3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-44770
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows an attacker to execute arbitrary code via a crafted script to the Organizer - Spare alias.

CVE-2023-6166
Quiz Maker Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Quiz Maker WordPress plugin before 6.4.9.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

CVE-2023-34960
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2023 12 PoCs

A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.

CVE-2023-40834
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated attackers to gain access to the application via a brute force attack to the password parameter.

CVE-2023-48808
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

CVE-2023-34852
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.

CVE-2023-36138
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

PHPJabbers Cleaning Business Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the theme parameter of preview.php.

CVE-2023-0212
Advanced Recent Posts Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Advanced Recent Posts WordPress plugin through 0.6.14 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-28875
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A Stored XSS issue in shared files download terms in Filerun Update 20220202 allows attackers to inject JavaScript code that is executed when a user follows the crafted share link.

CVE-2023-44762
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A Cross Site Scripting (XSS) vulnerability in Concrete CMS from versions 9.2.0 to 9.2.2 allows an attacker to execute arbitrary code via a crafted script to the Tags from Settings - Tags.

CVE-2023-30347
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Cross Site Scripting (XSS) vulnerability in Neox Contact Center 2.3.9, via the serach_sms_api_name parameter to the SMA API search.

CVE-2023-40756
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

User enumeration is found in PHPJabbers Callback Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-36940
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Cross Site Scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL v.1.2 allows attackers to execute arbitrary code via a crafted payload injected into the search field.

CVE-2023-36131
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation of password parameter.

CVE-2023-43456
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2023 2 PoCs

Cross Site Scripting vulnerability in Service Provider Management System v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the firstname, middlename and lastname parameters in the /php-spms/admin/?page=user endpoint.

CVE-2023-41564
Software Genérico Web
N/A
UNKNOWN
EPSS
20.1%
2023 1 PoC

An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a crafted .shtml file.

CVE-2023-27082
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev4 allows remote attackers to run arbitrary code via upload of crafted html file.

CVE-2023-46581
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary code via the name, uname and email parameters in the registration.php component.

CVE-2023-46450
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 3 PoCs

Sourcecodester Free and Open Source inventory management system 1.0 is vulnerable to Cross Site Scripting (XSS) via the Add supplier function.

CVE-2023-38316
Software Genérico Web
N/A
UNKNOWN
EPSS
1.2%
2023 1 PoC

An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrary OS commands by inserting them into the URL portion of HTTP GET requests. Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.