3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-6077
Slider Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Slider WordPress plugin before 3.5.12 does not ensure that posts to be accessed via an AJAX action are slides and can be viewed by the user making the request, allowing any authenticated users, such as subscriber to access the content arbitrary post such as private, draft and password protected

CVE-2023-39600
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.7%
2023 2 PoCs

IceWarp 11.4.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the color parameter.

CVE-2023-3076
MStore API Web Windows
N/A
UNKNOWN
EPSS
30.4%
2023 1 PoC

The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plugin's pro features.

CVE-2023-44766
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 allows an attacker to execute arbitrary code via a crafted script to the SEO - Extra from Page Settings. NOTE: the vendor disputes this because this SEO-related header change can only be made by an admin, and allowing an admin to place JavaScript there is an intentional customization feature.

CVE-2023-25282
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2023 1 PoC

A heap overflow vulnerability in D-Link DIR820LA1_FW106B02 allows attackers to cause a denial of service via the config.log_to_syslog and log_opt_dropPackets parameters to mydlink_api.ccp.

CVE-2023-0065
i2 Pros & Cons Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The i2 Pros & Cons WordPress plugin through 1.3.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-38912
Software Genérico Web Database
N/A
UNKNOWN
EPSS
4.1%
2023 1 PoC

SQL injection vulnerability in Super Store Finder PHP Script v.3.6 allows a remote attacker to execute arbitrary code via a crafted payload to the username parameter.

CVE-2023-31466
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An XSS issue was discovered in FSMLabs TimeKeeper 8.0.17. On the "Configuration -> Compliance -> Add a new compliance report" and "Configuration -> Timekeeper Configuration -> Add a new source there" screens, there are entry points to inject JavaScript code.

CVE-2023-23302
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

The `Toybox.GenericChannel.setDeviceConfig` API method in CIQ API version 1.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying various attributes. A malicious application could call the API method with specially crafted object and hijack the execution of the device's firmware.

CVE-2023-2579
InventoryPress Web Windows
N/A
UNKNOWN
EPSS
16.6%
2023 1 PoC

The InventoryPress WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-2761
User Activity Log Web Database Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The User Activity Log WordPress plugin before 1.6.3 does not properly sanitise and escape the `txtsearch` parameter before using it in a SQL statement in some admin pages, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-46021
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL Injection vulnerability in cancel.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary commands via the 'reqid' parameter.

CVE-2023-43154
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 2 PoCs

In Macrob7 Macs Framework Content Management System (CMS) 1.1.4f, loose comparison in "isValidLogin()" function during login attempt results in PHP type confusion vulnerability that leads to authentication bypass and takeover of the administrator account.

CVE-2023-40931
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
88.4%
2023 3 PoCs

A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php

CVE-2023-1110
Yellow Yard Searchbar Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Yellow Yard Searchbar WordPress plugin before 2.8.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-40765
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-48839
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Appointment Scheduler 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.

CVE-2023-23300
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

The `Toybox.Cryptography.Cipher.initialize` API method in CIQ API version 3.0.0 through 4.1.7 does not validate its parameters, which can result in buffer overflows when copying data. A malicious application could call the API method with specially crafted parameters and hijack the execution of the device's firmware.

CVE-2023-28485
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

A stored cross-site scripting (Stored XSS) vulnerability in file preview in WeKan before 6.75 allows remote authenticated users to inject arbitrary web script or HTML via names of file attachments. Any user can obtain the privilege to rename within their own board (where they have BoardAdmin access), and renameAttachment does not block XSS payloads.

CVE-2023-0172
Embed, curate & aggregate social media feeds into your website using JUICER Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Juicer WordPress plugin before 1.11 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks