3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-37630
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2023 2 PoCs

Online Piggery Management System 1.0 is vulnerable to Cross Site Scripting (XSS). An unauthenticated user can POST JavaScript code to "manage-breed.php" resulting in Persistent XSS.

CVE-2023-46582
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary SQL commands via the id paramter in the deleteProduct.php component.

CVE-2023-5939
rtMedia for WordPress, BuddyPress and bbPress Web Windows
N/A
UNKNOWN
EPSS
3.7%
2023 1 PoC

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 loads the contents of the import file in an unsafe manner, leading to remote code execution by privileged users.

CVE-2023-2606
WP Brutal AI Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WP Brutal AI WordPress plugin before 2.06 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-5210
AMP+ Plus Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The AMP+ Plus WordPress plugin through 3.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-26326
BuddyForms WordPress Plugin Web Windows
N/A
UNKNOWN
EPSS
45.0%
2023 3 PoCs

The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present.

CVE-2023-5799
WP Hotel Booking Web Windows
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing Contributor and above roles to delete posts that do no belong to them

CVE-2023-36306
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
5.3%
2023 1 PoC

A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the asktheoracle.php, details.php, index.php, search.php, export.php, reports.php, and statistics.php components.

CVE-2023-35793
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

An issue was discovered in Cassia Access Controller 2.1.1.2303271039. Establishing a web SSH session to gateways is vulnerable to Cross Site Request Forgery (CSRF) attacks.

CVE-2023-39676
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
6.1%
2023 1 PoC

FieldPopupNewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback parameter at ajax.php.

CVE-2023-2359
Slider Revolution Web Windows
N/A
UNKNOWN
EPSS
6.3%
2023 2 PoCs

The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.

CVE-2023-28660
Events Made Easy WordPress Plugin Web Database Windows
N/A
UNKNOWN
EPSS
1.1%
2023 1 PoC

The Events Made Easy WordPress Plugin, version <= 2.3.14 is affected by an authenticated SQL injection vulnerability in the 'search_name' parameter in the eme_recurrences_list action.

CVE-2023-34830
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2023 2 PoCs

i-doit Open v24 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the timeout parameter on the login page.

CVE-2023-43325
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
19.7%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the data[redirect_url] parameter of mooSocial v3.1.8 allows attackers to steal user's session cookies and impersonate their account via a crafted URL.

CVE-2023-38911
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A Cross-Site Scripting (XSS) vulnerability in CSZ CMS 1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Gallery parameter in the YouTube URL fields.

CVE-2023-33336
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

Reflected cross site scripting (XSS) vulnerability was discovered in Sophos Web Appliance v4.3.9.1 that allows for arbitrary code to be inputted via the double quotes.

CVE-2023-36211
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Barebones CMS v2.0.2 is vulnerable to Stored Cross-Site Scripting (XSS) when an authenticated user interacts with certain features on the admin panel.

CVE-2023-41642
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
17.0%
2023 1 PoC

Multiple reflected cross-site scripting (XSS) vulnerabilities in the ErroreNonGestito.aspx component of GruppoSCAI RealGimm 1.1.37p38 allow attackers to execute arbitrary Javascript in the context of a victim user's browser via a crafted payload injected into the VIEWSTATE parameter.

CVE-2023-3356
Subscribers Text Counter Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Subscribers Text Counter WordPress plugin before 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

CVE-2023-5509
Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The myStickymenu WordPress plugin before 2.6.5 does not adequately authorize some ajax calls, allowing any logged-in user to perform the actions.