3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-48824
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

BoidCMS 2.0.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the title, subtitle, footer, or keywords parameter in a page=create action.

CVE-2023-46016
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Cross Site Scripting (XSS) in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'search' parameter in the application URL.

CVE-2023-37189
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2023 2 PoCs

A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the Name or Prefix fields under the Create New Rate module.

CVE-2023-47014
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

A Cross-Site Request Forgery (CSRF) vulnerability in Sourcecodester Sticky Notes App Using PHP with Source Code v.1.0 allows a local attacker to obtain sensitive information via a crafted payload to add-note.php.

CVE-2023-41436
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Cross Site Scripting vulnerability in CSZCMS v.1.3.0 allows a local attacker to execute arbitrary code via a crafted script to the Additional Meta Tag parameter in the Pages Content Menu component.

CVE-2023-24998
Apache Commons FileUpload Web
N/A
UNKNOWN
EPSS
33.2%
2023 CWE-770 1 PoC

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.

CVE-2023-50968
Apache OFBiz Web ⚡ nuclei
N/A
UNKNOWN
EPSS
83.9%
2023 CWE-200 0 PoCs

Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. The same uri can be operated to realize a SSRF attack also without authorizations. Users are recommended to upgrade to version 18.12.11, which fixes this issue.

CVE-2023-5057
ActivityPub Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The ActivityPub WordPress plugin before 1.0.0 does not escape user metadata before outputting them in mentions, which could allow users with a role of Contributor and above to perform Stored XSS attacks

CVE-2023-39001
Software Genérico Web
N/A
UNKNOWN
EPSS
5.5%
2023 1 PoC

A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary commands via a crafted backup configuration file.

CVE-2023-5882
Export any WordPress data to XML/CSV Web Windows
N/A
UNKNOWN
EPSS
0.8%
2023 1 PoC

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers to make logged in users perform unwanted actions leading to remote code execution.

CVE-2023-2578
Buy Me a Coffee Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Buy Me a Coffee WordPress plugin before 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-0067
Timed Content Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Timed Content WordPress plugin before 2.73 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-35759
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

In Progress WhatsUp Gold before 23.0.0, an SNMP-related application endpoint failed to adequately sanitize malicious input. This could allow an unauthenticated attacker to execute arbitrary code in a victim's browser, aka XSS.

CVE-2023-43353
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the extra parameter in the news menu component.

CVE-2023-31297
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue was discovered in SESAMI planfocus CPTO (Cash Point & Transport Optimizer) 6.3.8.6 718. There is XSS via the Name field when modifying a client.

CVE-2023-3345
LMS by Masteriyo Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
64.8%
2023 1 PoC

The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students

CVE-2023-3186
Popup by Supsystic Web Windows
N/A
UNKNOWN
EPSS
6.1%
2023 1 PoC

The Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties into Object.prototype.

CVE-2023-44847
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ Weixin.php component.

CVE-2023-46022
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

SQL Injection vulnerability in delete.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via the 'bid' parameter.

CVE-2023-38883
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'ajax' parameter in 'ParentLookup.php'.