3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-36118
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Cross Site Scripting vulnerability in Faculty Evaulation System using PHP/MySQLi v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the page parameter.

CVE-2023-39325
net/http Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the existing one is still executing. With the fix applied, HTTP/2 servers now bound the number of simultaneously executing handler goroutines to the stream concurrency limit (MaxConcurrentStreams). New requests arriving when at the limit (which can only happen after the client has reset

CVE-2023-2326
Gravity Forms Google Sheet Connector Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

CVE-2023-2709
AN_GradeBook Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The AN_GradeBook WordPress plugin through 5.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-2272
Tiempo.com Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
14.1%
2023 1 PoC

The Tiempo.com WordPress plugin through 0.1.2 does not sanitise and escape the page parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-5641
Martins Free & Easy SEO BackLink Link Building Network Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Martins Free & Easy SEO BackLink Link Building Network WordPress plugin before 1.2.30 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-26959
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Phpgurukul Park Ticketing Management System 1.0 is vulnerable to SQL Injection via the User Name parameter.

CVE-2023-2812
Ultimate Dashboard Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Ultimate Dashboard WordPress plugin before 3.7.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-23299
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The permission system implemented and enforced by the GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 can be bypassed entirely. A malicious application with specially crafted code and data sections could access restricted CIQ modules, call their functions and disclose sensitive data such as user profile information and GPS coordinates, among others.

CVE-2023-36141
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

User enumeration is found in in PHPJabbers Cleaning Business Software 1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-28467
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

In MyBB before 1.8.34, there is XSS in the User CP module via the user email field.

CVE-2023-47804
Apache OpenOffice Web
N/A
UNKNOWN
EPSS
2.3%
2023 CWE-20 1 PoC

Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. Links can be activated by clicks, or by automatic document events. The execution of such links must be subject to user approval. In the affected versions of OpenOffice, approval for certain links is not requested; when activated, such links could therefore result in arbitrary script execution. This is a corner case of CVE-2022-47502.

CVE-2023-24735
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.1%
2023 0 PoCs

PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerability allows attackers to redirect victim users to an external domain via a crafted URL.

CVE-2023-46024
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.1%
2023 1 PoC

SQL Injection vulnerability in index.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to run arbitrary SQL commands and obtain sensitive information via the 'searchdata' parameter.

CVE-2023-33335
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Cross Site Scripting (XSS) in Sophos Sophos iView (The EOL was December 31st 2020) in grpname parameter that allows arbitrary script to be executed.

CVE-2023-6065
Quttera Web Malware Scanner Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
37.5%
2023 2 PoCs

The Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 doesn't restrict access to detailed scan logs, which allows a malicious actor to discover local paths and portions of the site's code

CVE-2023-47489
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 3 PoCs

CSV injection in export as csv in Combodo iTop v.3.1.0-2-11973 allows a local attacker to execute arbitrary code via a crafted script to the export-v2.php and ajax.render.php components.

CVE-2023-3209
MStore API Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both.

CVE-2023-40617
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start 7 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'file' parameter in 'displayPDF.php'.

CVE-2023-36085
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 3 PoCs

The sisqualWFM 7.1.319.103 thru 7.1.319.111 for Android, has a host header injection vulnerability in its "/sisqualIdentityServer/core/" endpoint. By modifying the HTTP Host header, an attacker can change webpage links and even redirect users to arbitrary or malicious locations. This can lead to phishing attacks, malware distribution, and unauthorized access to sensitive resources.