3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-33335
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Cross Site Scripting (XSS) in Sophos Sophos iView (The EOL was December 31st 2020) in grpname parameter that allows arbitrary script to be executed.

CVE-2023-6065
Quttera Web Malware Scanner Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
37.5%
2023 2 PoCs

The Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 doesn't restrict access to detailed scan logs, which allows a malicious actor to discover local paths and portions of the site's code

CVE-2023-47489
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 3 PoCs

CSV injection in export as csv in Combodo iTop v.3.1.0-2-11973 allows a local attacker to execute arbitrary code via a crafted script to the export-v2.php and ajax.render.php components.

CVE-2023-3209
MStore API Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both.

CVE-2023-40617
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start 7 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'file' parameter in 'displayPDF.php'.

CVE-2023-36085
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 3 PoCs

The sisqualWFM 7.1.319.103 thru 7.1.319.111 for Android, has a host header injection vulnerability in its "/sisqualIdentityServer/core/" endpoint. By modifying the HTTP Host header, an attacker can change webpage links and even redirect users to arbitrary or malicious locations. This can lead to phishing attacks, malware distribution, and unauthorized access to sensitive resources.

CVE-2023-44048
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Sourcecodester Expense Tracker App v1 is vulnerable to Cross Site Scripting (XSS) via add category.

CVE-2023-2271
Tiempo.com Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Tiempo.com WordPress plugin through 0.1.2 does not have CSRF check when deleting its shortcode, which could allow attackers to make logged in admins delete arbitrary shortcode via a CSRF attack

CVE-2023-39558
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

AudimexEE v15.0 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the Show Kai Data component.

CVE-2023-39560
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
68.4%
2023 0 PoCs

ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php.

CVE-2023-44764
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A Cross Site Scripting (XSS) vulnerability in Concrete CMS before 9.2.3 exists via the Name parameter during installation (aka Site of Installation or Settings).

CVE-2023-5640
Article analytics Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2023 2 PoCs

The Article Analytics WordPress plugin does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection vulnerability.

CVE-2023-38881
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into any of the 'calendar_id', 'school_date', 'month' or 'year' parameters in 'CalendarModal.php'.

CVE-2023-40852
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL Injection vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to obtain sensitive information via crafted string in the admin user name field on the admin log in page.

CVE-2023-5886
Export any WordPress data to XML/CSV Web Windows
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers with the ability to upload files to make logged in users perform unwanted actions leading to PHAR deserialization, which may lead to remote code execution.

CVE-2023-38546
curl Web
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met. libcurl performs transfers. In its API, an application creates "easy handles" that are the individual handles for single transfers. libcurl provides a function call that duplicates en easy handle called [curl_easy_duphandle](https://curl.se/libcurl/c/curl_easy_duphandle.html). If a transfer has cookies enabled when the handle is duplicated, the cookie-enable state is also cloned - but without cloning the actual cookies. If the source handle did not read

CVE-2023-43871
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

A File upload vulnerability in WBCE v.1.6.1 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).

CVE-2023-39318
html/template Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The html/template package does not properly handle HTML-like "" comment tokens, nor hashbang "#!" comment tokens, in <script> contexts. This may cause the template parser to improperly interpret the contents of <script> contexts, causing actions to be improperly escaped. This may be leveraged to perform an XSS attack.

CVE-2023-52240
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The Kantega SAML SSO OIDC Kerberos Single Sign-on apps before 6.20.0 for Atlassian products allow XSS if SAML POST Binding is enabled. This affects 4.4.2 through 4.14.8 before 4.14.9, 5.0.0 through 5.11.4 before 5.11.5, and 6.0.0 through 6.19.0 before 6.20.0. The full product names are Kantega SAML SSO OIDC Kerberos Single Sign-on for Jira Data Center & Server (Kantega SSO Enterprise), Kantega SAML SSO OIDC Kerberos Single Sign-on for Confluence Data Center & Server (Kantega SSO Enterprise), Kantega SAML SSO OIDC Kerberos Single Sign-on for Bitbucket Data Center & Server (Kantega SSO Enterpris

CVE-2023-2026
Image Protector Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Image Protector WordPress plugin through 1.1 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).