3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-5340
Five Star Restaurant Menu and Food Ordering Web Windows
N/A
UNKNOWN
EPSS
1.0%
2023 1 PoC

The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticated users, allowing them to perform PHP Object Injection when a suitable gadget is present on the blog.

CVE-2023-41593
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in Dairy Farm Shop Management System Using PHP and MySQL v1.1 allow attackers to execute arbitrary web scripts and HTML via a crafted payload injected into the Category and Category Field parameters.

CVE-2023-43323
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
80.8%
2023 1 PoC

mooSocial 3.1.8 is vulnerable to external service interaction on post function. When executed, the server sends a HTTP and DNS request to external server. The Parameters effected are multiple - messageText, data[wall_photo], data[userShareVideo] and data[userShareLink].

CVE-2023-3175
AI ChatBot Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The AI ChatBot WordPress plugin before 4.6.1 does not adequately escape some settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2023-23634
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.2%
2023 1 PoC

SQL Injection vulnerability in Documize version 5.4.2, allows remote attackers to execute arbitrary code via the user parameter of the /api/dashboard/activity endpoint.

CVE-2023-24317
Software Genérico Web
N/A
UNKNOWN
EPSS
9.1%
2023 2 PoCs

Judging Management System 1.0 was discovered to contain an arbitrary file upload vulnerability via the component edit_organizer.php.

CVE-2023-23127
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

In Connectwise Control 22.8.10013.8329, the login page does not implement HSTS headers therefore not enforcing HTTPS. NOTE: the vendor's position is that, by design, this is controlled by a configuration option in which a customer can choose to use HTTP (rather than HTTPS) during troubleshooting.

CVE-2023-37152
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2023 2 PoCs

Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This has been disputed as not a valid vulnerability.

CVE-2023-3134
Forminator Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

The Forminator WordPress plugin before 1.24.4 does not properly escape values that are being reflected inside form fields that use pre-populated query parameters, which could lead to reflected XSS attacks.

CVE-2023-38948
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers to execute arbitrary code via downloading a crafted plugin.

CVE-2023-36220
Software Genérico Web
N/A
UNKNOWN
EPSS
2.8%
2023 1 PoC

Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain access to sensitive information via the plugin Upload function.

CVE-2023-0369
GoToWP Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The GoToWP WordPress plugin through 5.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-31718
Software Genérico Web
N/A
UNKNOWN
EPSS
37.6%
2023 2 PoCs

FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.

CVE-2023-40764
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-33690
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

SonicJS up to v0.7.0 allows attackers to execute an authenticated path traversal when an attacker injects special characters into the filename of a backup CMS.

CVE-2023-3435
User Activity Log Web Database Windows
N/A
UNKNOWN
EPSS
0.8%
2023 1 PoC

The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before using it in a SQL statement as part of its exportation feature, allowing unauthenticated attackers to conduct SQL injection attacks.

CVE-2023-36134
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2023 2 PoCs

In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.

CVE-2023-36970
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function.

CVE-2023-44848
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_template.php component.