3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-46023
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL injection vulnerability in addTask.php in Code-Projects Simple Task List 1.0 allows attackers to obtain sensitive information via the 'status' parameter.

CVE-2023-33253
Software Genérico Web
N/A
UNKNOWN
EPSS
44.4%
2023 1 PoC

LabCollector 6.0 though 6.15 allows remote code execution. An authenticated remote low-privileged user can upload an executable PHP file and execute system commands. The vulnerability is in the message function, and is due to insufficient validation of the file (such as shell.jpg.php.shell) being sent.

CVE-2023-4311
Vrm 360 3D Model Viewer Web Windows
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

The Vrm 360 3D Model Viewer WordPress plugin through 1.2.1 is vulnerable to arbitrary file upload due to insufficient checks in a plugin shortcode.

CVE-2023-36159
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 3 PoCs

Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers to run arbitrary code via the First Name, Middle Name and Last Name fields on the Create User page.

CVE-2023-2256
Product Addons & Fields for WooCommerce Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
21.2%
2023 1 PoC

The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting.

CVE-2023-2470
Add to Feedly Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Add to Feedly WordPress plugin through 1.2.11 does not sanitize and escape its settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2023-2605
wpbrutalai Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

The wpbrutalai WordPress plugin before 2.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a logged in high privilege users such as admin.

CVE-2023-24279
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter of the API documentation dashboard.

CVE-2023-37201
Firefox Web
N/A
UNKNOWN
EPSS
0.8%
2023 1 PoC

An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.

CVE-2023-52257
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

LogoBee 0.2 allows updates.php?id= XSS.

CVE-2023-35810
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Second-Order PHP Object Injection vulnerability has been identified in the DocuSign module. By using crafted requests, custom PHP code can be injected and executed through the DocuSign module because of missing input validation. Admin user privileges are required to exploit this vulnerability. Editions other than Enterprise are also affected.

CVE-2023-39578
Software Genérico Web
N/A
UNKNOWN
EPSS
1.6%
2023 1 PoC

A stored cross-site scripting (XSS) vulnerability in the Create function of Zenario CMS v9.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Menu navigation text field.

CVE-2023-4970
PubyDoc Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The PubyDoc WordPress plugin through 2.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2023-41599
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.0%
2023 1 PoC

An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal.

CVE-2023-44796
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925 allows a remote attacker to escalate privileges via a crafted script to the _generaloptions_panel.php component.

CVE-2023-6268
JSON Content Importer Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The JSON Content Importer WordPress plugin before 1.5.4 does not sanitise and escape the tab parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-38836
Software Genérico Web
N/A
UNKNOWN
EPSS
88.3%
2023 2 PoCs

File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks.

CVE-2023-2329
WooCommerce Google Sheet Connector Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The WooCommerce Google Sheet Connector WordPress plugin before 1.3.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

CVE-2023-36139
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2023 2 PoCs

In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.

CVE-2023-6063
WP Fastest Cache Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.4%
2023 6 PoCs

The WP Fastest Cache WordPress plugin before 1.2.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.