3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-48811
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution vulnerability.

CVE-2023-44763
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cross-Site Scripting (XSS). NOTE: the vendor's position is that a customer is supposed to know that "pdf" should be excluded from the allowed file types, even though pdf is one of the allowed file types in the default configuration.

CVE-2023-49070
Apache OFBiz Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2023 CWE-94 7 PoCs

Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Users are recommended to upgrade to version 18.12.10

CVE-2023-2296
Loginizer Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Loginizer WordPress plugin before 1.7.9 does not escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-40752
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.

CVE-2023-36310
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

There is a Cross Site Scripting (XSS) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0.

CVE-2023-0588
Catalyst Connect Zoho CRM Client Portal Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Catalyst Connect Zoho CRM Client Portal WordPress plugin before 2.1.0 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admin.

CVE-2023-37683
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Profile Page of the Admin.

CVE-2023-36256
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

The Online Examination System Project 1.0 version is vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker can craft a malicious link that, when clicked by an admin user, will delete a user account from the database without the admin's consent. The email of the user to be deleted is passed as a parameter in the URL, which can be manipulated by the attacker. This could result in a loss of data.

CVE-2023-43875
Software Genérico Web
N/A
UNKNOWN
EPSS
2.6%
2023 2 PoCs

Multiple Cross-Site Scripting (XSS) vulnerabilities in installation of Subrion CMS v.4.2.1 allows a local attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost, dbname, dbuser, adminusername and adminemail.

CVE-2023-33564
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3.

CVE-2023-2718
Contact Form Email Web Windows
N/A
UNKNOWN
EPSS
0.5%
2023 2 PoCs

The Contact Form Email WordPress plugin before 1.3.38 does not escape submitted values before displaying them in the HTML, leading to a Stored XSS vulnerability.

CVE-2023-0489
SlideOnline Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The SlideOnline WordPress plugin through 1.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0538
Campaign URL Builder Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Campaign URL Builder WordPress plugin before 1.8.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-2122
Image Optimizer by 10web Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
17.8%
2023 1 PoC

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter before rendering it in the plugin admin panel, leading to a reflected Cross-Site Scripting vulnerability, allowing an attacker to trick a logged in admin to execute arbitrary javascript by clicking a link.

CVE-2023-43263
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2023 2 PoCs

A Cross-site scripting (XSS) vulnerability in Froala Editor v.4.1.1 allows attackers to execute arbitrary code via the Markdown component.

CVE-2023-50070
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_ticket via department_id, customer_id, and subject.

CVE-2023-5609
Seraphinite Accelerator Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Seraphinite Accelerator WordPress plugin before 2.2.29 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-0165
Cost Calculator Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Cost Calculator WordPress plugin through 1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0231
ShopLentor Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The ShopLentor WordPress plugin before 2.5.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.