3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-39319
html/template Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The html/template package does not apply the proper rules for handling occurrences of "<script", "<!--", and "</script" within JS literals in <script> contexts. This may cause the template parser to improperly consider script contexts to be terminated early, causing actions to be improperly escaped. This could be leveraged to perform an XSS attack.

CVE-2023-50917
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.6%
2023 3 PoCs

MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majordomo mailing-list manager.

CVE-2023-39714
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 3 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Member section.

CVE-2023-1273
ND Shortcodes Web Windows
N/A
UNKNOWN
EPSS
12.8%
2023 2 PoCs

The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks

CVE-2023-45391
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A stored cross-site scripting (XSS) vulnerability in the Create A New Employee function of Granding UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the First Name parameter.

CVE-2023-34537
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
15.8%
2023 1 PoC

A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter to trick user on browser and/or exfiltrate data.

CVE-2023-2592
FormCraft Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The FormCraft WordPress plugin before 3.9.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-46865
Software Genérico Web
N/A
UNKNOWN
EPSS
70.2%
2023 2 PoCs

/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image.

CVE-2023-44761
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS versions affected to 8.5.13 and below, and 9.0.0 through 9.2.1 allow a local attacker to execute arbitrary code via a crafted script to the Forms of the Data objects.

CVE-2023-50470
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A cross-site scripting (XSS) vulnerability in the component admin_ Video.php of SeaCMS v12.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2023-46857
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomplete blacklist in the SVG inspection, allowing JavaScript in the SRC attribute of an IFRAME element. An authenticated attack with assets.create permission is required for exploitation.

CVE-2023-31302
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Teller field.

CVE-2023-31301
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Stored Cross Site Scripting (XSS) Vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the Username field of the login form and application log.

CVE-2023-38130
CubeCart Web
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

Cross-site request forgery (CSRF) vulnerability in CubeCart prior to 6.5.3 allows a remote unauthenticated attacker to delete data in the system.

CVE-2023-48003
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' in the WebSocket messages.

CVE-2023-5762
Filr Web Windows
N/A
UNKNOWN
EPSS
14.2%
2023 1 PoC

The Filr WordPress plugin before 1.2.3.6 is vulnerable from an RCE (Remote Code Execution) vulnerability, which allows the operating system to execute commands and fully compromise the server on behalf of a user with Author-level privileges.

CVE-2023-23130
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext) with SSL disabled. OTE: the vendor's position is that, by design, this is controlled by a configuration option in which a customer can choose to use HTTP (rather than HTTPS) during troubleshooting.

CVE-2023-38891
Software Genérico Web Database
N/A
UNKNOWN
EPSS
3.4%
2023 1 PoC

SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php.

CVE-2023-2842
WP Inventory Manager Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WP Inventory Manager WordPress plugin before 2.1.0.14 does not have CSRF checks, which could allow attackers to make logged-in admins delete Inventory Items via a CSRF attack

CVE-2023-0579
YARPP Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscribers to perform SQL Injection attacks.