3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-33580
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2023 2 PoCs

Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" field on Admin Profile page.

CVE-2023-44813
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
20.8%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a crafted payload to the mode parameter of the invite friend login function.

CVE-2023-36376
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Cross-Site Scripting (XSS) vulnerability in Hostel Management System v.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the add course section.

CVE-2023-39711
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 3 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Subtotal and Paidbill parameters under the Add New Put section.

CVE-2023-2178
Aajoda Testimonials Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.1%
2023 1 PoC

The Aajoda Testimonials WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-5141
BSK Contact Form 7 Blacklist Web Windows
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The BSK Contact Form 7 Blacklist WordPress plugin through 1.0.1 does not sanitise and escape the inserted_count parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-4252
EventPrime Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attacker to purchase bookings without payment.

CVE-2023-2796
EventON Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
71.5%
2023 2 PoCs

The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.

CVE-2023-39709
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 3 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Member section.

CVE-2023-46468
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

An issue in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted file to the custom plugin function.

CVE-2023-37602
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

An arbitrary file upload vulnerability in the component /workplace#!explorer of Alkacon OpenCMS v15.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.

CVE-2023-31714
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.3%
2023 2 PoCs

Chitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities.

CVE-2023-45868
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Learning Module in ILIAS 7.25 (2023-09-12 release) allows an attacker (with basic user privileges) to achieve a high-impact Directory Traversal attack on confidentiality and availability. By exploiting this network-based vulnerability, the attacker can move specified directories, normally outside the documentRoot, to a publicly accessible location via the PHP function rename(). This results in a total loss of confidentiality, exposing sensitive resources, and potentially denying access to the affected component and the operating system's components. To exploit this, an attacker must manipu

CVE-2023-47326
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) via the Domain SQL Create function.

CVE-2023-47324
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Silverpeas Core 6.3.1 is vulnerable to Cross Site Scripting (XSS) via the message/notification feature.

CVE-2023-23126
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.

CVE-2023-44770
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows an attacker to execute arbitrary code via a crafted script to the Organizer - Spare alias.

CVE-2023-6166
Quiz Maker Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Quiz Maker WordPress plugin before 6.4.9.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

CVE-2023-34960
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2023 12 PoCs

A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.

CVE-2023-40834
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated attackers to gain access to the application via a brute force attack to the password parameter.