5623 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-22884
Apache Airflow Web Database
9.8
CRITICAL
EPSS
76.3%
2023 CWE-77 1 PoC

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Airflow MySQL Provider.This issue affects Apache Airflow: before 2.5.1; Apache Airflow MySQL Provider: before 4.0.0.

CVE-2023-23488
Paid Memberships Pro WordPress Plugin Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
84.2%
2023 5 PoCs

The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route.

CVE-2023-22894
Software Genérico Web
9.8
CRITICAL
EPSS
16.6%
2023 4 PoCs

Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The attacker can filter users by columns that contain sensitive information and infer a value from API responses. If the attacker has super admin access, then this can be exploited to discover the password hash and password reset token of all users. If the attacker has admin panel access to an account with permission to access the username and email of API users with a lower privileged role (e.g., Editor or Author), then this can be exploited to discover sen

CVE-2023-48901
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.7%
2023 1 PoC

A SQL injection vulnerability in tramyardg Autoexpress version 1.3.0, allows remote unauthenticated attackers to execute arbitrary SQL commands via the parameter "id" within the getPhotosByCarId function call in details.php.

CVE-2023-2982
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
70.1%
2023 CWE-288 5 PoCs

The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on the user being supplied during a login validated through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they know the email address associated with that user. This was partially patched in version 7.6.4 and fully patched in version 7.6.5.

CVE-2023-4521
Import XML and RSS Feeds Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
92.7%
2023 2 PoCs

The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue (https://wpscan.com/vulnerability/d4220025-2272-4d5f-9703-4b2ac4a51c42) and not deleting the created files when releasing the new version.

CVE-2023-51828
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.8%
2023 1 PoC

A SQL Injection vulnerability in /admin/convert/export.class.php in PMB 7.4.7 and earlier versions allows remote unauthenticated attackers to execute arbitrary SQL commands via the query parameter in get_next_notice function.

CVE-2023-47253
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
93.9%
2023 4 PoCs

Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridValoresPopHidden parameter.

CVE-2023-37777
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

A SQL injection vulnerability exists in Synnefo Internet Management Software (IMS) version 2023 and earlier. This vulnerability occurs due to improper input validation in a specific API endpoint parameter allowing an attacker to manipulate SQL queries via crafted input. Successful exploitation could lead to unauthorized access to database records with DB administrator privileges which can be leveraged to escalate privileges further and execute arbitrary OS commands.

CVE-2023-30150
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
49.3%
2023 1 PoC

PrestaShop leocustomajax 1.0 and 1.0.0 are vulnerable to SQL Injection via modules/leocustomajax/leoajax.php.

CVE-2023-3197
MStore API – Create Native Android & iOS Apps On The Cloud Web Database Cloud Windows ⚡ nuclei
9.8
CRITICAL
EPSS
32.4%
2023 CWE-89 0 PoCs

The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2023-48802
Software Genérico Web
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

CVE-2023-33246
🔥 KEV Apache RocketMQ Web
9.8
CRITICAL
EPSS
94.4%
2023 CWE-94 23 PoCs

For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content.  To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using R

CVE-2023-28662
Gift Cards (Gift Vouchers and Packages) WordPress Plugin Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
74.3%
2023 1 PoC

The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action.

CVE-2023-1730
SupportCandy Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
81.8%
2023 1 PoC

The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks

CVE-2023-41503
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

Student Enrollment In PHP v1.0 was discovered to contain a SQL injection vulnerability via the Login function.

CVE-2023-30803
Net-Gen Application Firewall Web Networking
9.8
CRITICAL
EPSS
1.4%
2023 CWE-290 1 PoC

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can bypass authentication and access administrative functionality by sending HTTP requests using a crafted Y-forwarded-for header.

CVE-2023-4596
Forminator Forms – Contact Form, Payment Form & Custom Form Builder Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
90.8%
2023 CWE-434 5 PoCs

The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and including, 1.24.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2023-41505
Software Genérico Web
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

An arbitrary file upload vulnerability in the Add Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

CVE-2023-49606
Tinyproxy Web
9.8
CRITICAL
EPSS
74.2%
2023 CWE-416 3 PoCs

A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of previously freed memory, which leads to memory corruption and could lead to remote code execution. An attacker needs to make an unauthenticated HTTP request to trigger this vulnerability.