3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-4549
DoLogin Security Web Windows
N/A
UNKNOWN
EPSS
1.3%
2023 2 PoCs

The DoLogin Security WordPress plugin before 3.7 does not properly sanitize IP addresses coming from the X-Forwarded-For header, which can be used by attackers to conduct Stored XSS attacks via WordPress' login form.

CVE-2023-44812
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
36.7%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a crafted payload to the admin_redirect_url parameter of the user login function.

CVE-2023-39712
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 3 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Put section.

CVE-2023-46383
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

LOYTEC electronics GmbH LINX Configurator (all versions) uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the password and gain full control of Loytec device configuration.

CVE-2023-38830
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

An information leak in PHPJabbers Yacht Listing Script v1.0 allows attackers to export clients' credit card numbers from the Reservations module.

CVE-2023-23315
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The PrestaShop e-commerce platform module stripejs contains a Blind SQL injection vulnerability up to version 4.5.5. The method `stripejsValidationModuleFrontController::initContent()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

CVE-2023-31719
Software Genérico Web Database
N/A
UNKNOWN
EPSS
65.5%
2023 2 PoCs

FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.

CVE-2023-43906
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Xolo CMS v0.11 was discovered to contain a reflected cross-site scripting (XSS) vulnerability.

CVE-2023-41614
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A stored cross-site scripting (XSS) vulnerability in the Add Animal Details function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description of Animal parameter.

CVE-2023-5209
WordPress Online Booking and Scheduling Plugin Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-2223
Login rebuilder Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

The Login rebuilder WordPress plugin before 2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-40754
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 2 PoCs

In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.

CVE-2023-46288
Apache Airflow Web
N/A
UNKNOWN
EPSS
0.6%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.4.0 to 2.7.0. Sensitive configuration information has been exposed to authenticated users with the ability to read configuration via Airflow REST API for configuration even when the expose_config option is set to non-sensitive-only. The expose_config option is False by default. It is recommended to upgrade to a version that is not affected if you set expose_config to non-sensitive-only configuration. This is a different error than CVE-2023-45348 which allows auth

CVE-2023-46382
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) use cleartext HTTP for login.

CVE-2023-36317
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in sourcecodester Student Study Center Desk Management System 1.0 allows attackers to run arbitrary code via crafted GET request to web application URL.

CVE-2023-37191
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2023 2 PoCs

A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Group and Description parameters.

CVE-2023-42270
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Grocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF).

CVE-2023-48208
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php.

CVE-2023-23301
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The `news` MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not extending past the end of the expected sections. A malicious CIQ application could craft a string that starts near the end of a section, and whose length extends past its end. Upon loading the string, the GarminOS TVM component may read out-of-bounds memory.

CVE-2023-6295
SiteOrigin Widgets Bundle Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The SiteOrigin Widgets Bundle WordPress plugin before 1.51.0 does not validate user input before using it to generate paths passed to include function/s, allowing users with the administrator role to perform LFI attacks in the context of Multisite WordPress sites.