5623 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-6623
Essential Blocks Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
88.1%
2023 2 PoCs

The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may lead to Local File Inclusion attacks.

CVE-2023-49109
Apache DolphinScheduler Web
9.8
CRITICAL
EPSS
7.1%
2023 CWE-94 1 PoC

Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue.

CVE-2023-29631
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

PrestaShop jmsslider 1.6.0 is vulnerable to Incorrect Access Control via ajax_jmsslider.php.

CVE-2023-27638
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
39.0%
2023 1 PoC

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised tshirtecommerce_design_cart_id GET parameter in order to exploit an insecure parameter in the functions hookActionCartSave and updateCustomizationTable, which could lead to a SQL injection. This is exploited in the wild in March 2023.

CVE-2023-34747
Software Genérico Web
9.8
CRITICAL
EPSS
29.0%
2023 1 PoC

File upload vulnerability in ujcms 6.0.2 via /api/backend/core/web-file-upload/upload.

CVE-2023-47246
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2023 3 PoCs

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

CVE-2023-2734
MStore API – Create Native Android & iOS Apps On The Cloud Web Cloud Windows ⚡ nuclei
9.8
CRITICAL
EPSS
63.1%
2023 CWE-288 0 PoCs

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart sync from mobile REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.

CVE-2023-50030
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

In the module "Jms Setting" (jmssetting) from Joommasters for PrestaShop, a guest can perform SQL injection in versions <= 1.1.0. The method `JmsSetting::getSecondImgs()` has a sensitive SQL call that can be executed with a trivial http call and exploited to forge a blind SQL injection.

CVE-2023-49547
Software Genérico Web Database
9.8
CRITICAL
EPSS
7.6%
2023 2 PoCs

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login.

CVE-2023-6989
Shield: Blocks Bots, Protects Users, and Prevents Security Breaches Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
65.8%
2023 CWE-98 0 PoCs

The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 18.5.9 via the render_action_template parameter. This makes it possible for unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

CVE-2023-0600
WP Visitor Statistics (Real Time Traffic) Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
77.4%
2023 1 PoC

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.

CVE-2023-0037
10Web Map Builder for Google Maps Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
65.6%
2023 1 PoC

The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2023-29919
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
91.9%
2023 2 PoCs

SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted.

CVE-2023-46012
Software Genérico Web
9.8
CRITICAL
EPSS
34.6%
2023 2 PoCs

Buffer Overflow vulnerability LINKSYS EA7500 3.0.1.207964 allows a remote attacker to execute arbitrary code via an HTTP request to the IGD UPnP.

CVE-2023-23607
Dasherr Web
9.8
CRITICAL
EPSS
4.4%
2023 CWE-434 2 PoCs

erohtar/Dasherr is a dashboard for self-hosted services. In affected versions unrestricted file upload allows any unauthenticated user to execute arbitrary code on the server. The file /www/include/filesave.php allows for any file to uploaded to anywhere. If an attacker uploads a php file they can execute code on the server. This issue has been addressed in version 1.05.00. Users are advised to upgrade. There are no known workarounds for this issue.

CVE-2023-5877
affiliate-toolkit Web Windows
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, including RFC1918 private addresses, leading to a Server Side Request Forgery (SSRF) issue.

CVE-2023-23306
Software Genérico Web
9.8
CRITICAL
EPSS
0.7%
2023 1 PoC

The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnreability, which can result in an out-of-bounds write operation. A malicious application could create a specially crafted `Toybox.Ant.BurstPayload` object, call its `add` method, override arbitrary memory and hijack the execution of the device's firmware.

CVE-2023-36845
🔥 KEV Junos OS Web Networking ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2023 CWE-473 27 PoCs

A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request which sets the variable PHPRC an attacker is able to modify the PHP execution environment allowing the injection und execution of code. This issue affects Juniper Networks Junos OS on EX Series and SRX Series: * All versions prior to 20.4R3-S9; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S7; * 21.3 versions prior to 21.3R3-S5; *

CVE-2023-50919
Software Genérico Web
9.8
CRITICAL
EPSS
52.3%
2023 1 PoC

An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.

CVE-2023-37582
Apache RocketMQ Web
9.8
CRITICAL
EPSS
94.0%
2023 CWE-94 3 PoCs

The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1. When NameServer address are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function on the NameServer component to execute commands as the system users that RocketMQ is running as. It is recommended for users to upgrade their NameServer version to 5.1.2 or above for RocketMQ 5.x or 4.9.7 or above for RocketMQ 4.x to prevent these attacks.