3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-24733
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
14.9%
2023 0 PoCs

PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /admin/convert/export_z3950_new.php.

CVE-2023-43470
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.3%
2023 1 PoC

SQL injection vulnerability in janobe Online Voting System v.1.0 allows a remote attacker to execute arbitrary code via the checklogin.php component.

CVE-2023-37685
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Page of the Admin portal.

CVE-2023-27212
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A cross-site scripting (XSS) vulnerability in /php-opos/signup.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the redirect parameter.

CVE-2023-43278
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A Cross-Site Request Forgery (CSRF) in admin_manager.php of Seacms up to v12.8 allows attackers to arbitrarily add an admin account.

CVE-2023-5559
10Web Booster Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
52.5%
2023 1 PoC

The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.

CVE-2023-39707
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 3 PoCs

A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Add Expense parameter under the Expense section.

CVE-2023-2701
gravityforms Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin.

CVE-2023-5674
WP Mail Log Web Database Windows
N/A
UNKNOWN
EPSS
11.0%
2023 1 PoC

The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Contributor.

CVE-2023-34839
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2023 2 PoCs

A Cross Site Request Forgery (CSRF) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows a remote attacker to gain privileges via a Custom CSRF exploit to create new user function in the application.

CVE-2023-47248
PyArrow Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.4%
2023 CWE-502 1 PoC

Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (for example user-supplied input files). This vulnerability only affects PyArrow, not other Apache Arrow implementations or bindings. It is recommended that users of PyArrow upgrade to 14.0.1. Similarly, it is recommended that downstream libraries upgrade their dependency requirements to PyArrow 14.0.1 or later. PyPI packages are already available, and we hope that

CVE-2023-41364
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

In tine through 2023.01.14.325, the sort parameter of the /index.php endpoint allows SQL Injection.

CVE-2023-42283
Software Genérico Web Database
N/A
UNKNOWN
EPSS
10.7%
2023 1 PoC

Blind SQL injection in api_id parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query.

CVE-2023-42406
Software Genérico Web Database
N/A
UNKNOWN
EPSS
23.3%
2023 1 PoC

SQL injection vulnerability in D-Link Online behavior audit gateway DAR-7000 V31R02B1413C allows a remote attacker to obtain sensitive information and execute arbitrary code via the editrole.php component.

CVE-2023-0364
real.Kit Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The real.Kit WordPress plugin before 5.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-48803
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

CVE-2023-28873
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An XSS issue in wiki and discussion pages in Seafile 9.0.6 allows attackers to inject JavaScript into the Markdown editor.

CVE-2023-34869
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

PHPJabbers Catering System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /index.php?controller=pjAdmin&action=pjActionForgot.

CVE-2023-0439
NEX-Forms Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The NEX-Forms WordPress plugin before 8.4.4 does not escape its form name, which could lead to Stored Cross-Site Scripting issues. By default only SuperAdmins (in multisite) / admins (in single site) can create forms, however there is a settings allowing them to give lower roles access to such feature.

CVE-2023-0328
WPCode Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The WPCode WordPress plugin before 2.0.7 does not have adequate privilege checks in place for several AJAX actions, only checking the nonce. This may lead to allowing any authenticated user who can edit posts to call the endpoints related to WPCode Library authentication (such as update and delete the auth key).