3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-48003
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' in the WebSocket messages.

CVE-2023-5762
Filr Web Windows
N/A
UNKNOWN
EPSS
14.2%
2023 1 PoC

The Filr WordPress plugin before 1.2.3.6 is vulnerable from an RCE (Remote Code Execution) vulnerability, which allows the operating system to execute commands and fully compromise the server on behalf of a user with Author-level privileges.

CVE-2023-23130
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext) with SSL disabled. OTE: the vendor's position is that, by design, this is controlled by a configuration option in which a customer can choose to use HTTP (rather than HTTPS) during troubleshooting.

CVE-2023-38891
Software Genérico Web Database
N/A
UNKNOWN
EPSS
3.4%
2023 1 PoC

SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php.

CVE-2023-2842
WP Inventory Manager Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WP Inventory Manager WordPress plugin before 2.1.0.14 does not have CSRF checks, which could allow attackers to make logged-in admins delete Inventory Items via a CSRF attack

CVE-2023-0579
YARPP Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscribers to perform SQL Injection attacks.

CVE-2023-2324
Elementor Forms Google Sheet Connector Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Elementor Forms Google Sheet Connector WordPress plugin before 1.0.7, gsheetconnector-for-elementor-forms-pro WordPress plugin through 1.0.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-46475
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

A Stored Cross-Site Scripting vulnerability was discovered in ZenTao 18.3 where a user can create a project, and in the name field of the project, they can inject malicious JavaScript code.

CVE-2023-41013
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Cross Site Scripting (XSS) in Webmail Calendar in IceWarp 10.3.1 allows remote attackers to inject arbitrary web script or HTML via the "p4" field.

CVE-2023-40760
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

User enumeration is found in PHP Jabbers Hotel Booking System v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-5979
eCommerce Product Catalog Plugin for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The eCommerce Product Catalog Plugin for WordPress plugin before 3.3.26 does not have CSRF checks in some of its admin pages, which could allow attackers to make logged-in users perform unwanted actions via CSRF attacks, such as delete all products

CVE-2023-39650
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
35.0%
2023 0 PoCs

Theme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /tvcmsblog/single.

CVE-2023-36090
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Authentication Bypass vulnerability in D-Link DIR-885L FW102b01 allows remote attackers to gain escalated privileges via phpcgi. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-43147
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

PHPJabbers Limo Booking Software 1.0 is vulnerable to Cross Site Request Forgery (CSRF) to add an admin user via the Add Users Function, aka an index.php?controller=pjAdminUsers&action=pjActionCreate URI.

CVE-2023-2495
Greeklish-permalink Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Greeklish-permalink WordPress plugin through 3.3 does not implement correct authorization or nonce checks in the cyrtrans_ajax_old AJAX action, allowing unauthenticated and low-privilege users to trigger the plugin's functionality to change Post slugs either directly or through CSRF.

CVE-2023-3492
WP Shopping Pages Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WP Shopping Pages WordPress plugin through 1.14 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2023-3139
Protect WP Admin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.4%
2023 1 PoC

The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered.

CVE-2023-39675
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php.

CVE-2023-46020
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Cross Site Scripting (XSS) in updateprofile.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'rename', 'remail', 'rphone' and 'rcity' parameters.

CVE-2023-36089
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Authentication Bypass vulnerability in D-Link DIR-645 firmware version 1.03 allows remote attackers to gain escalated privileges via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.