3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-41362
Software Genérico Web
N/A
UNKNOWN
EPSS
23.5%
2023 2 PoCs

MyBB before 1.8.36 allows Code Injection by users with certain high privileges. Templates in Admin CP intentionally use eval, and there was some validation of the input to eval, but type juggling interfered with this when using PCRE within PHP.

CVE-2023-36213
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

SQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of the search function.

CVE-2023-43341
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Cross-site scripting (XSS) vulnerability in evolution evo v.3.2.3 allows a local attacker to execute arbitrary code via a crafted payload injected uid parameter.

CVE-2023-33534
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A Cross-Site Request Forgery (CSRF) in Guanzhou Tozed Kangwei Intelligent Technology ZLTS10G software version S10G_3.11.6 allows attackers to takeover user accounts via sending a crafted POST request to /goform/goform_set_cmd_process.

CVE-2023-36210
Software Genérico Web
N/A
UNKNOWN
EPSS
10.5%
2023 1 PoC

MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter.

CVE-2023-43360
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Top Directory parameter in the File Picker Menu component.

CVE-2023-2744
WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting Web Database Windows
N/A
UNKNOWN
EPSS
28.4%
2023 3 PoCs

The ERP WordPress plugin before 1.12.4 does not properly sanitise and escape the `type` parameter in the `erp/v1/accounting/v1/people` REST API endpoint before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-40758
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

User enumeration is found in PHPJabbers Document Creator v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-0477
Auto Featured Image (Auto Post Thumbnail) Web Windows
N/A
UNKNOWN
EPSS
0.8%
2023 1 PoC

The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.16 includes an AJAX endpoint that allows any user with at least Author privileges to upload arbitrary files, such as PHP files. This is caused by incorrect file extension validation.

CVE-2023-5874
Popup box Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-43222
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.

CVE-2023-46017
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL Injection vulnerability in receiverLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'remail' and 'rpassword' parameters.

CVE-2023-27922
Newsletter Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.8%
2023 0 PoCs

Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script.

CVE-2023-5620
Web Push Notifications Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Web Push Notifications WordPress plugin before 4.35.0 does not prevent visitors on the site from changing some of the plugin options, some of which may be used to conduct Stored XSS attacks.

CVE-2023-37598
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

A Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via the delete new virtual fax function.

CVE-2023-38882
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'include' parameter in 'ForExport.php'

CVE-2023-31298
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the User ID field when creating a new system user.

CVE-2023-52444
Linux Web
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid dirent corruption As Al reported in link[1]: f2fs_rename() ... if (old_dir != new_dir && !whiteout) f2fs_set_link(old_inode, old_dir_entry, old_dir_page, new_dir); else f2fs_put_page(old_dir_page, 0); You want correct inumber in the ".." link. And cross-directory rename does move the source to new parent, even if you'd been asked to leave a whiteout in the old place. [1] https://lore.kernel.org/all/20231017055040.GN800259@ZenIV/ With below testcase, it may cause dirent corruption, due to it

CVE-2023-4824
Woohoo Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WooHoo Newspaper Magazine theme does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2023-39002
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
23.6%
2023 1 PoC

A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.