3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-0258
Online Food Ordering System General
2.4
LOW
EPSS
0.2%
2023 CWE-79 1 PoC

A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Category List Handler. The manipulation of the argument Reason with the input "><script>prompt(1)</script> leads to cross site scripting. The attack may be launched remotely. VDB-218186 is the identifier assigned to this vulnerability.

CVE-2023-7171
Novel-Plus General
2.4
LOW
EPSS
0.1%
2023 CWE-79 1 PoC

A vulnerability was found in Novel-Plus up to 4.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file novel-admin/src/main/java/com/java2nb/novel/controller/FriendLinkController.java of the component Friendly Link Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The patch is named d6093d8182362422370d7eaf6c53afde9ee45215. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-2

CVE-2023-5789
707GR1 General
2.4
LOW
EPSS
0.1%
2023 CWE-79 1 PoC

A vulnerability classified as problematic has been found in Dragon Path 707GR1 up to 20231022. Affected is an unknown function of the component Ping Diagnostics. The manipulation of the argument Host Address with the input >><img/src/onerror=alert(1)> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-243594 is the identifier assigned to this vulnerability.

CVE-2023-1857
Online Computer and Laptop Store General
2.4
LOW
EPSS
0.3%
2023 CWE-79 1 PoC

A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/?page=product/manage_product&id=2. The manipulation of the argument Product Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224996.

CVE-2023-4624
bookstackapp/bookstack General
2.4
LOW
EPSS
0.5%
2023 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository bookstackapp/bookstack prior to v23.08.

CVE-2023-0966
Online Eyewear Shop General
2.4
LOW
EPSS
0.5%
2023 CWE-79 1 PoC

A vulnerability classified as problematic was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerability is an unknown functionality of the file admin/?page=orders/view_order. The manipulation of the argument id leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221635.

CVE-2023-2384
SRX5308 General
2.4
LOW
EPSS
0.1%
2023 CWE-79 1 PoC

A vulnerability was found in Netgear SRX5308 up to 4.3.5-3. It has been declared as problematic. This vulnerability affects unknown code of the file scgi-bin/platform.cgi?page=dmz_setup.htm of the component Web Management Interface. The manipulation of the argument dhcp.SecDnsIPByte2 leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-227662 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-1961
Online Computer and Laptop Store General
2.4
LOW
EPSS
0.3%
2023 CWE-79 1 PoC

A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/?page=system_info. The manipulation of the argument System Name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-225348.

CVE-2023-5585
Online Motorcycle Rental System General
2.4
LOW
EPSS
0.0%
2023 CWE-79 1 PoC

A vulnerability was found in SourceCodester Online Motorcycle Rental System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/?page=bike of the component Bike List. The manipulation of the argument Model with the input "><script>confirm (document.cookie)</script> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-242170 is the identifier assigned to this vulnerability.

CVE-2023-7160
Engineers Online Portal General
2.4
LOW
EPSS
0.1%
2023 CWE-79 1 PoC

A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Add Engineer Handler. The manipulation of the argument first name/last name with the input <script>alert(0)</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-249182 is the identifier assigned to this vulnerability.

CVE-2023-21450
One Hand Operation + General
2.3
LOW
EPSS
0.1%
2023 CWE-862 1 PoC

Missing Authorization vulnerability in One Hand Operation + prior to version 6.1.21 allows multi-users to access owner&#39;s widget without authorization via gesture setting.

CVE-2023-0859
Canon Office/Small Office Multifunction Printers and Laser Printers General
2.2
LOW
EPSS
0.1%
2023 CWE-1285 1 PoC

Arbitrary Files can be installed in the Setting Data Import function of Office / Small Office Multifunction Printers and Laser Printers(*). *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i firmware Ver.11.04 and earlier sold in Europe.

CVE-2023-21438
Samsung Mobile Devices General
2.1
LOW
EPSS
0.1%
2023 CWE-284 1 PoC

Improper logic in HomeScreen prior to SMR Feb-2023 Release 1 allows physical attacker to access App preview protected by Secure Folder.

CVE-2023-40353
Software Genérico General
2.0
LOW
EPSS
0.0%
2023 1 PoC

An issue was discovered in Exynos Mobile Processor 980 and 2100. An integer overflow at a buffer index can prevent the execution of requested services via a crafted application.

CVE-2023-37377
Software Genérico General
2.0
LOW
EPSS
0.0%
2023 1 PoC

An issue was discovered in Samsung Exynos Mobile Processor and Wearable Processor (Exynos 980, Exynos 850, Exynos 2100, and Exynos W920). Improper handling of length parameter inconsistency can cause incorrect packet filtering.

CVE-2023-5028
TEWA-800G General
2.0
LOW
EPSS
0.0%
2023 CWE-534 1 PoC

A vulnerability, which was classified as problematic, has been found in China Unicom TEWA-800G 4.16L.04_CT2015_Yueme. Affected by this issue is some unknown functionality. The manipulation leads to information exposure through debug log file. It is possible to launch the attack on the physical device. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. VDB-239870 is the identifier assigned to this vulnerability.

CVE-2023-40218
Software Genérico General
2.0
LOW
EPSS
0.0%
2023 1 PoC

An issue was discovered in the NPU kernel driver in Samsung Exynos Mobile Processor 9820, 980, 2100, 2200, 1280, and 1380. An integer overflow can bypass detection of error cases via a crafted application.

CVE-2023-20526
AMD Ryzen™ Threadripper™ 2000 Series Processors “Colfax” General
1.9
LOW
EPSS
0.1%
2023 3 PoCs

Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.

CVE-2023-48207
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.

CVE-2023-6253
Digital Guardian Agent General
N/A
UNKNOWN
EPSS
0.0%
2023 CWE-922 3 PoCs

A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file.