/
cyberknowledge
/
CVE_lab
ОбзорДокументацияВойти
/
cyberknowledge
/
CVE_lab
Код
Запросы
0
Задачи
Вики
Пакеты
0
Релизы
0
Аналитика
ДокументацияПоддержка
Политика конфиденциальностиПользовательское соглашениеПолитика использования «cookies»Согласие субъекта персональных данных
2026 ©
samples/Exploits.csv
115 строк57 KB

Zeros312

Rename sample/ to samples/; remove README from samples
30 июн 2026, 21:21
30 июн 2026, 21:21594ff1d
100 строк
4e466519-fab8-4086-b82f-5e7887cb9916
https://github.com/0xrobiul/CVE-2023-38646
CVE-2023-38646
https://nvd.nist.gov/vuln/detail/CVE-2023-38646
2023-07-29 13:07:00
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.
Exploits_CVE_Monitor,Exploits_InTheWild,Exploits_PoC_CVE
1e30d5bf-ce6a-4262-86b6-725f73d61136
https://github.com/vchan-in/CVE-2023-35078-Exploit-POC
CVE-2023-35078
https://nvd.nist.gov/vuln/detail/CVE-2023-35078
2023-07-29 05:06:27
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
Exploits_CVE_Monitor,Exploits_InTheWild,Exploits_PoC_CVE
cf014e1c-4ed0-442f-9808-35656fd774ac
https://github.com/getgrav/grav/security/advisories/GHSA-9436-3gmp-4f53
CVE-2023-37897
https://nvd.nist.gov/vuln/detail/CVE-2023-37897
2023-07-28 22:24:00
Grav is a file-based Web-platform built in PHP. Grav is subject to a server side template injection (SSTI) vulnerability. The fix for another SSTI vulnerability using `|map`, `|filter` and `|reduce` twigs implemented in the commit `71bbed1` introduces bypass of the denylist due to incorrect return value from `isDangerousFunction()`, which allows to execute the payload prepending double backslash (`\\`). The `isDangerousFunction()` check in version 1.7.42 and onwards retuns `false` value instead of `true` when the `\` symbol is found in the `$name`. This vulnerability can be exploited if the attacker has access to: 1. an Administrator account, or 2. a non-administrator, user account that has Admin panel access and Create/Update page permissions. A fix for this vulnerability has been introduced in commit `b4c6210` and is included in release version `1.7.42.2`. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Exploits_InTheWild,Exploits_NVD
8f91ccef-13c6-43ca-b3fb-26edb3ac4d9c
https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2011.pdf
CVE-2023-3879
https://nvd.nist.gov/vuln/detail/CVE-2023-3879
2023-07-28 19:25:00
A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/del_category.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235241 was assigned to this vulnerability.
Exploits_InTheWild,Exploits_NVD
a6ac0700-a436-4446-9e3d-9a901b1748cf
https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2010.pdf
CVE-2023-3878
https://nvd.nist.gov/vuln/detail/CVE-2023-3878
2023-07-28 19:25:00
A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/about-us.php. The manipulation of the argument pagedes leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235240.
Exploits_InTheWild,Exploits_NVD
55045c1c-668e-435a-8559-6f0dc05d6b3c
https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%209.pdf
CVE-2023-3877
https://nvd.nist.gov/vuln/detail/CVE-2023-3877
2023-07-28 19:25:00
A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/add-services.php. The manipulation of the argument cost leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235239.
Exploits_InTheWild,Exploits_NVD
86b245e8-74e3-4a53-a027-6c40d4cda5f6
https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2019.pdf
CVE-2023-3887
https://nvd.nist.gov/vuln/detail/CVE-2023-3887
2023-07-28 19:04:00
A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/search-appointment.php. The manipulation of the argument searchdata leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235249 was assigned to this vulnerability.
Exploits_InTheWild,Exploits_NVD
4d6e876d-462b-4d19-b37f-539ce06dbd94
https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2018.pdf
CVE-2023-3886
https://nvd.nist.gov/vuln/detail/CVE-2023-3886
2023-07-28 19:03:00
A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/invoice.php. The manipulation of the argument inv_id leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235248.
Exploits_InTheWild,Exploits_NVD
f0a847ec-99d2-45a6-905c-635861d8969d
https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2017.pdf
CVE-2023-3885
https://nvd.nist.gov/vuln/detail/CVE-2023-3885
2023-07-28 19:03:00
A vulnerability was found in Campcodes Beauty Salon Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/edit_category.php. The manipulation of the argument id leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235247.
Exploits_InTheWild,Exploits_NVD
b3bb6d60-7baf-4025-8cc1-680d432ec2f1
https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2016.pdf
CVE-2023-3884
https://nvd.nist.gov/vuln/detail/CVE-2023-3884
2023-07-28 19:03:00
A vulnerability has been found in Campcodes Beauty Salon Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/edit_product.php. The manipulation of the argument id leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235246 is the identifier assigned to this vulnerability.
Exploits_InTheWild,Exploits_NVD
adf45b62-76e4-4445-9932-42bfadc901b3
https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2015.pdf
CVE-2023-3883
https://nvd.nist.gov/vuln/detail/CVE-2023-3883
2023-07-28 19:03:00
A vulnerability, which was classified as problematic, was found in Campcodes Beauty Salon Management System 1.0. This affects an unknown part of the file /admin/add-category.php. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235245 was assigned to this vulnerability.
Exploits_InTheWild,Exploits_NVD
8a702ac9-bf13-40c9-8a07-4f1f754c5422
https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2014.pdf
CVE-2023-3882
https://nvd.nist.gov/vuln/detail/CVE-2023-3882
2023-07-28 19:03:00
A vulnerability, which was classified as critical, has been found in Campcodes Beauty Salon Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/edit-accepted-appointment.php. The manipulation of the argument contactno leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235244.
Exploits_InTheWild,Exploits_NVD
0c15fd7c-c0e2-4161-a682-7a92ddcfdb79
https://github.com/CYN521/cve/blob/main/NS-ASG.md
CVE-2023-3792
https://nvd.nist.gov/vuln/detail/CVE-2023-3792
2023-07-28 19:03:00
A vulnerability was found in Beijing Netcon NS-ASG 6.3. It has been classified as problematic. This affects an unknown part of the file /admin/test_status.php. The manipulation leads to direct request. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235059. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Exploits_InTheWild,Exploits_NVD
ef13e4a4-1492-41ac-83fb-5eaff9697fbf
https://www.whid.ninja/blog/mojobox-yet-another-not-so-smartlock
CVE-2023-34625
https://nvd.nist.gov/vuln/detail/CVE-2023-34625
2023-07-28 19:00:00
ShowMojo MojoBox Digital Lockbox 1.4 is vulnerable to Authentication Bypass. The implementation of the lock opening mechanism via Bluetooth Low Energy (BLE) is vulnerable to replay attacks. A malicious user is able to intercept BLE requests and replicate them to open the lock at any time. Alternatively, an attacker with physical access to the device on which the Android app is installed, can obtain the latest BLE messages via the app logs and use them for opening the lock.
Exploits_InTheWild,Exploits_NVD
856a979c-a11b-46af-adb6-538069f59e0e
https://mandomat.github.io/2023-03-15-testing-mojobox-security/
CVE-2023-34625
https://nvd.nist.gov/vuln/detail/CVE-2023-34625
2023-07-28 19:00:00
ShowMojo MojoBox Digital Lockbox 1.4 is vulnerable to Authentication Bypass. The implementation of the lock opening mechanism via Bluetooth Low Energy (BLE) is vulnerable to replay attacks. A malicious user is able to intercept BLE requests and replicate them to open the lock at any time. Alternatively, an attacker with physical access to the device on which the Android app is installed, can obtain the latest BLE messages via the app logs and use them for opening the lock.
Exploits_InTheWild,Exploits_NVD
00d83fee-f54a-418c-9489-27c45ecce7cf
https://github.com/TXPH/CVE/blob/main/sqli-report.pdf
CVE-2023-3839
https://nvd.nist.gov/vuln/detail/CVE-2023-3839
2023-07-28 18:47:00
A vulnerability, which was classified as problematic, has been found in DedeBIZ 6.2.10. Affected by this issue is some unknown functionality of the file /admin/sys_sql_query.php. The manipulation of the argument sqlquery leads to sql injection. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. VDB-235190 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Exploits_InTheWild,Exploits_NVD
f79ea5aa-290d-4665-8a32-466bf12fd364
https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2012.pdf
CVE-2023-3880
https://nvd.nist.gov/vuln/detail/CVE-2023-3880
2023-07-28 18:22:00
A vulnerability classified as critical has been found in Campcodes Beauty Salon Management System 1.0. Affected is an unknown function of the file /admin/del_service.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-235242 is the identifier assigned to this vulnerability.
Exploits_InTheWild,Exploits_NVD
ff374611-966c-4f2e-b1d6-acf39801522d
https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2020.pdf
CVE-2023-3888
https://nvd.nist.gov/vuln/detail/CVE-2023-3888
2023-07-28 18:21:00
A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-235250 is the identifier assigned to this vulnerability.
Exploits_InTheWild,Exploits_NVD
4e9527a7-24d3-4ec3-93a3-862879a48236
https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2013.pdf
CVE-2023-3881
https://nvd.nist.gov/vuln/detail/CVE-2023-3881
2023-07-28 18:21:00
A vulnerability classified as critical was found in Campcodes Beauty Salon Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/forgot-password.php. The manipulation of the argument contactno leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235243.
Exploits_InTheWild,Exploits_NVD
c043df6f-c2be-4287-9197-22fc889c776d
https://github.com/qiuhuihk/cve/blob/main/upload.md
CVE-2023-3836
https://nvd.nist.gov/vuln/detail/CVE-2023-3836
2023-07-28 18:17:00
A vulnerability classified as critical was found in Dahua Smart Park Management up to 20230713. This vulnerability affects unknown code of the file /emap/devicePoint_addImgIco?hasSubsystem=true. The manipulation of the argument upload leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235162 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Exploits_InTheWild,Exploits_NVD
f8d684e7-7716-47da-a487-2f9f8ffcba9d
https://github.com/TXPH/CVE/blob/main/xss-report.pdf
CVE-2023-3837
https://nvd.nist.gov/vuln/detail/CVE-2023-3837
2023-07-28 18:16:00
A vulnerability classified as problematic has been found in DedeBIZ 6.2.10. Affected is an unknown function of the file /admin/sys_sql_query.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235188. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Exploits_InTheWild,Exploits_NVD
ce629dc4-4665-4914-b3d4-0126d7271c5e
https://github.com/TXPH/CVE/blob/main/xss-report2.pdf
CVE-2023-3838
https://nvd.nist.gov/vuln/detail/CVE-2023-3838
2023-07-28 17:55:00
A vulnerability classified as problematic was found in DedeBIZ 6.2.10. Affected by this vulnerability is an unknown functionality of the file /admin/vote_edit.php. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235189 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Exploits_InTheWild,Exploits_NVD
7e21e580-9c6c-40d5-9060-a99b51bfcfe4
https://youtu.be/XlRVwWXpv4w
CVE-2023-3763
https://nvd.nist.gov/vuln/detail/CVE-2023-3763
2023-07-28 17:51:00
A vulnerability was found in Intergard SGS 8.7.0. It has been declared as problematic. This vulnerability affects unknown code of the component SQL Query Handler. The manipulation leads to cleartext transmission of sensitive information. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-234448. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Exploits_InTheWild,Exploits_NVD
32bb5574-45f0-4115-859b-34f3a1a2b80b
https://youtu.be/yW4tRnjDjhM
CVE-2023-3759
https://nvd.nist.gov/vuln/detail/CVE-2023-3759
2023-07-28 17:51:00
A vulnerability, which was classified as critical, was found in Intergard SGS 8.7.0. Affected is an unknown function. The manipulation leads to permission issues. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-234444. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Exploits_InTheWild,Exploits_NVD
0d5ea219-2fdb-4368-8fdd-db05b7d70b03
https://github.com/convisolabs/CVE-2022-24834
CVE-2022-24834
https://nvd.nist.gov/vuln/detail/CVE-2022-24834
2023-07-28 17:42:33
Redis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson library, and result with heap corruption and potentially remote code execution. The problem exists in all versions of Redis with Lua scripting support, starting from 2.6, and affects only authenticated and authorized users. The problem is fixed in versions 7.0.12, 6.2.13, and 6.0.20.
Exploits_CVE_Monitor,Exploits_InTheWild,Exploits_PoC_CVE
69258448-b75d-489c-864b-4cd2a82290df
https://github.com/nagenanhai/cve/blob/main/2.pdf
CVE-2023-3872
https://nvd.nist.gov/vuln/detail/CVE-2023-3872
2023-07-28 17:26:00
A vulnerability classified as critical was found in Campcodes Beauty Salon Management System 1.0. This vulnerability affects unknown code of the file /admin/edit-services.php. The manipulation of the argument editid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235234 is the identifier assigned to this vulnerability.
Exploits_InTheWild,Exploits_NVD
ea2f066f-d306-4033-9166-425277e48a61
https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%207.pdf
CVE-2023-3875
https://nvd.nist.gov/vuln/detail/CVE-2023-3875
2023-07-28 17:18:00
A vulnerability has been found in Campcodes Beauty Salon Management System 0.1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/del_feedback.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235237 was assigned to this vulnerability.
Exploits_InTheWild,Exploits_NVD
873edffd-349c-42c5-855f-d26c36fdd502
https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%206.pdf
CVE-2023-3874
https://nvd.nist.gov/vuln/detail/CVE-2023-3874
2023-07-28 17:17:00
A vulnerability, which was classified as critical, was found in Campcodes Beauty Salon Management System 1.0. Affected is an unknown function of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235236.
Exploits_InTheWild,Exploits_NVD
e62b8860-a213-457a-acad-317432848c5c
https://github.com/nagenanhai/cve/blob/main/3.pdf
CVE-2023-3873
https://nvd.nist.gov/vuln/detail/CVE-2023-3873
2023-07-28 17:16:00
A vulnerability, which was classified as critical, has been found in Campcodes Beauty Salon Management System 1.0. This issue affects some unknown processing of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235235.
Exploits_InTheWild,Exploits_NVD
6d287b36-90c1-45b8-9810-81eef31dd796
https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%2021.pdf
CVE-2023-3890
https://nvd.nist.gov/vuln/detail/CVE-2023-3890
2023-07-28 17:13:00
A vulnerability classified as problematic has been found in Campcodes Beauty Salon Management System 1.0. This affects an unknown part of the file /admin/edit-accepted-appointment.php. The manipulation of the argument id leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235251.
Exploits_InTheWild,Exploits_NVD
36340d1a-05ca-4950-8554-cea866527a2c
https://github.com/E1CHO/cve_hub/blob/main/Beauty%20Salon%20Management%20System/Beauty%20Salon%20Management%20System%20-%20vuln%208.pdf
CVE-2023-3876
https://nvd.nist.gov/vuln/detail/CVE-2023-3876
2023-07-28 16:57:00
A vulnerability was found in Campcodes Beauty Salon Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/search-appointment.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-235238 is the identifier assigned to this vulnerability.
Exploits_InTheWild,Exploits_NVD
b86268dc-2b40-433c-8bdf-0b96afa60425
https://seclists.org/fulldisclosure/2023/Jul/34
CVE-2023-3788
https://nvd.nist.gov/vuln/detail/CVE-2023-3788
2023-07-28 16:57:00
A vulnerability, which was classified as problematic, has been found in ActiveITzone Active Super Shop CMS 2.5. This issue affects some unknown processing of the component Manage Details Page. The manipulation of the argument name/phone/address leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235055.
Exploits_InTheWild,Exploits_NVD
8227934e-bb8d-415b-9012-691dfc30b44f
https://www.vulnerability-lab.com/get_content.php?id=2278
CVE-2023-3788
https://nvd.nist.gov/vuln/detail/CVE-2023-3788
2023-07-28 16:57:00
A vulnerability, which was classified as problematic, has been found in ActiveITzone Active Super Shop CMS 2.5. This issue affects some unknown processing of the component Manage Details Page. The manipulation of the argument name/phone/address leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235055.
Exploits_InTheWild,Exploits_NVD
709418ff-9fe9-4053-b0f0-b858eeee7d24
https://github.com/chakra-core/ChakraCore/issues/6887
CVE-2023-37142
https://nvd.nist.gov/vuln/detail/CVE-2023-37142
2023-07-27 04:00:00
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::EntryPointInfo::HasInlinees().
Exploits_InTheWild,Exploits_NVD
7838146c-4ffa-4128-b1f8-467e5eab381d
https://github.com/nagenanhai/cve/blob/main/1.pdf
CVE-2023-3871
https://nvd.nist.gov/vuln/detail/CVE-2023-3871
2023-07-28 16:56:00
A vulnerability classified as critical has been found in Campcodes Beauty Salon Management System 1.0. This affects an unknown part of the file /admin/edit_category.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235233 was assigned to this vulnerability.
Exploits_InTheWild,Exploits_NVD
68d9912e-01fe-4960-a9a8-351f4e78a264
http://packetstormsecurity.com/files/173691/mooDating-1.2-Cross-Site-Scripting.html
CVE-2023-3843
https://nvd.nist.gov/vuln/detail/CVE-2023-3843
2023-07-28 16:32:00
A vulnerability was found in mooSocial mooDating 1.2. It has been classified as problematic. Affected is an unknown function of the file /matchmakings/question of the component URL Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. VDB-235194 is the identifier assigned to this vulnerability. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.
Exploits_InTheWild,Exploits_NVD
7487aee2-fc34-497b-8dbd-10a37e2684e8
https://huntr.dev/bounties/4be5fd63-8a0a-490d-9ee1-f33dc768ed76
CVE-2023-3765
https://nvd.nist.gov/vuln/detail/CVE-2023-3765
2023-07-28 15:58:00
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.
Exploits_InTheWild,Exploits_NVD
770df3af-c7db-4d55-9544-dd5fa89e7cd9
https://seclists.org/fulldisclosure/2023/Jul/36
CVE-2023-3789
https://nvd.nist.gov/vuln/detail/CVE-2023-3789
2023-07-28 15:57:00
A vulnerability, which was classified as problematic, was found in PaulPrinting CMS 2018. Affected is an unknown function of the file /account/delivery of the component Search. The manipulation of the argument s leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235056.
Exploits_InTheWild,Exploits_NVD
62dfd5fd-8bee-4361-8066-feb1b216d03c
https://www.vulnerability-lab.com/get_content.php?id=2286
CVE-2023-3789
https://nvd.nist.gov/vuln/detail/CVE-2023-3789
2023-07-28 15:57:00
A vulnerability, which was classified as problematic, was found in PaulPrinting CMS 2018. Affected is an unknown function of the file /account/delivery of the component Search. The manipulation of the argument s leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235056.
Exploits_InTheWild,Exploits_NVD
0dbf1212-de24-47b6-9d2f-2b7e9cd03902
https://seclists.org/fulldisclosure/2023/Jul/35
CVE-2023-3787
https://nvd.nist.gov/vuln/detail/CVE-2023-3787
2023-07-28 15:56:00
A vulnerability classified as problematic was found in Codecanyon Tiva Events Calender 1.4. This vulnerability affects unknown code. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235054 is the identifier assigned to this vulnerability.
Exploits_InTheWild,Exploits_NVD
d74a82bb-bdf6-4c48-b6c8-dd53848b02ea
https://www.vulnerability-lab.com/get_content.php?id=2276
CVE-2023-3787
https://nvd.nist.gov/vuln/detail/CVE-2023-3787
2023-07-28 15:56:00
A vulnerability classified as problematic was found in Codecanyon Tiva Events Calender 1.4. This vulnerability affects unknown code. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235054 is the identifier assigned to this vulnerability.
Exploits_InTheWild,Exploits_NVD
bcbf9393-333b-4f66-9e61-aff360b11221
https://github.com/feathersjs/feathers/security/advisories/GHSA-hhr9-rh25-hvf9
CVE-2023-37899
https://nvd.nist.gov/vuln/detail/CVE-2023-37899
2023-07-28 15:55:00
Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Feathers socket handler did not catch invalid string conversion errors like `const message = ${{ toString: '' }}` which would cause the NodeJS process to crash when sending an unexpected Socket.io message like `socket.emit('find', { toString: '' })`. A fix has been released in versions 5.0.8 and 4.5.18. Users are advised to upgrade. There is no known workaround for this vulnerability.
Exploits_InTheWild,Exploits_NVD
e86e2634-c54c-4f0d-82e6-d0bb54dfb502
https://github.com/aio-libs/aiohttp/security/advisories/GHSA-45c4-8wx5-qw6w
CVE-2023-37276
https://nvd.nist.gov/vuln/detail/CVE-2023-37276
2023-07-28 15:55:00
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. aiohttp v3.8.4 and earlier are bundled with llhttp v6.0.6. Vulnerable code is used by aiohttp for its HTTP request parser when available which is the default case when installing from a wheel. This vulnerability only affects users of aiohttp as an HTTP server (ie `aiohttp.Application`), you are not affected by this vulnerability if you are using aiohttp as an HTTP client library (ie `aiohttp.ClientSession`). Sending a crafted HTTP request will cause the server to misinterpret one of the HTTP header values leading to HTTP request smuggling. This issue has been addressed in version 3.8.5. Users are advised to upgrade. Users unable to upgrade can reinstall aiohttp using `AIOHTTP_NO_EXTENSIONS=1` as an environment variable to disable the llhttp HTTP request parser implementation. The pure Python implementation isn't vulnerable.
Exploits_InTheWild,Exploits_NVD
390cacb0-2c0d-49c5-880c-a5414652552c
https://hackerone.com/reports/2001873
CVE-2023-30589
https://nvd.nist.gov/vuln/detail/CVE-2023-30589
2023-07-11 17:21:00
The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16, v18, and, v20
Exploits_InTheWild,Exploits_NVD
2a1c358e-16c3-44f8-baa6-7213817d9453
https://www.vulnerability-lab.com/get_content.php?id=2317
CVE-2023-3784
https://nvd.nist.gov/vuln/detail/CVE-2023-3784
2023-07-28 15:52:00
A vulnerability was found in Dooblou WiFi File Explorer 1.13.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument search/order/download/mode leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235051.
Exploits_InTheWild,Exploits_NVD
61e54df6-3c5f-4b22-9b62-5964170f99a2
https://seclists.org/fulldisclosure/2023/Jul/37
CVE-2023-3784
https://nvd.nist.gov/vuln/detail/CVE-2023-3784
2023-07-28 15:52:00
A vulnerability was found in Dooblou WiFi File Explorer 1.13.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument search/order/download/mode leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235051.
Exploits_InTheWild,Exploits_NVD
cc27125d-5289-4800-bf18-0c300319b845
https://www.vulnerability-lab.com/get_content.php?id=2321
CVE-2023-3783
https://nvd.nist.gov/vuln/detail/CVE-2023-3783
2023-07-28 15:52:00
A vulnerability was found in Webile 1.0.1. It has been classified as problematic. Affected is an unknown function of the component HTTP POST Request Handler. The manipulation of the argument new_file_name/c leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-235050 is the identifier assigned to this vulnerability.
Exploits_InTheWild,Exploits_NVD
6317dc3f-9e1f-4457-ad80-aa2d95fca291
https://seclists.org/fulldisclosure/2023/Jul/38
CVE-2023-3783
https://nvd.nist.gov/vuln/detail/CVE-2023-3783
2023-07-28 15:52:00
A vulnerability was found in Webile 1.0.1. It has been classified as problematic. Affected is an unknown function of the component HTTP POST Request Handler. The manipulation of the argument new_file_name/c leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-235050 is the identifier assigned to this vulnerability.
Exploits_InTheWild,Exploits_NVD
23b35b70-3fae-44b9-9309-7f34704f63c1
https://www.vulnerability-lab.com/get_content.php?id=2285
CVE-2023-3785
https://nvd.nist.gov/vuln/detail/CVE-2023-3785
2023-07-28 15:41:00
A vulnerability was found in PaulPrinting CMS 2018. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument firstname/lastname/address/city/state leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235052.
Exploits_InTheWild,Exploits_NVD
f557e012-6238-44a6-bf14-be63d9c8f50b
https://seclists.org/fulldisclosure/2023/Jul/39
CVE-2023-3785
https://nvd.nist.gov/vuln/detail/CVE-2023-3785
2023-07-28 15:41:00
A vulnerability was found in PaulPrinting CMS 2018. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument firstname/lastname/address/city/state leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235052.
Exploits_InTheWild,Exploits_NVD
70b52634-77a9-4e72-abf2-ee0d3a14d355
https://research.jfrog.com/vulnerabilities/okhttp-client-brotli-dos/
CVE-2023-3782
https://nvd.nist.gov/vuln/detail/CVE-2023-3782
2023-07-28 14:57:00
DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb into an HTTP response
Exploits_InTheWild,Exploits_NVD
bdd0cb92-9193-48f6-96f8-75de58338122
https://github.com/miniupnp/ngiflib/issues/25
CVE-2023-37748
https://nvd.nist.gov/vuln/detail/CVE-2023-37748
2023-07-28 14:55:00
ngiflib commit 5e7292 was discovered to contain an infinite loop via the function DecodeGifImg at ngiflib.c.
Exploits_InTheWild,Exploits_NVD
2e4da850-cfbe-49f5-a690-6014f22749b7
https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1927070
CVE-2021-32256
https://nvd.nist.gov/vuln/detail/CVE-2021-32256
2023-07-28 14:08:00
An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.
Exploits_InTheWild,Exploits_NVD
197d6c11-d809-45a1-8d2a-4915c032d6e1
https://cacharros-inthewild.blogspot.com/2023/07/the-3080ipx-is-integrated-multicast.html
CVE-2020-22159
https://nvd.nist.gov/vuln/detail/CVE-2020-22159
2023-07-28 13:52:00
EVERTZ devices 3080IPX exe-guest-v1.2-r26125, 7801FC 1.3 Build 27, and 7890IXG V494 are vulnerable to Arbitrary File Upload, allowing an authenticated attacker to upload a webshell or overwrite any critical system files.
Exploits_InTheWild,Exploits_NVD
a895592e-9f6b-4061-a4e4-5bafcc4969b3
https://github.com/segonse/cve/blob/main/sichuang/sichuang.md
CVE-2023-3797
https://nvd.nist.gov/vuln/detail/CVE-2023-3797
2023-07-28 13:43:00
A vulnerability, which was classified as critical, was found in Gen Technology Four Mountain Torrent Disaster Prevention and Control of Monitoring and Early Warning System up to 20230712. This affects an unknown part of the file /Duty/AjaxHandle/UploadFloodPlanFileUpdate.ashx. The manipulation of the argument Filedata leads to unrestricted upload. The exploit has been disclosed to the public and may be used. The identifier VDB-235065 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Exploits_InTheWild,Exploits_NVD
5bca1692-689f-4a9d-81c8-f8f75b735a98
https://github.com/RCEraser/cve/blob/main/wanjiang.md
CVE-2023-3798
https://nvd.nist.gov/vuln/detail/CVE-2023-3798
2023-07-28 13:42:00
A vulnerability has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0 and classified as critical. This vulnerability affects unknown code of the file /App_Resource/UEditor/server/upload.aspx. The manipulation of the argument file leads to unrestricted upload. The exploit has been disclosed to the public and may be used. VDB-235066 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Exploits_InTheWild,Exploits_NVD
efa0772a-cf10-4b48-9d31-543a31c4a75b
https://fluidattacks.com/advisories/indio/
CVE-2023-30791
https://nvd.nist.gov/vuln/detail/CVE-2023-30791
2023-07-28 13:31:00
Plane version 0.7.1-dev allows an attacker to change the avatar of his profile, which allows uploading files with HTML extension that interprets both HTML and JavaScript.
Exploits_InTheWild,Exploits_NVD
aeb088a4-2dcb-4485-8cdd-db997cf7d500
https://github.com/emqx/emqx/issues/10419
CVE-2023-37781
https://nvd.nist.gov/vuln/detail/CVE-2023-37781
2023-07-28 13:26:00
An issue in the emqx_sn plugin of EMQX v4.3.8 allows attackers to execute a directory traversal via uploading a crafted .txt file.
Exploits_InTheWild,Exploits_NVD
80883f3b-f9e5-4c63-8a96-0c0869873441
https://wpscan.com/vulnerability/545007fc-3173-47b1-82c4-ed3fd1247b9c
CVE-2023-3186
https://nvd.nist.gov/vuln/detail/CVE-2023-3186
2023-07-28 13:24:00
The Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties into Object.prototype.
Exploits_InTheWild,Exploits_NVD
ca46cc42-c461-463a-a397-7e04c1212996
https://gitlab.freedesktop.org/pixman/pixman/-/issues/76
CVE-2023-37769
https://nvd.nist.gov/vuln/detail/CVE-2023-37769
2023-07-28 13:22:00
stress-test master commit e4c878 was discovered to contain a FPE vulnerability via the component combine_inner at /pixman-combine-float.c.
Exploits_InTheWild,Exploits_NVD
a08916a1-0feb-46dc-b8a4-d0afac9ccc12
https://wpscan.com/vulnerability/f9f8ae7e-6621-4e29-9257-b8306dbe8811
CVE-2023-3245
https://nvd.nist.gov/vuln/detail/CVE-2023-3245
2023-07-28 13:22:00
The Floating Chat Widget WordPress plugin before 3.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Exploits_InTheWild,Exploits_NVD
b55d59c1-341b-4d6c-b800-ad6a3ddd4bb0
https://hackmd.io/@pSgS7xsnS5a4K7Y0yiB43g/rJr8oNn_n
CVE-2023-37758
https://nvd.nist.gov/vuln/detail/CVE-2023-37758
2023-07-28 13:07:00
D-LINK DIR-815 v1.01 was discovered to contain a buffer overflow via the component /web/captcha.cgi.
Exploits_InTheWild
bbb8fd69-267e-4c97-813f-ea84252dc6e8
https://github.com/Pumpkin-Garden/POC_Metabase_CVE-2023-38646
CVE-2023-38646
https://nvd.nist.gov/vuln/detail/CVE-2023-38646
2023-07-28 11:43:06
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.
Exploits_CVE_Monitor,Exploits_InTheWild,Exploits_PoC_CVE
e6b5def8-caa0-4871-90c3-ec208ea5c2f1
https://github.com/GUIqizsq/cve/blob/main/sql.md
CVE-2023-3799
https://nvd.nist.gov/vuln/detail/CVE-2023-3799
2023-07-28 00:20:00
A vulnerability was found in IBOS OA 4.5.5 and classified as critical. This issue affects some unknown processing of the file ?r=article/category/del of the component Delete Category Handler. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235067. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Exploits_InTheWild,Exploits_NVD
0394532f-d72b-44a2-8307-a83114f4c22c
https://github.com/weng-xianhu/eyoucms/issues/50
CVE-2023-37645
https://nvd.nist.gov/vuln/detail/CVE-2023-37645
2023-07-27 23:49:00
eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.
Exploits_InTheWild,Exploits_NVD
37307ebd-f56c-4fb0-9864-12a8e9f50c25
https://www.akamai.com/blog/security-research/exploit-steelseries-subapp-privilege-escalation
CVE-2023-31461
https://nvd.nist.gov/vuln/detail/CVE-2023-31461
2023-07-27 23:40:00
Attackers can exploit an open API listener on SteelSeries GG 36.0.0 to create a sub-application that will be executed automatically from a controlled location, because of a path traversal vulnerability.
Exploits_InTheWild,Exploits_NVD
62fbe313-6496-47b0-aa54-a5c0c35794bc
https://github.com/khmk2k/CVE-2023-31753/
CVE-2023-31753
https://nvd.nist.gov/vuln/detail/CVE-2023-31753
2023-07-27 23:37:00
SQL injection vulnerability in diskusi.php in eNdonesia 8.7, allows an attacker to execute arbitrary SQL commands via the "rid=" parameter.
Exploits_InTheWild,Exploits_NVD
6e24b967-7518-49b6-a67e-57770e52b830
https://medium.com/@ayush.engr29/cve-2023-37728-6dfb7586311
CVE-2023-37728
https://nvd.nist.gov/vuln/detail/CVE-2023-37728
2023-07-27 23:36:00
IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter.
Exploits_InTheWild
7ccab381-b577-48cf-9848-51188329add3
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/wd_mycloud_unauthenticated_cmd_injection.rb
CVE-2018-17153
https://nvd.nist.gov/vuln/detail/CVE-2018-17153
2023-07-27 23:09:50
It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulnerability to authenticate as an admin user without needing to provide a password, thereby gaining full control of the device. (Whenever an admin logs into My Cloud, a server-side session is created that is bound to the user's IP address. After the session is created, it is possible to call authenticated CGI modules by sending the cookie username=admin in the HTTP request. The invoked CGI will check if a valid session is present and bound to the user's IP address.) It was found that it is possible for an unauthenticated attacker to create a valid session without a login. The network_mgr.cgi CGI module contains a command called "cgi_get_ipv6" that starts an admin session -- tied to the IP address of the user making the request -- if the additional parameter "flag" with the value "1" is provided. Subsequent invocation of commands that would normally require admin privileges now succeed if an attacker sets the username=admin cookie.
Exploits_InTheWild
5e73913b-da57-4498-8f5b-3932a0431ecf
https://youtu.be/CtOFB-L1rOg
CVE-2023-3760
https://nvd.nist.gov/vuln/detail/CVE-2023-3760
2023-07-27 23:08:00
A vulnerability has been found in Intergard SGS 8.7.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Change Password Handler. The manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-234445 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Exploits_InTheWild,Exploits_NVD
66c22163-2762-4545-92ff-d23c5d4f6660
https://huntr.dev/bounties/be6616eb-384d-40d6-b1fd-0ec9e4973f12
CVE-2023-3692
https://nvd.nist.gov/vuln/detail/CVE-2023-3692
2023-07-27 19:56:00
Unrestricted Upload of File with Dangerous Type in GitHub repository admidio/admidio prior to 4.2.10.
Exploits_InTheWild,Exploits_NVD
b7b67cd1-4b05-4500-9b52-422112056e5d
https://huntr.dev/bounties/e8d530db-a6a7-4f79-a95d-b77654cc04f8
CVE-2023-3700
https://nvd.nist.gov/vuln/detail/CVE-2023-3700
2023-07-27 19:54:00
Authorization Bypass Through User-Controlled Key in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
Exploits_InTheWild,Exploits_NVD
f806ef9e-70a0-4ec9-a78b-39b9a4b939f8
https://lore.kernel.org/all/CABcoxUayum5oOqFMMqAeWuS8+EzojquSOSyDA3J_2omY=2EeAg@mail.gmail.com/
CVE-2023-0160
https://nvd.nist.gov/vuln/detail/CVE-2023-0160
2023-07-27 19:48:00
A deadlock flaw was found in the Linux kernel’s BPF subsystem. This flaw allows a local user to potentially crash the system.
Exploits_InTheWild,Exploits_NVD
174311a3-9866-4302-a26f-48c5fe49c584
https://github.com/9001/copyparty/security/advisories/GHSA-pxfv-7rr3-2qjg
CVE-2023-37474
https://nvd.nist.gov/vuln/detail/CVE-2023-37474
2023-07-27 19:47:00
Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path Traversal attack technique allows an attacker access to files, directories, and commands that reside outside the web document root directory. This issue has been addressed in commit `043e3c7d` which has been included in release 1.8.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Exploits_InTheWild,Exploits_NVD
ba06e59b-a6a4-4197-8a73-24ce4bb059f0
https://talosintelligence.com/vulnerability_reports/TALOS-2022-1666
CVE-2022-46291
https://nvd.nist.gov/vuln/detail/CVE-2022-46291
2023-07-27 18:31:00
Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability affects the MSI file format
Exploits_InTheWild,Exploits_NVD
9954d332-cb40-482f-907f-1561e8e94111
https://talosintelligence.com/vulnerability_reports/TALOS-2022-1665
CVE-2022-46289
https://nvd.nist.gov/vuln/detail/CVE-2022-46289
2023-07-27 18:22:00
Multiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.nAtoms calculation wrap-around, leading to a small buffer allocation
Exploits_InTheWild,Exploits_NVD
f6202b42-c88e-430d-b31f-1313fde99ec1
https://talosintelligence.com/vulnerability_reports/TALOS-2022-1670
CVE-2022-46280
https://nvd.nist.gov/vuln/detail/CVE-2022-46280
2023-07-27 18:21:00
A use of uninitialized pointer vulnerability exists in the PQS format pFormat functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Exploits_InTheWild,Exploits_NVD
b8715061-6d66-4a75-8d3f-4633e92f167b
https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-p9xf-74xh-mhw5
CVE-2023-37477
https://nvd.nist.gov/vuln/detail/CVE-2023-37477
2023-07-27 18:20:00
1Panel is an open source Linux server operation and maintenance management panel. An OS command injection vulnerability exists in 1Panel firewall functionality. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. 1Panel firewall functionality `/hosts/firewall/ip` endpoint read user input without validation, the attacker extends the default functionality of the application, which execute system commands. An attacker can execute arbitrary code on the target system, which can lead to a complete compromise of the system. This issue has been addressed in commit `e17b80cff49` which is included in release version `1.4.3`. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Exploits_InTheWild,Exploits_NVD
b6ad7184-52c8-4c04-b0c5-feeb28b3ac04
https://talosintelligence.com/vulnerability_reports/TALOS-2022-1664
CVE-2022-43607
https://nvd.nist.gov/vuln/detail/CVE-2022-43607
2023-07-27 18:10:00
An out-of-bounds write vulnerability exists in the MOL2 format attribute and value functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Exploits_InTheWild,Exploits_NVD
1684e458-f149-4f3d-a134-b03ec3fe4bd1
https://talosintelligence.com/vulnerability_reports/TALOS-2022-1669
CVE-2022-44451
https://nvd.nist.gov/vuln/detail/CVE-2022-44451
2023-07-27 18:09:00
A use of uninitialized pointer vulnerability exists in the MSI format atom functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Exploits_InTheWild,Exploits_NVD
cbeb7c91-e945-48ed-aeec-5521120f6bf3
https://talosintelligence.com/vulnerability_reports/TALOS-2022-1671
CVE-2022-43467
https://nvd.nist.gov/vuln/detail/CVE-2022-43467
2023-07-27 18:09:00
An out-of-bounds write vulnerability exists in the PQS format coord_file functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Exploits_InTheWild,Exploits_NVD
f8e36850-e97d-44f6-95c5-5d40e110fb24
https://talosintelligence.com/vulnerability_reports/TALOS-2022-1672
CVE-2022-37331
https://nvd.nist.gov/vuln/detail/CVE-2022-37331
2023-07-27 18:06:00
An out-of-bounds write vulnerability exists in the Gaussian format orientation functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Exploits_InTheWild,Exploits_NVD
c3a33ba9-a59a-4833-8b2f-a3d0bd5b074e
https://talosintelligence.com/vulnerability_reports/TALOS-2022-1667
CVE-2022-41793
https://nvd.nist.gov/vuln/detail/CVE-2022-41793
2023-07-27 18:05:00
An out-of-bounds write vulnerability exists in the CSR format title functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Exploits_InTheWild,Exploits_NVD
4c559ae1-f042-4856-a0a3-724b02505480
https://talosintelligence.com/vulnerability_reports/TALOS-2022-1668
CVE-2022-42885
https://nvd.nist.gov/vuln/detail/CVE-2022-42885
2023-07-27 18:04:00
A use of uninitialized pointer vulnerability exists in the GRO format res functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Exploits_InTheWild,Exploits_NVD
38b99267-00e8-4442-806c-a8a628275f8d
https://github.com/naihsin/IoT/tree/main/D-Link/DIR-619L/overflow
CVE-2023-37791
https://nvd.nist.gov/vuln/detail/CVE-2023-37791
2023-07-27 16:11:00
D-Link DIR-619L v2.04(TW) was discovered to contain a stack overflow via the curTime parameter at /goform/formLogin.
Exploits_InTheWild,Exploits_NVD
3b893e34-ac58-42bd-844d-8cab948f47cd
https://github.com/michaelrsweet/htmldoc/issues/433
CVE-2021-34121
https://nvd.nist.gov/vuln/detail/CVE-2021-34121
2023-07-27 15:19:00
An Out of Bounds flaw was discovered in htmodoc 1.9.12 in function parse_tree() in toc.cxx, this possibly leads to memory layout information leaking in the data. This might be used in a chain of vulnerability in order to reach code execution.
Exploits_InTheWild,Exploits_NVD
f4c5e871-df53-44ff-8152-62d6264d6793
https://github.com/michaelrsweet/htmldoc/issues/431
CVE-2021-34119
https://nvd.nist.gov/vuln/detail/CVE-2021-34119
2023-07-27 15:19:00
A flaw was discovered in htmodoc 1.9.12 in function parse_paragraph in ps-pdf.cxx ,this flaw possibly allows possible code execution and a denial of service via a crafted file.
Exploits_InTheWild,Exploits_NVD
85a45334-1d58-4f37-8714-379baae1e0bf
https://sourceware.org/bugzilla/show_bug.cgi?id=27501
CVE-2021-33294
https://nvd.nist.gov/vuln/detail/CVE-2021-33294
2023-07-27 15:19:00
In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file.
Exploits_InTheWild,Exploits_NVD
0e75da41-aa2c-4eb1-906e-77dfb72f13fd
https://github.com/libsndfile/libsndfile/issues/832
CVE-2022-33064
https://nvd.nist.gov/vuln/detail/CVE-2022-33064
2023-07-27 15:14:00
An off-by-one error in function wav_read_header in src/wav.c in Libsndfile 1.1.0, results in a write out of bound, which allows an attacker to execute arbitrary code, Denial of Service or other unspecified impacts.
Exploits_InTheWild,Exploits_NVD
3a1ff867-f48f-42c7-8a25-4789411d27cf
https://lana.codes/lanavdb/071fa6eb-2e54-43a1-b37f-1e562988b7d4?_s_id=cve
CVE-2022-34155
https://nvd.nist.gov/vuln/detail/CVE-2022-34155
2023-07-27 15:12:00
Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3.
Exploits_InTheWild,Exploits_NVD
7f481b7d-ae65-43fb-8447-31451e83f74c
https://github.com/libsndfile/libsndfile/issues/833
CVE-2022-33065
https://nvd.nist.gov/vuln/detail/CVE-2022-33065
2023-07-27 15:11:00
Multiple signed integers overflow in function au_read_header in src/au.c and in functions mat4_open and mat4_read_header in src/mat4.c in Libsndfile, allows an attacker to cause Denial of Service or other unspecified impacts.
Exploits_InTheWild,Exploits_NVD
2a46947e-3aba-4271-be4a-14287ff05092
https://doc.rust-lang.org/std/macro.eprintln.html
CVE-2022-47085
https://nvd.nist.gov/vuln/detail/CVE-2022-47085
2023-07-27 15:08:00
An issue was discovered in ostree before 2022.7 allows attackers to cause a denial of service or other unspecified impacts via the print_panic function in repo_checkout_filter.rs.
Exploits_InTheWild,Exploits_NVD
1720569b-5187-47ca-9ca6-33b010c97540
https://github.com/NCI-Agency/anet/issues/4408
CVE-2023-31441
https://nvd.nist.gov/vuln/detail/CVE-2023-31441
2023-07-27 15:07:00
In NATO Communications and Information Agency anet (aka Advisor Network) through 3.3.0, an attacker can provide a crafted JSON file to sanitizeJson and cause an exception. This is related to the U+FFFD Unicode replacement character. A for loop does not consider that a data structure is being modified during loop execution.
Exploits_InTheWild,Exploits_NVD
c77509c9-4378-4168-a121-609eab3ab9af
https://github.com/thorfdbg/libjpeg/issues/87#BUG1
CVE-2023-37836
https://nvd.nist.gov/vuln/detail/CVE-2023-37836
2023-07-27 15:02:00
libjpeg commit db33a6e was discovered to contain a reachable assertion via BitMapHook::BitMapHook at bitmaphook.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
Exploits_InTheWild,Exploits_NVD
41e42507-5d7a-40dd-b4d4-624dde48c25b
https://github.com/thorfdbg/libjpeg/issues/87#BUG0
CVE-2023-37837
https://nvd.nist.gov/vuln/detail/CVE-2023-37837
2023-07-27 15:00:00
libjpeg commit db33a6e was discovered to contain a heap buffer overflow via LineBitmapRequester::EncodeRegion at linebitmaprequester.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
Exploits_InTheWild,Exploits_NVD
a9d33458-8936-474f-bdc8-c9a10e5d4714
https://heegong.github.io/posts/Local-privilege-escalation-in-Panda-Dome-VPN-for-Windows-Installer/
CVE-2023-37849
https://nvd.nist.gov/vuln/detail/CVE-2023-37849
2023-07-27 14:50:00
A DLL hijacking vulnerability in Panda Security VPN for Windows prior to version v15.14.8 allows attackers to execute arbitrary code via placing a crafted DLL file in the same directory as PANDAVPN.exe.
Exploits_InTheWild,Exploits_NVD
5c65be17-0fd0-47f3-9875-5c2282dbb9cf
https://github.com/yezere/src/blob/main/Dedecms%20v5.7.109%20Background%20Command%20Execution%20Vulnerability.md
CVE-2023-37839
https://nvd.nist.gov/vuln/detail/CVE-2023-37839
2023-07-27 14:48:00
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file.
Exploits_InTheWild,Exploits_NVD
fb8dbc2d-3c92-41b8-a13b-63db85ee682d
https://github.com/sahiloj/CVE-2023-37599
CVE-2023-37599
https://nvd.nist.gov/vuln/detail/CVE-2023-37599
2023-07-27 14:40:00
An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory
Exploits_CVE_Monitor,Exploits_InTheWild,Exploits_NVD,Exploits_PoC_CVE
049d064f-e65b-40c3-84fb-f2278a389177
https://github.com/rapid7/metasploit-framework/pull/13607
CVE-2020-7357
https://nvd.nist.gov/vuln/detail/CVE-2020-7357
2023-07-27 13:31:00
Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several branches and versions of the CMS application, including CME-SE, CMS-60, CMS-40, CMS-20, and CMS version 8.2, 8.0, and 7.5.
Exploits_InTheWild,Exploits_NVD
a952077c-368d-42ef-8e48-e44a93d58d62
https://starlabs.sg/advisories/23/23-3514/
CVE-2023-3514
https://nvd.nist.gov/vuln/detail/CVE-2023-3514
2023-07-27 12:58:00
Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access to gain SYSTEM privilege via communicating with the named pipe as a low-privilege user and calling "AddModule" or "UninstallModules" command to execute arbitrary executable file.
Exploits_InTheWild,Exploits_NVD