3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-39675
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php.

CVE-2023-46020
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Cross Site Scripting (XSS) in updateprofile.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'rename', 'remail', 'rphone' and 'rcity' parameters.

CVE-2023-36089
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Authentication Bypass vulnerability in D-Link DIR-645 firmware version 1.03 allows remote attackers to gain escalated privileges via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-38879
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
12.0%
2023 1 PoC

The Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to read arbitrary files via a directory traversal vulnerability in the 'filename' parameter of 'DownloadWindow.php'.

CVE-2023-48838
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Appointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code.

CVE-2023-43148
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2023 1 PoC

SPA-Cart 1.9.0.3 has a Cross Site Request Forgery (CSRF) vulnerability that allows a remote attacker to delete all accounts.

CVE-2023-45880
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can create a new Asset Component. The templateFileDestination parameter can be set to an arbitrary pathname (and extension). This allows creation of PHP files outside of the uploads directory, directly in the webroot.

CVE-2023-27214
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Online Student Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the fromdate and todate parameters at /eduauth/student/between-date-reprtsdetails.php.

CVE-2023-4808
WP Post Popup Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WP Post Popup WordPress plugin through 3.7.3 does not sanitise and escape some of its inputs, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-50011
Software Genérico Web
N/A
UNKNOWN
EPSS
3.3%
2023 1 PoC

PopojiCMS version 2.0.1 is vulnerable to remote command execution in the Meta Social field.

CVE-2023-38315
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a try_to_authenticate NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing client token query string parameter. Triggering this issue results in crashing OpenNDS (a Denial-of-Service condition). Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.

CVE-2023-1274
Pricing Tables For WPBakery Page Builder (formerly Visual Composer) Web Windows
N/A
UNKNOWN
EPSS
0.8%
2023 1 PoC

The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks

CVE-2023-31546
Software Genérico Web
N/A
UNKNOWN
EPSS
21.2%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature.

CVE-2023-40762
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

User enumeration is found in PHPJabbers Fundraising Script v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-50449
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

JFinalCMS 5.0.0 could allow a remote attacker to read files via ../ Directory Traversal in the /common/down/file fileKey parameter.

CVE-2023-1166
Ultimate-Premium-Plugin Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The USM-Premium WordPress plugin before 16.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVE-2023-36319
Software Genérico Web
N/A
UNKNOWN
EPSS
25.4%
2023 1 PoC

File Upload vulnerability in Openupload Stable v.0.4.3 allows a remote attacker to execute arbitrary code via the action parameter of the compress-inc.php file.

CVE-2023-38314
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a NULL pointer dereference in preauthenticated() that can be triggered with a crafted GET HTTP request with a missing redirect query string parameter. Triggering this issue results in crashing OpenNDS (a Denial-of-Service condition). Affected OpenNDS Captive Portal before version 10.1.2 fixed infixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on28. August 2023 by updating OpenNDS to version 10.1.3.

CVE-2023-39115
Software Genérico Web
N/A
UNKNOWN
EPSS
2.2%
2023 3 PoCs

install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document.

CVE-2023-40759
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.