class_form.php sql injection
- CVE-2023-66201 PoCPost SMTP < 2.8.7 - Admin+ SQL Injection
- CVE-2023-66211 PoCPost SMTP < 2.8.7 - Reflected Cross-Site Scripting
- CVE-2023-66233 PoCsEssential Blocks < 4.4.3 - Unauthenticated Local File Inclusion
- CVE-2023-66251 PoCProduct Enquiry for WooCommerce < 3.1 - Arbitrary Enquiry Deletion via CSRF
- CVE-2023-66261 PoCProduct Enquiry for WooCommerce < 3.1 - Admin+ Stored XSS
- CVE-2023-66272 PoCsWP Go Maps < 9.0.28 - Unauthenticated Stored XSS
- CVE-2023-66331 PoCSite Notes <= 2.0.0 - Admin Note Deletion via CSRF
- CVE-2023-66342 PoCsLearnPress <= 4.2.5.7 - Command Injection
- CVE-2023-66461 PoClinkding cross site scripting
- CVE-2023-66471 PoCAMTT HiBOS sql injection
- CVE-2023-66481 PoCPHPGurukul Nipah Virus Testing Management System password-recovery.php sql injection
- CVE-2023-66491 PoCPHPGurukul Teacher Subject Allocation Management System index.php cross site scripting
- CVE-2023-66501 PoCSourceCodester Simple Invoice Generator System login.php cross site scripting
- CVE-2023-66511 PoCcode-projects Matrimonial Site sql injection
- CVE-2023-66521 PoCcode-projects Matrimonial Site register.php register sql injection
- CVE-2023-66531 PoCPHPGurukul Teacher Subject Allocation Management System Create a new Subject subject.php cross-site request forgery
- CVE-2023-66542 PoCsPHPEMS Session Data session.cls.php deserialization
- CVE-2023-66552 PoCsHongjing e-HR Login Interface loadhistroyorgtree sql injection
- CVE-2023-66571 PoCSourceCodester Simple Student Attendance System student_form.php sql injection
- CVE-2023-66581 PoCSourceCodester Simple Student Attendance System sql injection
- CVE-2023-66591 PoCCampcodes Web-Based Student Clearance System login.php sql injection
- CVE-2023-66781 PoCInefficient Regular Expression Complexity in GitLab
- CVE-2023-66821 PoCInefficient Regular Expression Complexity in GitLab
- CVE-2023-66881 PoCInefficient Regular Expression Complexity in GitLab
- CVE-2023-66971 PoCWP Go Maps (formerly WP Google Maps) <= 9.0.28 - Reflected Cross-Site Scripting
- CVE-2023-67001 PoCCookie Information | Free GDPR Consent Solution <= 2.0.22 - Authenticated (Subscriber+) Arbitrary Options Update
- CVE-2023-67021 PoCType confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2023-67103 PoCsMod_cluster/mod_proxy_cluster: stored cross site scripting
- CVE-2023-67321 PoCUltimate Maps by Supsystic < 1.2.16 - Admin+ Stored XSS
- CVE-2023-67361 PoCInefficient Regular Expression Complexity in GitLab
- CVE-2023-67411 PoCWP Customer Area < 8.2.1 - Subscriber+ Account Address Update
- CVE-2023-67502 PoCsClone < 2.4.3 - Unauthenticated Backup Download
- CVE-2023-67531 PoCPath Traversal in mlflow/mlflow
- CVE-2023-67551 PoCDedeBIZ content_batchup_action.php sql injection
- CVE-2023-67561 PoCThecosy IceCMS Captcha login excessive authentication
- CVE-2023-67571 PoCThecosy IceCMS API PlanetUser information disclosure
- CVE-2023-67581 PoCThecosy IceCMS API PlanetCommentList access control
- CVE-2023-67591 PoCThecosy IceCMS Love resource improper enforcement of a single, unique action
- CVE-2023-67601 PoCThecosy IceCMS user session
- CVE-2023-67611 PoCThecosy IceCMS User Data access control
- CVE-2023-67621 PoCThecosy IceCMS Article permission
- CVE-2023-67651 PoCSourceCodester Online Tours & Travels Management System email_setup.php prepare sql injection
- CVE-2023-67661 PoCPHPGurukul Teacher Subject Allocation Management System Delete Course course.php cross-site request forgery
- CVE-2023-67711 PoCSourceCodester Simple Student Attendance System actions.class.php save_attendance sql injection
- CVE-2023-67721 PoCOTCMS ind_backstage.php sql injection
- CVE-2023-67731 PoCCodeAstro POS and Inventory Management System User Creation register_account access control
- CVE-2023-67741 PoCCodeAstro POS and Inventory Management System register_account cross site scripting
- CVE-2023-67751 PoCCodeAstro POS and Inventory Management System item_con cross site scripting
- CVE-2023-67781 PoCCross-site Scripting (XSS) - Stored in allegroai/clearml-server
- CVE-2023-67792 PoCsGlibc: off-by-one heap-based buffer overflow in __vsyslog_internal()
- CVE-2023-67802 PoCsGlibc: integer overflow in __vsyslog_internal()
- CVE-2023-67831 PoCWolfNet IDX for WordPress <= 1.19.1 - Admin+ Stored XSS
- CVE-2023-67862 PoCsPayment Gateway for Telcell <= 2.0.1 - Unauthenticated Open Redirect
- CVE-2023-68211 PoCError Log Viewer < 1.1.3 - Directory Listing to Sensitive Data Exposure
- CVE-2023-68241 PoCWP Customer Area < 8.2.1 - Subscriber+ Account Address Leak
- CVE-2023-68251 PoCFile Manager And File Manager Pro (Multiple Versions) - Directory Traversal
- CVE-2023-68311 PoCPath Traversal: '\..\filename' in mlflow/mlflow
- CVE-2023-68321 PoCBusiness Logic Errors in microweber/microweber
- CVE-2023-68401 PoCMissing Authorization in GitLab
- CVE-2023-68431 PoCeasy.jobs < 2.4.7 - Subscriber+ Arbitrary Settings Update
- CVE-2023-68451 PoCCommentTweets <= 0.6 - Settings Update via CSRF
- CVE-2023-68481 PoCkalcaddle kodbox index.class.php check command injection
- CVE-2023-68491 PoCkalcaddle kodbox app.php cover server-side request forgery
- CVE-2023-68501 PoCkalcaddle KodExplorer API Endpoint unrestricted upload
- CVE-2023-68511 PoCkalcaddle KodExplorer ZIP Archive app.php unzipList code injection
- CVE-2023-68521 PoCkalcaddle KodExplorer app.php server-side request forgery
- CVE-2023-68531 PoCkalcaddle KodExplorer app.php index server-side request forgery
- CVE-2023-68755 PoCsPOST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type…
- CVE-2023-68851 PoCTongda OA 2017 delete.php sql injection
- CVE-2023-68861 PoCxnx3 wangmarket Role Management Page code injection
- CVE-2023-68871 PoCsaysky ForestBlog Image Upload img unrestricted upload
- CVE-2023-68881 PoCPHZ76 RtspServer RtspMesaage.cpp ParseRequestLine stack-based overflow
- CVE-2023-68891 PoCCross-site Scripting (XSS) - Stored in thorsten/phpmyfaq
- CVE-2023-68901 PoCCross-site Scripting (XSS) - Stored in thorsten/phpmyfaq
- CVE-2023-68931 PoCHikvision Intercom Broadcasting System exportrecord.php path traversal
- CVE-2023-68941 PoCHikvision Intercom Broadcasting System Log File system.html information disclosure
- CVE-2023-68955 PoCsHikvision Intercom Broadcasting System ping.php os command injection
- CVE-2023-68961 PoCSourceCodester Simple Image Stack Website cross site scripting
- CVE-2023-68981 PoCSourceCodester Best Courier Management System manage_user.php sql injection
- CVE-2023-68991 PoCrmountjoy92 DashMachine Config save_config code injection
- CVE-2023-69001 PoCrmountjoy92 DashMachine delete_file path traversal
- CVE-2023-69011 PoCcodelyfe Stupid Simple CMS HTTP POST Request handle-command.php os command injection
- CVE-2023-69021 PoCcodelyfe Stupid Simple CMS upload.php unrestricted upload
- CVE-2023-69031 PoCNetentsec NS-ASG Application Security Gateway sql injection
- CVE-2023-69061 PoCTotolink A7100RU HTTP POST Request main buffer overflow
- CVE-2023-69071 PoCcodelyfe Stupid Simple CMS Deletion Interface delete.php improper authentication
- CVE-2023-69091 PoCPath Traversal: '\..\filename' in mlflow/mlflow
- CVE-2023-69311 PoCOut-of-bounds write in Linux kernel's Performance Events system component
- CVE-2023-69331 PoCBetter Search Replace <= 1.4.4 - Unauthenticated PHP Object Injection
- CVE-2023-69411 PoCKeap Official Opt-in Forms <= 1.0.11 - Admin+ Stored XSS
- CVE-2023-69451 PoCSourceCodester Online Student Management System edit-student-detail.php cross site scripting
- CVE-2023-69461 PoCAutotitle for WordPress <= 1.0.3 - Settings Update to Stored XSS via CSRF
- CVE-2023-69701 PoCWP Recipe Maker <= 9.1.0 - Reflected Cross-Site Scripting via Referer
- CVE-2023-69721 PoCBackup Migration <= 1.3.9 - Unauthenticated Path Traversal to Arbitrary File Deletion
- CVE-2023-69761 PoCUnrestricted Upload of File with Dangerous Type
- CVE-2023-69772 PoCsPath Traversal: '\..\filename'
- CVE-2023-69851 PoC10Web AI Assistant – AI content writing assistant <= 1.0.18 - Missing Authorization to Arbitrary Plugin Installation
- CVE-2023-69891 PoCShield Security – Smart Bot Blocking & Intrusion Prevention Security <= 18.5.9 - Unauthenticated Local File Inclusion
- CVE-2023-69911 PoCJSM file_get_contents() Shortcode < 2.7.1 - Contributor+ SSRF