3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-45277
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2023 2 PoCs

Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the buckets, freely navigate system directories, and read arbitrary files.

CVE-2023-0099
Simple URLs Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
70.1%
2023 3 PoCs

The Simple URLs WordPress plugin before 115 does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-39110
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
80.1%
2023 0 PoCs

rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPath.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.

CVE-2023-44846
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 2 PoCs

An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ notify.php component.

CVE-2023-2482
Responsive CSS EDITOR Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Responsive CSS EDITOR WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admin.

CVE-2023-5458
CITS Support svg, webp Media and TTF,OTF File Upload Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The CITS Support svg, webp Media and TTF,OTF File Upload WordPress plugin before 3.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2023-0873
Kanban Boards for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Kanban Boards for WordPress plugin before 2.5.21 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-27641
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.7%
2023 0 PoCs

The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XSS attacks via a crafted URL.

CVE-2023-45311
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.9%
2023 2 PoCs

fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adversary to execute arbitrary code if any JavaScript project (that depends on fsevents) distributes code that was obtained from that URL at a time when it was controlled by an adversary. NOTE: some sources feel that this means that no version is affected any longer, because the URL is not controlled by an adversary.

CVE-2023-0419
Shortcode for Font Awesome Web Windows
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The Shortcode for Font Awesome WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-40757
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

User enumeration is found in PHPJabbers Food Delivery Script v3.1. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-0063
WordPress Shortcodes Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The WordPress Shortcodes WordPress plugin through 1.6.36 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-38435
Apache Felix Healthcheck Webconsole Plugin Web
N/A
UNKNOWN
EPSS
1.4%
2023 CWE-79 1 PoC

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack. Upgrade to Apache Felix Healthcheck Webconsole Plugin 2.1.0 or higher.

CVE-2023-2877
Formidable Forms Web Windows
N/A
UNKNOWN
EPSS
70.0%
2023 2 PoCs

The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository onto the site, leading to Remote Code Execution.

CVE-2023-46025
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL Injection vulnerability in teacher-info.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to obtain sensitive information via the 'editid' parameter.

CVE-2023-31698
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trusted by the administrator to insert arbitrary content (users cannot create their own accounts through self-registration).

CVE-2023-2330
Caldera Forms Google Sheets Connector Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Caldera Forms Google Sheets Connector WordPress plugin before 1.3 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

CVE-2023-36314
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

There is a Cross Site Scripting (XSS) vulnerability in the value-text-o_sms_email_request_message parameters of index.php in PHPJabbers Callback Widget v1.0.

CVE-2023-46451
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Best Courier Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the change username field.

CVE-2023-29689
Software Genérico Web
N/A
UNKNOWN
EPSS
51.3%
2023 1 PoC

PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.