13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-26774
Software Genérico Web
7.5
HIGH
EPSS
0.6%
2023 3 PoCs

An issue found in Sales Tracker Management System v.1.0 allows a remote attacker to access sensitive information via sales.php component of the admin/reports endpoint.

CVE-2023-44487
🔥 KEV Software Genérico Web
7.5
HIGH
EPSS
94.4%
2023 22 PoCs

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

CVE-2023-6584
WP JobSearch Web Windows
7.5
HIGH
EPSS
0.3%
2023 1 PoC

The WP JobSearch WordPress plugin before 2.3.4 does not prevent attackers from logging-in as any users with the only knowledge of that user's email address.

CVE-2023-3071
tsolucio/corebos Web
7.5
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.

CVE-2023-6294
Popup Builder Web Windows
7.5
HIGH
EPSS
0.3%
2023 1 PoC

The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the administrator role to perform SSRF attack in Multisite WordPress configurations.

CVE-2023-52285
Software Genérico Web Database
7.5
HIGH
EPSS
0.1%
2023 1 PoC

ExamSys 9150244 allows SQL Injection via the /Support/action/Pages.php s_score2 parameter.

CVE-2023-23132
Software Genérico Web
7.5
HIGH
EPSS
0.3%
2023 1 PoC

Selfwealth iOS mobile App 3.3.1 is vulnerable to Sensitive key disclosure. The application reveals hardcoded API keys.

CVE-2023-41815
Pandora FMS Web
7.5
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). Malicious code could be executed in the File Manager section. This issue affects Pandora FMS: from 700 through 774.

CVE-2023-6113
WP STAGING WordPress Backup Plugin Web Windows
7.5
HIGH
EPSS
0.4%
2023 2 PoCs

The WP STAGING WordPress Backup Plugin before 3.1.3 and WP STAGING Pro WordPress Backup Plugin before 5.1.3 do not prevent visitors from leaking key information about ongoing backups processes, allowing unauthenticated attackers to download said backups later.

CVE-2023-7269
ArtPlacer Widget Web Windows
7.5
HIGH
EPSS
0.1%
2023 1 PoC

The ArtPlacer Widget WordPress plugin before 2.21.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2023-2180
KIWIZ Invoices Certification & PDF System Web Windows
7.5
HIGH
EPSS
0.6%
2023 1 PoC

The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unserialization (assuming they can upload a file on the server)

CVE-2023-52355
Software Genérico Web
7.5
HIGH
EPSS
1.3%
2023 CWE-787 1 PoC

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

CVE-2023-26130
yhirose/cpp-httplib Web
7.5
HIGH
EPSS
0.2%
2023 CWE-93 2 PoCs

Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type header in the HTTP .Patch, .Post, .Put and .Delete requests. This can lead to logical errors and other misbehaviors. **Note:** This issue is present due to an incomplete fix for [CVE-2020-11709](https://security.snyk.io/vuln/SNYK-UNMANAGED-YHIROSECPPHTTPLIB-2366507).

CVE-2023-0331
Correos Oficial Web Windows
7.5
HIGH
EPSS
0.5%
2023 1 PoC

The Correos Oficial WordPress plugin through 1.2.0.2 does not have an authorization check user input validation when generating a file path, allowing unauthenticated attackers to download arbitrary files from the server.

CVE-2023-21852
Learning Management Web Database
7.5
HIGH
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Setup). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Learning Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Learning Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).

CVE-2023-1405
Formidable Forms Web Windows
7.5
HIGH
EPSS
0.3%
2023 2 PoCs

The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.

CVE-2023-39375
SiberianCMS Web
7.5
HIGH
EPSS
0.1%
2023 CWE-274 1 PoC

SiberianCMS - CWE-274: Improper Handling of Insufficient Privileges

CVE-2023-5454
Templately Web Windows
7.5
HIGH
EPSS
0.8%
2023 1 PoC

The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, allowing unauthenticated users to delete arbitrary posts.

CVE-2023-34105
srs Web ⚡ nuclei
7.5
HIGH
EPSS
84.8%
2023 CWE-78 0 PoCs

SRS is a real-time video server supporting RTMP, WebRTC, HLS, HTTP-FLV, SRT, MPEG-DASH, and GB28181. Prior to versions 5.0.157, 5.0-b1, and 6.0.48, SRS's `api-server` server is vulnerable to a drive-by command injection. An attacker may send a request to the `/api/v1/snapshots` endpoint containing any commands to be executed as part of the body of the POST request. This issue may lead to Remote Code Execution (RCE). Versions 5.0.157, 5.0-b1, and 6.0.48 contain a fix.

CVE-2023-5003
Active Directory Integration / LDAP Integration Web Windows ⚡ nuclei
7.5
HIGH
EPSS
77.8%
2023 1 PoC

The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.