CVE-2023-7000 to CVE-2023-7999
181 CVEs with public proof-of-concept exploits.
- CVE-2023-70121 PoCInsufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convinced a user to…
- CVE-2023-70161 PoCPrivilege Escalation in SafeNet Authentication Client
- CVE-2023-70181 PoCDeserialization of Untrusted Data in huggingface/transformers
- CVE-2023-70201 PoCTongda OA 2017 view.php sql injection
- CVE-2023-70211 PoCTongda OA 2017 delete_search.php sql injection
- CVE-2023-70221 PoCTongda OA 2017 delete_all.php sql injection
- CVE-2023-70231 PoCTongda OA 2017 delete.php sql injection
- CVE-2023-70251 PoCKylinSoft hedron-domain-hook DBus init_kcm access control
- CVE-2023-70261 PoCLightxun IPTV Gateway web_upload_template.html unrestricted upload
- CVE-2023-702824 PoCsKEVWeak Password Recovery Mechanism for Forgotten Password in GitLab
- CVE-2023-70351 PoCautomad Setting post.php cross site scripting
- CVE-2023-70361 PoCautomad Content Type FileCollectionController.php upload unrestricted upload
- CVE-2023-70371 PoCautomad FileController.php import server-side request forgery
- CVE-2023-70381 PoCautomad User Creation cross-site request forgery
- CVE-2023-70391 PoCByzoro S210 importexport.php injection
- CVE-2023-70401 PoCcodelyfe Stupid Simple CMS rename.php path traversal
- CVE-2023-70411 PoCcodelyfe Stupid Simple CMS rename.php path traversal
- CVE-2023-70452 PoCsCross-Site Request Forgery (CSRF) in GitLab
- CVE-2023-70501 PoCPHPGurukul Online Notes Sharing System profile.php cross site scripting
- CVE-2023-70511 PoCPHPGurukul Online Notes Sharing System manage-notes.php cross-site request forgery
- CVE-2023-70521 PoCPHPGurukul Online Notes Sharing System profile.php cross-site request forgery
- CVE-2023-70531 PoCPHPGurukul Online Notes Sharing System signup.php weak password
- CVE-2023-70541 PoCPHPGurukul Online Notes Sharing System add-notes.php unrestricted upload
- CVE-2023-70551 PoCPHPGurukul Online Notes Sharing System Contact Information profile.php access control
- CVE-2023-70561 PoCcode-projects Faculty Management System subjects.php cross site scripting
- CVE-2023-70571 PoCcode-projects Faculty Management System yearlevel.php cross site scripting
- CVE-2023-70581 PoCSourceCodester Simple Student Attendance System path traversal
- CVE-2023-70591 PoCSourceCodester School Visitor Log e-Book log-book.php cross site scripting
- CVE-2023-70601 PoCMissing Security Control in Zephyr OS IP Packet Handling
- CVE-2023-70741 PoCWP Social Bookmark Menu <= 1.2 - Settings Update via CSRF
- CVE-2023-70751 PoCcode-projects Point of Sales and Inventory Management System checkout.php cross site scripting
- CVE-2023-70821 PoCWP All Import < 3.7.3 - Admin+ Arbitrary File Upload to RCE
- CVE-2023-70831 PoCVoting Record <= 2.0 - Settings Update to Stored XSS via CSRF
- CVE-2023-70841 PoCVoting Record <= 2.0 - Subscriber+ Stored XSS
- CVE-2023-70851 PoCScalable Vector Graphics (SVG) <= 3.4 - Author+ Stored XSS via SVG
- CVE-2023-70861 PoCSVG Uploads Support <= 2.1.1 - Author+ Stored XSS via SVG
- CVE-2023-70881 PoCAdd SVG Support for Media Uploader | inventivo <= 1.0.5 - Author+ Stored XSS via SVG
- CVE-2023-70891 PoCEasy SVG Allow <= 1.0 - Author+ Stored XSS via SVG
- CVE-2023-70911 PoCDreamer CMS uploadFile unrestricted upload
- CVE-2023-70921 PoCUniway UW-302VP Admin Web Interface wlan_basic_set.cgi cross-site request forgery
- CVE-2023-70931 PoCKylinSoft kylin-system-updater com.kylin.systemupgrade Service UpgradeStrategiesDbus.py os command injection
- CVE-2023-70941 PoCNetentsec NS-ASG Application Security Gateway nsasg6.0.tgz information disclosure
- CVE-2023-70951 PoCTotolink A7100RU HTTP POST Request main buffer overflow
- CVE-2023-70961 PoCcode-projects Faculty Management System crud.php sql injection
- CVE-2023-70971 PoCcode-projects Water Billing System addbill.php sql injection
- CVE-2023-70981 PoCicret EasyImages hide.php path traversal
- CVE-2023-70991 PoCPHPGurukul Nipah Virus Testing Management System bwdates-report-result.php sql injection
- CVE-2023-71001 PoCPHPGurukul Restaurant Table Booking System bwdates-report-details.php sql injection
- CVE-2023-71011 PoCKEVArbitrary Code Execution (ACE) Vulnerability
- CVE-2023-71021 PoCRemote Code Execution (RCE) Vulnerability
- CVE-2023-71051 PoCcode-projects E-Commerce Website index_search.php sql injection
- CVE-2023-71061 PoCcode-projects E-Commerce Website sql injection
- CVE-2023-71081 PoCcode-projects E-Commerce Website user_signup.php cross site scripting
- CVE-2023-71091 PoCcode-projects Library Management System login.php sql injection
- CVE-2023-71101 PoCcode-projects Library Management System login.php sql injection
- CVE-2023-71111 PoCcode-projects Library Management System index.php sql injection
- CVE-2023-71151 PoCPageLayer < 1.8.1 - Admin+ Stored XSS
- CVE-2023-71162 PoCsWeiYe-Jing datax-web HTTP POST Request killJob os command injection
- CVE-2023-71231 PoCSourceCodester Medicine Tracking System sql injection
- CVE-2023-71241 PoCcode-projects E-Commerce Site search.php cross site scripting
- CVE-2023-71251 PoCCommunity by PeepSo < 6.3.1.2 - User Post Creation via CSRF
- CVE-2023-71261 PoCcode-projects Automated Voting System Admin Login sql injection
- CVE-2023-71271 PoCcode-projects Automated Voting System Login sql injection
- CVE-2023-71281 PoCcode-projects Voting System Admin Login sql injection
- CVE-2023-71291 PoCcode-projects Voting System Voters Login sql injection
- CVE-2023-71301 PoCcode-projects College Notes Gallery login.php sql injection
- CVE-2023-71311 PoCcode-projects Intern Membership Management System User Registration sql injection
- CVE-2023-71321 PoCcode-projects Intern Membership Management System User Registration cross site scripting
- CVE-2023-71331 PoCy_project RuoYi HTTP POST Request login cross site scripting
- CVE-2023-71341 PoCSourceCodester Medicine Tracking System path traversal
- CVE-2023-71351 PoCcode-projects Record Management System Offices offices.php cross site scripting
- CVE-2023-71361 PoCcode-projects Record Management System Document Type doctype.php cross site scripting
- CVE-2023-71371 PoCcode-projects Client Details System HTTP POST Request sql injection
- CVE-2023-71381 PoCcode-projects Client Details System HTTP POST Request admin sql injection
- CVE-2023-71391 PoCcode-projects Client Details System HTTP POST Request regester.php sql injection
- CVE-2023-71401 PoCcode-projects Client Details System manage-users.php sql injection
- CVE-2023-71411 PoCcode-projects Client Details System update-clients.php sql injection
- CVE-2023-71421 PoCcode-projects Client Details System clientview.php sql injection
- CVE-2023-71431 PoCcode-projects Client Details System regester.php cross site scripting
- CVE-2023-71441 PoCgopeak MasterLab HTTP POST Request Feature.php sqlInject sql injection
- CVE-2023-71451 PoCgopeak MasterLab HTTP POST Request Framework.php sqlInject sql injection
- CVE-2023-71461 PoCgopeak MasterLab HTTP POST Request Feature.php sqlInjectDelete sql injection
- CVE-2023-71481 PoCShifuML shifu Java Expression Language DataPurifier.java code injection
- CVE-2023-71491 PoCcode-projects QR Code Generator cross site scripting
- CVE-2023-71501 PoCCampcodes Chic Beauty Salon Product product-list.php unrestricted upload
- CVE-2023-71511 PoCProduct Enquiry for WooCommerce < 3.2 - Reflected XSS
- CVE-2023-71521 PoCMicroPython modselect.c poll_set_add_fd use after free
- CVE-2023-71541 PoCHubbub Lite < 1.32.0 - Admin+ Stored XSS
- CVE-2023-71551 PoCSourceCodester Free and Open Source Inventory Management System edit_product.php sql injection
- CVE-2023-71561 PoCCampcodes Online College Library System Search index.php sql injection
- CVE-2023-71571 PoCSourceCodester Free and Open Source Inventory Management System sell_return_data.php sql injection
- CVE-2023-71581 PoCMicroPython objslice.c slice_indices heap-based overflow
- CVE-2023-71591 PoCgopeak MasterLab User.php update unrestricted upload
- CVE-2023-71611 PoCNetentsec NS-ASG Application Security Gateway Login sql injection
- CVE-2023-71631 PoCD-Link D-View 8 Unauthenticated Probe-Core Server Communication
- CVE-2023-71642 PoCsBackWPup < 4.0.4 - Unauthenticated Backup Download
- CVE-2023-71652 PoCsJetBackup < 2.0.9.9 - Directory Listing Exposing Backups
- CVE-2023-71661 PoCNovel-Plus HTTP POST Request updateUserInfo cross site scripting
- CVE-2023-71671 PoCPersian Fonts <= 1.6 - Admin+ Stored XSS
- CVE-2023-71681 PoCBetter Follow Button for Jetpack <= 8.0 - Admin+ Stored XSS
- CVE-2023-71701 PoCEventON-RSVP < 2.9.5 - Reflected XSS
- CVE-2023-71711 PoCNovel-Plus Friendly Link FriendLinkController.java cross site scripting
- CVE-2023-71721 PoCPHPGurukul Hospital Management System Admin Dashboard sql injection
- CVE-2023-71732 PoCsPHPGurukul Hospital Management System registration.php cross site scripting
- CVE-2023-71741 PoCaBitGone CommentSafe <= 1.0.0 - Settings Update to Stored XSS via CSRF
- CVE-2023-71751 PoCCampcodes Online College Library System HTTP POST Request borrow_add.php sql injection
- CVE-2023-71761 PoCCampcodes Online College Library System HTTP POST Request return_add.php sql injection
- CVE-2023-71771 PoCCampcodes Online College Library System HTTP POST Request book_add.php sql injection
- CVE-2023-71781 PoCCampcodes Online College Library System HTTP POST Request book_row.php sql injection
- CVE-2023-71791 PoCCampcodes Online College Library System HTTP POST Request category_row.php sql injection
- CVE-2023-71801 PoCTongda OA 2017 delete.php sql injection
- CVE-2023-71811 PoCMuyun DedeBIZ Add Attachment unrestricted upload
- CVE-2023-71831 PoC7-card Fakabao alipay_notify.php sql injection
- CVE-2023-71841 PoC7-card Fakabao notify.php sql injection
- CVE-2023-71851 PoC7-card Fakabao wxpay_notify.php sql injection
- CVE-2023-71861 PoC7-card Fakabao notify.php sql injection
- CVE-2023-71871 PoCTotolink N350RT HTTP POST Request stack-based overflow
- CVE-2023-71881 PoCShipping 100 Fahuo100 login.php sql injection
- CVE-2023-71891 PoCS-CMS sql injection
- CVE-2023-71901 PoCS-CMS sql injection
- CVE-2023-71911 PoCS-CMS reg.php sql injection
- CVE-2023-71931 PoCMTab Bookmark Installation install.php access control
- CVE-2023-71941 PoCMeris <= 1.1.2 - Reflected XSS
- CVE-2023-71951 PoCWP-Reply Notify <= 1.1 - Settings Update via CSRF
- CVE-2023-71961 PoCUltimate Noindex Nofollow Tool <= 1.1.2 - Settings Update via CSRF
- CVE-2023-71971 PoCMarketing Twitter Bot <= 1.11 - Settings Update to Stored XSS via CSRF
- CVE-2023-71981 PoCWPDashboardNotes < 1.0.11 - Unauthorised Deletion of Private Notes
- CVE-2023-71991 PoCRelevanssi (Free < 4.22.0, Premium < 2.25.0) - Unauthenticated Private/Draft Post Disclosure
- CVE-2023-72001 PoCEventON < 4.4.1 - Reflected Cross-Site Scripting
- CVE-2023-72011 PoCEverest Backup < 2.2.5 - Admin+ Arbitrary File Upload
- CVE-2023-72022 PoCsFatal Error Notify < 1.5.3 - Subscriber+ Test Error Email Sending
- CVE-2023-72031 PoCSmart Forms < 2.6.87 - Subscriber+ Arbitrary Entry Deletion
- CVE-2023-72041 PoCWP STAGING WordPress Backup Plugin < 3.2.0 - Unauthorized Sensitive Data Exposure
- CVE-2023-72081 PoCTotolink X2000R_V2 boa formTmultiAP buffer overflow
- CVE-2023-72091 PoCUniway Router Device Reset device_reset.cgi denial of service
- CVE-2023-72101 PoCOneNav API improper authentication
- CVE-2023-72111 PoCUniway Router Administrative Web Interface reliance on ip address for authentication
- CVE-2023-72121 PoCDeDeCMS Backend file_class.php unrestricted upload
- CVE-2023-72131 PoCTotolink N350RT HTTP POST Request main stack-based overflow
- CVE-2023-72141 PoCTotolink N350RT HTTP POST Request main stack-based overflow
- CVE-2023-72151 PoCChanzhaoyu chatgpt-web cross site scripting
- CVE-2023-72161 PoCCpio: extraction allows symlinks which enables remote command execution
- CVE-2023-72191 PoCTotolink N350RT cstecgi.cgi loginAuth stack-based overflow
- CVE-2023-72201 PoCTotolink NR1800X cstecgi.cgi loginAuth stack-based overflow
- CVE-2023-72211 PoCTotolink T6 HTTP POST Request main buffer overflow
- CVE-2023-72221 PoCTotolink X2000R HTTP POST Request boa formTmultiAP buffer overflow
- CVE-2023-72231 PoCTotolink T6 cstecgi.cgi access control
- CVE-2023-72261 PoCmeetyoucrop big-whale Admin Module all.api improper ownership management
- CVE-2023-72281 PoCilli Link Party! <= 1.0 - Unauthenticated Stored XSS
- CVE-2023-72291 PoCilli Link Party! <= 1.0 - Settings Update via CSRF
- CVE-2023-72301 PoCilli Link Party! <= 1.0 - Admin+ Stored Cross-Site Scripting
- CVE-2023-72312 PoCsilli Link Party! <= 1.0 - Unauthenticated Arbitrary Link Deletion
- CVE-2023-72321 PoCBackup and Restore WordPress <= 1.45 - Unauthenticated Sensitive Data Exposure
- CVE-2023-72331 PoCGigPress <= 2.3.29 - Admin+ Stored Cross Site Scripting
- CVE-2023-72361 PoCBackup Bolt <= 1.3.0 - Sensitive Data Exposure
- CVE-2023-72391 PoCwp-dashboard-notes < 1.0.11 - Contributor+ Arbitrary Private Notes Update via IDOR
- CVE-2023-72462 PoCsSystem Dashboard < 2.8.10 - XSS via Header Injection
- CVE-2023-72471 PoCLogin as User or Customer <= 3.8 - Admin Account Takeover
- CVE-2023-72521 PoCTickera < 3.5.2.5 - Ticket leakage through IDOR
- CVE-2023-72531 PoCImport WP < 2.13.1 - Admin+ Server-side Request Forgery
- CVE-2023-72591 PoCzzdevelop lenosp Adduser Page cross site scripting
- CVE-2023-72612 PoCsInappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to perform privilege…
- CVE-2023-72681 PoCArtPlacer Widget < 2.21.2 - Subscriber+ Arbitrary Widget Deletion
- CVE-2023-72691 PoCArtPlacer Widget < 2.21.2 - Stored XSS via CSRF
- CVE-2023-72701 PoCLocal Privilege Escalation via MSI installer
- CVE-2023-72971 PoCTwitterPosts <= 1.0.2 - Settings Update via CSRF
- CVE-2023-73041 PoCRuijie RG-UAC nmc_sync.php Command Injection
- CVE-2023-73051 PoCSmartBI RMIServlet Unrestricted File Upload RCE
- CVE-2023-73071 PoCSangfor Behavior Management System XML External Entity Injection
- CVE-2023-73081 PoCSecGate3600 Firewall Information Disclosure via authManageSet.cgi
- CVE-2023-73092 PoCsDahua Smart Park Integrated Management Platform Front-End Arbitrary File Upload
- CVE-2023-73113 PoCsBYTEVALUE Intelligent Flow Control Router Command Injection
- CVE-2023-73252 PoCsMingyu Operations and Maintenance Audit and Risk Control System xmlrpc.sock SSRF
- CVE-2023-73261 PoCEpson Stylus SX510W Printer Remote Power Off DoS
- CVE-2023-73272 PoCsOzeki SMS Gateway <= 10.3.208 Unauthenticated Arbitrary File Read
- CVE-2023-73283 PoCsScreen SFT DAB 600/C <= 1.9.3 Unauthenticated Information Disclosure
- CVE-2023-73293 PoCsTinycontrol LAN Controller v3 (LK3) Remote DoS
- CVE-2023-73304 PoCsRuijie Networks NBR Routers Unauthenticated Arbitrary File Upload via fileupload.php
- CVE-2023-73344 PoCsChangjetong T+ <= 16.x GetStoreWarehouseByStore Deserialization RCE
- CVE-2023-73354 PoCsEduSoho < 22.4.7 Arbitrary File Read via classroom-course-statistics
- CVE-2023-73371 PoCJS Help Desk – AI-Powered Support & Ticketing System 2.8.2 - Unauthenticated SQL Injection via 'js-support-ticket-token-tkstatus' Cookie