5623 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-21851
Marketing Web Database
7.5
HIGH
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Marketing accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).

CVE-2023-38950
🔥 KEV Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
83.4%
2023 0 PoCs

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.

CVE-2023-6266
BackupBliss – Backup & Migration with Free Cloud Storage Web Cloud Windows ⚡ nuclei
7.5
HIGH
EPSS
26.8%
2023 CWE-200 0 PoCs

The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP case of the handle_downloading function in all versions up to, and including, 1.3.6. This makes it possible for unauthenticated attackers to download back-up files which can contain sensitive information such as user passwords, PII, database credentials, and much more.

CVE-2023-38039
curl Web
7.5
HIGH
EPSS
12.3%
2023 1 PoC

When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory.

CVE-2023-5133
user-activity-log-pro Web Windows
7.5
HIGH
EPSS
0.1%
2023 1 PoC

This user-activity-log-pro WordPress plugin before 2.3.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to hide the source of malicious traffic.

CVE-2023-2916
InfiniteWP Client Web Windows
7.5
HIGH
EPSS
29.5%
2023 CWE-200 1 PoC

The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including configuration. It can only be exploited if the plugin has not been configured yet. If combined with another arbitrary plugin installation and activation vulnerability, it may be possible to connect a site to InfiniteWP which would make remote management possible and allow for elevation of privileges.

CVE-2023-52356
Software Genérico Web
7.5
HIGH
EPSS
0.7%
2023 CWE-122 5 PoCs

A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service.

CVE-2023-49799
nuxt-api-party Web
7.5
HIGH
EPSS
1.4%
2023 CWE-918 1 PoC

`nuxt-api-party` is an open source module to proxy API requests. nuxt-api-party attempts to check if the user has passed an absolute URL to prevent the aforementioned attack. This has been recently changed to use the regular expression `^https?://`, however this regular expression can be bypassed by an absolute URL with leading whitespace. For example `\nhttps://whatever.com` which has a leading newline. According to the fetch specification, before a fetch is made the URL is normalized. "To normalize a byte sequence potentialValue, remove any leading and trailing HTTP whitespace bytes from pot

CVE-2023-25156
kiwi Web
7.5
HIGH
EPSS
0.7%
2023 CWE-770 1 PoC

Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt brute-force attacks against the login page. Users should upgrade to v12.0 or later to receive a patch. As a workaround, users may install and configure a rate-limiting proxy in front of Kiwi TCMS.

CVE-2023-0812
Active Directory Integration / LDAP Integration Web Windows
7.5
HIGH
EPSS
0.4%
2023 1 PoC

The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure.

CVE-2023-31478
Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
82.6%
2023 0 PoCs

An issue was discovered on GL.iNet devices before 3.216. An API endpoint reveals information about the Wi-Fi configuration, including the SSID and key.

CVE-2023-51770
Apache DolphinScheduler Web
7.5
HIGH
EPSS
1.3%
2023 CWE-94 3 PoCs

Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue.

CVE-2023-38844
Software Genérico Web Database
7.5
HIGH
EPSS
0.2%
2023 1 PoC

SQL injection vulnerability in PMB v.7.4.7 and earlier allows a remote attacker to execute arbitrary code via the thesaurus parameter in export_skos.php.

CVE-2023-3525
Getnet Argentina para Woocommerce Web Windows
7.5
HIGH
EPSS
0.1%
2023 1 PoC

The Getnet Argentina para Woocommerce plugin for WordPress is vulnerable to authorization bypass due to missing validation on the 'webhook' function in versions up to, and including, 0.0.4. This makes it possible for unauthenticated attackers to set their payment status to 'APPROVED' without payment.

CVE-2023-49988
Software Genérico Web Database
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the npss parameter at rooms.php.

CVE-2023-42358
Software Genérico Web
7.5
HIGH
EPSS
0.5%
2023 1 PoC

An issue was discovered in O-RAN Software Community ric-plt-e2mgr in the G-Release environment, allows remote attackers to cause a denial of service (DoS) via a crafted request to the E2Manager API component.

CVE-2023-30112
Software Genérico Web Database
7.5
HIGH
EPSS
0.3%
2023 1 PoC

Medicine Tracker System in PHP 1.0.0 is vulnerable to SQL Injection.

CVE-2023-42581
Galaxy Store Web
7.5
HIGH
EPSS
0.3%
2023 1 PoC

Improper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to access data.

CVE-2023-30198
Software Genérico Web
7.5
HIGH
EPSS
5.7%
2023 1 PoC

Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download.php.

CVE-2023-21996
WebLogic Server Web Database
7.5
HIGH
EPSS
0.9%
2023 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).