3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-6114
Duplicator Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
61.3%
2023 2 PoCs

The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup-pro/tmp` directory in the Pro version), which temporarily stores files containing sensitive data. When directory listing is enabled in the web server, this allows unauthenticated attackers to discover and access these sensitive files, which include a full database dump and a zip archive of the site.

CVE-2023-27207
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php.

CVE-2023-46584
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.8%
2023 1 PoC

SQL Injection vulnerability in PHPGurukul Nipah virus (NiV) " Testing Management System v.1.0 allows a remote attacker to escalate privileges via a crafted request to the new-user-testing.php endpoint.

CVE-2023-37786
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in Geeklog v2.2.2 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Mail Settings[backend], Mail Settings[host], Mail Settings[port] and Mail Settings[auth] parameters of the /admin/configuration.php.

CVE-2023-31299
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Barcode field of a container.

CVE-2023-37772
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Online Shopping Portal Project v3.1 was discovered to contain a SQL injection vulnerability via the Email parameter at /shopping/login.php.

CVE-2023-48172
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A Cross Site Scripting (XSS) vulnerability in Shuttle Booking Software 2.0 allows a remote attacker to inject JavaScript via the name, description, title, or address parameter to index.php.

CVE-2023-37625
Software Genérico Web
N/A
UNKNOWN
EPSS
1.9%
2023 1 PoC

A stored cross-site scripting (XSS) vulnerability in Netbox v3.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Link templates.

CVE-2023-24788
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.9%
2023 3 PoCs

NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/sales/customer_delivery.php.

CVE-2023-36126
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Appointment Scheduler v3.0

CVE-2023-48827
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Time Slots Booking Calendar 4.0 is vulnerable to Multiple HTML Injection issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.

CVE-2023-43346
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Backend - Dashboard parameter in the Languages Menu component.

CVE-2023-3510
FTP Access Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The FTP Access WordPress plugin through 1.0 does not have authorisation and CSRF checks when updating its settings and is missing sanitisation as well as escaping in them, allowing any authenticated users, such as subscriber to update them with XSS payloads, which will be triggered when an admin will view the settings of the plugin. The attack could also be perform via CSRF against any authenticated user.

CVE-2023-5173
Firefox Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a local unprivileged webpage), leading to an out-of-bounds write to privileged process memory. *This bug only affects Firefox if a non-standard preference allowing non-HTTPS Alternate Services (`network.http.altsvc.oe`) is enabled.* This vulnerability affects Firefox < 118.

CVE-2023-44275
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

OPNsense before 23.7.5 allows XSS via the index.php column_count parameter to the Lobby Dashboard.

CVE-2023-27211
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A cross-site scripting (XSS) vulnerability in /admin/navbar.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page parameter.

CVE-2023-44760
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS v.9.2.1 allow an attacker to execute arbitrary code via a crafted script to the Header and Footer Tracking Codes of the SEO & Statistics. NOTE: the vendor disputes this because these header/footer changes can only be made by an admin, and allowing an admin to place JavaScript there is an intentional customization feature. Also, the exploitation method claimed by "sromanhu" does not provide any access to a Concrete CMS session, because the Concrete CMS session cookie is configured as HttpOnly.

CVE-2023-5610
Seraphinite Accelerator Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Seraphinite Accelerator WordPress plugin before 2.2.29 does not validate the URL to redirect any authenticated user to, leading to an arbitrary redirect

CVE-2023-43345
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Content - Name parameter in the Pages Menu component.

CVE-2023-2628
KiviCare Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The KiviCare WordPress plugin before 3.2.1 does not have CSRF checks (either flawed or missing completely) in various AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. This includes, but is not limited to: Delete arbitrary appointments/medical records/etc, create/update various users (patients, doctors etc)