3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-6210
Firefox Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

When an https: web page created a pop-up from a "javascript:" URL, that pop-up was incorrectly allowed to load blockable content such as iframes from insecure http: URLs This vulnerability affects Firefox < 120.

CVE-2023-39677
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
77.2%
2023 1 PoC

MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php.

CVE-2023-38965
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.

CVE-2023-38999
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A Cross-Site Request Forgery (CSRF) in the System Halt API (/system/halt) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

CVE-2023-47464
Software Genérico Web
N/A
UNKNOWN
EPSS
70.1%
2023 1 PoC

Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via the upload API function.

CVE-2023-38191
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

An issue was discovered in SuperWebMailer 9.00.0.01710. It allows spamtest_external.php XSS via a crafted filename.

CVE-2023-26325
ReviewX WordPress Plugin Web Database Windows
N/A
UNKNOWN
EPSS
1.4%
2023 1 PoC

The 'rx_export_review' action in the ReviewX WordPress Plugin, is affected by an authenticated SQL injection vulnerability in the 'filterValue' and 'selectedColumns' parameters.

CVE-2023-34212
Apache NiFi Web
N/A
UNKNOWN
EPSS
0.8%
2023 CWE-502 1 PoC

The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 allow an authenticated and authorized user to configure URL and library properties that enable deserialization of untrusted data from a remote location. The resolution validates the JNDI URL and restricts locations to a set of allowed schemes. You are recommended to upgrade to version 1.22.0 or later which fixes this issue.

CVE-2023-5108
Easy Newsletter Signups Web Database Windows
N/A
UNKNOWN
EPSS
1.3%
2023 1 PoC

The Easy Newsletter Signups WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2023-4642
kk Star Ratings Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The kk Star Ratings WordPress plugin before 5.4.6 does not implement atomic operations, allowing one user vote multiple times on a poll due to a Race Condition.

CVE-2023-27204
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.

CVE-2023-35811
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. Two SQL Injection vectors have been identified in the REST API. By using crafted requests, custom SQL code can be injected through the REST API because of missing input validation. Regular user privileges can use used for exploitation. Editions other than Enterprise are also affected.

CVE-2023-36936
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

Cross-Site Scripting (XSS) vulnerability in PHPGurukul Online Security Guards Hiring System using PHP and MySQL 1.0 allows attackers to execute arbitrary code via a crafted payload to the search booking box.

CVE-2023-45471
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

The QAD Search Server is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to, and including, 1.0.0.315 due to insufficient checks on indexes. This makes it possible for unauthenticated attackers to create a new index and inject a malicious web script into its name, that will execute whenever a user accesses the search page.

CVE-2023-43355
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the password and password again parameters in the My Preferences - Add user component.

CVE-2023-27225
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in User Registration & Login and User Management System with Admin Panel v3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the first and last name field.

CVE-2023-42470
Software Genérico Web
N/A
UNKNOWN
EPSS
10.6%
2023 1 PoC

The Imou Life com.mm.android.smartlifeiot application through 6.8.0 for Android allows Remote Code Execution via a crafted intent to an exported component. This relates to the com.mm.android.easy4ip.MainActivity activity. JavaScript execution is enabled in the WebView, and direct web content loading occurs.

CVE-2023-2711
Ultimate Product Catalog Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Ultimate Product Catalog WordPress plugin before 5.2.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-43319
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

Cross Site Scripting (XSS) vulnerability in the Sign-In page of IceWarp WebClient 10.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter.

CVE-2023-0377
Scriptless Social Sharing Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Scriptless Social Sharing WordPress plugin before 3.2.2 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.