3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-37682
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-jms/deductScores.php.

CVE-2023-42222
Software Genérico Web
N/A
UNKNOWN
EPSS
4.4%
2023 2 PoCs

WebCatalog before 49.0 is vulnerable to Incorrect Access Control. WebCatalog calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances.

CVE-2023-6272
tml-2fa Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts, which may allow an attacker to brute-force all possibilities, which shouldn't be too long, as the 2FA codes are 6 digits.

CVE-2023-39108
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
78.5%
2023 0 PoCs

rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Function of /classes/compareClass.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.

CVE-2023-3225
Float menu Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Float menu WordPress plugin before 5.0.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-2803
Ultimate Addons for Contact Form 7 Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Ultimate Addons for Contact Form 7 WordPress plugin before 3.1.29 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-45881
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

GibbonEdu Gibbon through version 25.0.0 allows /modules/Planner/resources_addQuick_ajaxProcess.php file upload with resultant XSS. The imageAsLinks parameter must be set to Y to return HTML code. The filename attribute of the bodyfile1 parameter is reflected in the response.

CVE-2023-5672
WP Mail Log Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file path parameters when attaching files to emails, leading to local file inclusion, and allowing an attacker to leak the contents of arbitrary files.

CVE-2023-37600
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Office Suite Premium Version v10.9.1.42602 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /api?path=profile.

CVE-2023-34581
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 3 PoCs

Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&id=2

CVE-2023-31852
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

Cudy LT400 1.13.4 is vulnerable to Cross Site Scripting (XSS) in cgi-bin/luci/admin/network/wireless/config via the iface parameter.

CVE-2023-37686
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Nurse Page in the Admin portal.

CVE-2023-47350
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in SwiftyEdit Content Management System prior to v1.2.0, allows remote attackers to escalate privileges via the user password update functionality.

CVE-2023-5952
Welcart e-Commerce Web Windows
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

The Welcart e-Commerce WordPress plugin before 2.9.5 unserializes user input from cookies, which could allow unautehtniacted users to perform PHP Object Injection when a suitable gadget is present on the blog

CVE-2023-37305
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

An issue was discovered in the ProofreadPage (aka Proofread Page) extension for MediaWiki through 1.39.3. In includes/Page/PageContentHandler.php and includes/Page/PageDisplayHandler.php, hidden users can be exposed via public interfaces.

CVE-2023-45992
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.6%
2023 3 PoCs

A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user of the admin management interface. A successful attack, combined with a certain admin activity, could allow the attacker to gain full admin privileges on the exploited system.

CVE-2023-38904
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

A Cross Site Scripting (XSS) vulnerability in Netlify CMS v.2.10.192 allows a remote attacker to execute arbitrary code via a crafted payload to the body parameter of the new post function.

CVE-2023-47322
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the Silverpeas application, the CSRF with execute making the attacker an administrator user in the application.

CVE-2023-37798
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A stored cross-site scripting (XSS) vulnerability in the new REDCap project creation function of Vanderbilt REDCap 13.1.35 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the project title parameter.

CVE-2023-5884
Word Balloon Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Word Balloon WordPress plugin before 4.20.3 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to trick a logged in user to delete arbitrary avatars by clicking a link.