3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-46022
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

SQL Injection vulnerability in delete.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via the 'bid' parameter.

CVE-2023-38883
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'ajax' parameter in 'ParentLookup.php'.

CVE-2023-2028
Call Now Accessibility Button Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Call Now Accessibility Button WordPress plugin before 1.1 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-5974
wpb-show-core Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
78.3%
2023 1 PoC

The WPB Show Core WordPress plugin through 2.2 is vulnerable to server-side request forgery (SSRF) via the `path` parameter.

CVE-2023-0145
Saan World Clock Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Saan World Clock WordPress plugin through 1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-43872
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

A File upload vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).

CVE-2023-36135
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

User enumeration is found in in PHPJabbers Class Scheduling System v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-40037
Apache NiFi Web
N/A
UNKNOWN
EPSS
1.3%
2023 CWE-184 1 PoC

Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs. An authenticated and authorized user can bypass connection URL validation using custom input formatting. The resolution enhances connection URL validation and introduces validation for additional related properties. Upgrading to Apache NiFi 1.23.1 is the recommended mitigation.

CVE-2023-0890
WordPress Shortcodes Plugin — Shortcodes Ultimate Web Windows
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not ensure that posts to be displayed via some shortcodes are already public and can be accessed by the user making the request, allowing any authenticated users such as subscriber to view draft, private or even password protected posts. It is also possible to leak the password of protected posts

CVE-2023-43469
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.4%
2023 1 PoC

SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the ForPass.php component.

CVE-2023-39006
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Crash Reporter (crash_reporter.php) component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 mishandles input sanitization.

CVE-2023-5652
WP Hotel Booking Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
66.6%
2023 1 PoC

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a function hooked to admin_init, allowing unauthenticated users to perform SQL injections

CVE-2023-27890
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The Export User plugin through 2.0 for MyBB allows XSS during the process of an admin generating DSGVO data for a user, via the Custom User Title, Location, or Bio field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-50089
Software Genérico Web
N/A
UNKNOWN
EPSS
3.1%
2023 1 PoC

A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication.

CVE-2023-43149
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2023 1 PoC

SPA-Cart 1.9.0.3 is vulnerable to Cross Site Request Forgery (CSRF) that allows a remote attacker to add an admin user with role status.

CVE-2023-45278
Software Genérico Web
N/A
UNKNOWN
EPSS
3.2%
2023 1 PoC

Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafted HTTP DELETE request.

CVE-2023-48837
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Car Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.

CVE-2023-33580
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2023 2 PoCs

Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" field on Admin Profile page.

CVE-2023-44813
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
20.8%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a crafted payload to the mode parameter of the invite friend login function.

CVE-2023-36376
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Cross-Site Scripting (XSS) vulnerability in Hostel Management System v.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the add course section.