3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-41101
Software Genérico Web
N/A
UNKNOWN
EPSS
5.4%
2023 1 PoC

An issue was discovered in the captive portal in OpenNDS before version 10.1.3. get_query in http_microhttpd.c does not validate the length of the query string of GET requests. This leads to a stack-based buffer overflow in versions 9.x and earlier, and to a heap-based buffer overflow in versions 10.x and later. Attackers may exploit the issue to crash OpenNDS (Denial-of-Service condition) or to inject and execute arbitrary bytecode (Remote Code Execution). Affected OpenNDS before version 10.1.3 fixed in OpenWrt master and OpenWrt 23.05 on 23. November by updating OpenNDS to version 10.2.0.

CVE-2023-31851
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Cudy LT400 1.13.4 is has a cross-site scripting (XSS) vulnerability in /cgi-bin/luci/admin/network/wireless/status via the iface parameter.

CVE-2023-46375
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

ZenTao Biz version 4.1.3 and before is vulnerable to Cross Site Request Forgery (CSRF).

CVE-2023-38192
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.4%
2023 1 PoC

An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords.

CVE-2023-38910
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

CSZ CMS 1.3.0 is vulnerable to cross-site scripting (XSS), which allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered in the 'Carousel Wiget' section and choosing our carousel widget created above, in 'Photo URL' and 'YouTube URL' plugin.

CVE-2023-31753
Software Genérico Web Database
N/A
UNKNOWN
EPSS
3.7%
2023 2 PoCs

SQL injection vulnerability in diskusi.php in eNdonesia 8.7, allows an attacker to execute arbitrary SQL commands via the "rid=" parameter.

CVE-2023-36132
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control.

CVE-2023-41592
Software Genérico Web
N/A
UNKNOWN
EPSS
2.2%
2023 3 PoCs

Froala Editor v4.0.1 to v4.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability.

CVE-2023-36313
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

PHPJabbers Document Creator v1.0 is vulnerable to Cross Site Scripting (XSS) via all post parameters of "Export Requests" aside from "request_feed".

CVE-2023-48810
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

CVE-2023-43340
Software Genérico Web
N/A
UNKNOWN
EPSS
1.4%
2023 1 PoC

Cross-site scripting (XSS) vulnerability in evolution v.3.2.3 allows a local attacker to execute arbitrary code via a crafted payload injected into the cmsadmin, cmsadminemail, cmspassword and cmspasswordconfim parameters

CVE-2023-0602
Twittee Text Tweet Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.4%
2023 1 PoC

The Twittee Text Tweet WordPress plugin through 1.0.8 does not properly escape POST values which are printed back to the user inside one of the plugin's administrative page, which allows reflected XSS attacks targeting administrators to happen.

CVE-2023-5738
WordPress Backup & Migration Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WordPress Backup & Migration WordPress plugin before 1.4.4 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.

CVE-2023-31705
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

A Reflected Cross-site scripting (XSS) vulnerability in Sourcecodester Task Reminder System 1.0 allows an authenticated user to inject malicious javascript into the page parameter.

CVE-2023-48042
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Cross Site Scripting (XSS) in Search filters in Prestashop Amazzing filter version up to version 3.2.5, allows remote attackers to inject arbitrary JavaScript code.

CVE-2023-24249
Software Genérico Web
N/A
UNKNOWN
EPSS
48.2%
2023 3 PoCs

An arbitrary file upload vulnerability in laravel-admin v1.8.19 allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2023-5340
Five Star Restaurant Menu and Food Ordering Web Windows
N/A
UNKNOWN
EPSS
1.0%
2023 1 PoC

The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticated users, allowing them to perform PHP Object Injection when a suitable gadget is present on the blog.

CVE-2023-41593
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in Dairy Farm Shop Management System Using PHP and MySQL v1.1 allow attackers to execute arbitrary web scripts and HTML via a crafted payload injected into the Category and Category Field parameters.

CVE-2023-43323
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
80.8%
2023 1 PoC

mooSocial 3.1.8 is vulnerable to external service interaction on post function. When executed, the server sends a HTTP and DNS request to external server. The Parameters effected are multiple - messageText, data[wall_photo], data[userShareVideo] and data[userShareLink].