3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-27082
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev4 allows remote attackers to run arbitrary code via upload of crafted html file.

CVE-2023-46581
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary code via the name, uname and email parameters in the registration.php component.

CVE-2023-46450
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 3 PoCs

Sourcecodester Free and Open Source inventory management system 1.0 is vulnerable to Cross Site Scripting (XSS) via the Add supplier function.

CVE-2023-38316
Software Genérico Web
N/A
UNKNOWN
EPSS
1.2%
2023 1 PoC

An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrary OS commands by inserting them into the URL portion of HTTP GET requests. Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.

CVE-2023-48866
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 2 PoCs

A Cross-Site Scripting (XSS) vulnerability in the recipe preparation component within /api/objects/recipes and note component within /api/objects/shopping_lists/ of Grocy <= 4.0.3 allows attackers to obtain the victim's cookies.

CVE-2023-39710
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 3 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Customer section.

CVE-2023-40749
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
44.5%
2023 2 PoCs

PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.

CVE-2023-41107
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 2 PoCs

TEF portal 2023-07-17 is vulnerable to a persistent cross site scripting (XSS)attack.

CVE-2023-23298
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2023 1 PoC

The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its parameters, which can result in integer overflows when allocating the underlying bitmap buffer. A malicious application could call the API method with specially crafted parameters and hijack the execution of the device's firmware.

CVE-2023-43468
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.8%
2023 1 PoC

SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the login.php component.

CVE-2023-46015
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in index.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via 'msg' parameter in application URL.

CVE-2023-40753
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the message parameter of index.php in PHPJabbers Ticket Support Script v3.2.

CVE-2023-5560
WP-UserOnline Web Windows
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

The WP-UserOnline WordPress plugin before 2.88.3 does not sanitise and escape the X-Forwarded-For header before outputting its content on the page, which allows unauthenticated users to perform Cross-Site Scripting attacks.

CVE-2023-2802
Ultimate Addons for Contact Form 7 Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Ultimate Addons for Contact Form 7 WordPress plugin before 3.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-5105
Frontend File Manager Plugin Web Windows
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass the file download logic and download files such as `wp-config.php`

CVE-2023-36140
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts.

CVE-2023-2254
Ko-fi Button Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Ko-fi Button WordPress plugin before 1.3.3 does not properly some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup), and we consider it a low risk.

CVE-2023-36132
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control.

CVE-2023-39575
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the url_str URL parameter of ISL ARP Guard v4.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2023-46987
Software Genérico Web
N/A
UNKNOWN
EPSS
5.7%
2023 1 PoC

SeaCMS v12.9 was discovered to contain a remote code execution (RCE) vulnerability via the component /augap/adminip.php.