3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-0076
Download Attachments Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Download Attachments WordPress plugin before 1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-39121
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
2.7%
2023 0 PoCs

emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.

CVE-2023-23162
Software Genérico Web Database
N/A
UNKNOWN
EPSS
3.3%
2023 1 PoC

Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php.

CVE-2023-46010
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.

CVE-2023-39062
Software Genérico Web
N/A
UNKNOWN
EPSS
35.5%
2023 1 PoC

Cross Site Scripting vulnerability in Spipu HTML2PDF before v.5.2.8 allows a remote attacker to execute arbitrary code via a crafted script to the forms.php.

CVE-2023-5605
URL Shortify Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The URL Shortify WordPress plugin before 1.7.9.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-1977
Booking Manager Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Booking Manager WordPress plugin before 2.0.29 does not validate URLs input in it's admin panel or in shortcodes for showing events from a remote .ics file, allowing an attacker with privileges as low as Subscriber to perform SSRF attacks on the sites internal network.

CVE-2023-2627
KiviCare Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The KiviCare WordPress plugin before 3.2.1 does not have proper CSRF and authorisation checks in various AJAX actions, allowing any authenticated users, such as subscriber to call them. Attacks include but are not limited to: Add arbitrary Clinic Admin/Doctors/etc and update plugin's settings

CVE-2023-44276
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.

CVE-2023-33561
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure passwords.

CVE-2023-43873
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Name filed in the Manage Menu.

CVE-2023-36127
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-28121
WooCommerce Payments WordPress Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.7%
2023 CWE-287 8 PoCs

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

CVE-2023-40618
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start versions 4, 5, 6, 7 as well as Visual Project Explorer 1.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'service' parameter in 'headstart_snapshot.php'.

CVE-2023-3219
EventON Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
74.0%
2023 2 PoCs

The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of the post.

CVE-2023-22974
Software Genérico Web Database
N/A
UNKNOWN
EPSS
4.5%
2023 1 PoC

A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controlling a connection to an attacker-controlled MySQL server.

CVE-2023-1208
HTTP Headers Web Windows
N/A
UNKNOWN
EPSS
3.7%
2023 1 PoC

This HTTP Headers WordPress plugin before 1.18.11 allows arbitrary data to be written to arbitrary files, leading to a Remote Code Execution vulnerability.

CVE-2023-33560
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in "cid" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3.

CVE-2023-2813
Aapna Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2023 1 PoC

All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite WordPress theme before 2.1, Cafe Bistro WordPress theme before 1.1.4, College WordPress theme before 1.5.1, Connections Reloaded WordPress theme through 3.1, Counterpoint WordPress theme through 1.8.1, Digitally WordPress theme through 1.0.8, Directory WordPress theme before 3.0.2, Drop

CVE-2023-5348
Product Catalog Mode For WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

The Product Catalog Mode For WooCommerce WordPress plugin before 5.0.3 does not properly authorize settings updates or escape settings values, leading to stored XSS by unauthenticated users.