3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-43187
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.7%
2023 0 PoCs

A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests.

CVE-2023-5611
Seraphinite Accelerator Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Seraphinite Accelerator WordPress plugin before 2.20.32 does not have authorisation and CSRF checks when resetting and importing its settings, allowing unauthenticated users to reset them

CVE-2023-26913
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

EVOLUCARE ECSIMAGING (aka ECS Imaging) < 6.21.5 is vulnerable to Cross Site Scripting (XSS) via new_movie. php.

CVE-2023-38876
Software Genérico Web
N/A
UNKNOWN
EPSS
7.6%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'selector' parameter in '/reset-password'.

CVE-2023-5906
Job Manager & Career Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Job Manager & Career WordPress plugin before 1.4.4 contains a vulnerability in the Directory Listings system, which allows an unauthorized user to view and download private files of other users. This vulnerability poses a serious security threat because it allows an attacker to gain access to confidential data and files of other users without their permission.

CVE-2023-39000
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the component /ui/diagnostics/log/core/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to inject arbitrary JavaScript via the URL path.

CVE-2023-3650
Bubble Menu Web Windows
N/A
UNKNOWN
EPSS
1.8%
2023 1 PoC

The Bubble Menu WordPress plugin before 3.0.5 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVE-2023-43357
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the Manage Shortcuts component.

CVE-2023-21522
AtHoc Web
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

A Reflected Cross-site Scripting (XSS) vulnerability in the Management Console (Reports) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially control a script that is executed in the victim's browser then they can execute script commands in the context of the affected user account. 

CVE-2023-38888
Software Genérico Web Database
N/A
UNKNOWN
EPSS
5.0%
2023 1 PoC

Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.

CVE-2023-2635
Call Now Accessibility Button Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Call Now Accessibility Button WordPress plugin before 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-38434
Software Genérico Web
N/A
UNKNOWN
EPSS
1.8%
2023 1 PoC

xHTTP 72f812d has a double free in close_connection in xhttp.c via a malformed HTTP request method.

CVE-2023-0844
Namaste! LMS Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Namaste! LMS WordPress plugin before 2.6 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-5653
WassUp Real Time Analytics Web Windows
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

The WassUp Real Time Analytics WordPress plugin through 1.9.4.5 does not escape IP address provided via some headers before outputting them back in an admin page, allowing unauthenticated users to perform Stored XSS attacks against logged in admins

CVE-2023-41616
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

A reflected cross-site scripting (XSS) vulnerability in the Search Student function of Student Management System v1.2.3 and before allows attackers to execute arbitrary Javascript in the context of a victim user's browser via a crafted payload.

CVE-2023-3179
POST SMTP Mailer Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged in users with the manage_postman_smtp capability resend an email to an arbitrary address (for example a password reset email could be resent to an attacker controlled email, and allow them to take over an account).

CVE-2023-2623
KiviCare Web Windows
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user data, allowing low privilege users such as subscriber to retrieve sensitive information such as the user email and hashed password of other users

CVE-2023-37596
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2023 2 PoCs

Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via a crafted script to the deleteuser function.

CVE-2023-44769
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2023 2 PoCs

A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted script to the Spare aliases from Alias.

CVE-2023-31853
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Cudy LT400 1.13.4 is vulnerable Cross Site Scripting (XSS) in /cgi-bin/luci/admin/network/bandwidth via the icon parameter.