3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-3435
User Activity Log Web Database Windows
N/A
UNKNOWN
EPSS
0.8%
2023 1 PoC

The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before using it in a SQL statement as part of its exportation feature, allowing unauthenticated attackers to conduct SQL injection attacks.

CVE-2023-36134
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2023 2 PoCs

In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.

CVE-2023-36970
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function.

CVE-2023-44848
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_template.php component.

CVE-2023-41150
F-RevoCRM Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

F-RevoCRM 7.3 series prior to version7.3.8 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the product.

CVE-2023-43352
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager Menu component.

CVE-2023-48199
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2023 2 PoCs

HTML Injection vulnerability in the 'manageApiKeys' component in Grocy <= 4.0.3 allows attackers to inject arbitrary HTML content without script execution. This occurs when user-supplied data is not appropriately sanitized, enabling the injection of HTML tags through parameter values. The attacker can then manipulate page content in the QR code detail popup, often coupled with social engineering tactics, exploiting both the trust of users and the application's lack of proper input handling.

CVE-2023-38617
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Office Suite Premium Version v10.9.1.42602 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the filter parameter at /api?path=files.

CVE-2023-34835
Software Genérico Web
N/A
UNKNOWN
EPSS
1.7%
2023 2 PoCs

A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary JavaScript code via a vulnerable delete_file parameter.

CVE-2023-36346
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.4%
2023 3 PoCs

POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parameter at print.php.

CVE-2023-2321
WPForms Google Sheet Connector Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WPForms Google Sheet Connector WordPress plugin before 3.4.6, gsheetconnector-wpforms-pro WordPress plugin through 3.4.6 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-3460
Ultimate Member Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2023 14 PoCs

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

CVE-2023-41165
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and 4.4.0 through 4.6.8 before 4.6.9. An administrator with write access to the SNS firewall can configure a login disclaimer with malicious JavaScript elements that can result in data theft.

CVE-2023-2010
Forminator Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Forminator WordPress plugin before 1.24.1 does not use an atomic operation to check whether a user has already voted, and then update that information. This leads to a Race Condition that may allow a single user to vote multiple times on a poll.

CVE-2023-2225
SEO ALert Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The SEO ALert WordPress plugin through 1.59 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-47446
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

Pre-School Enrollment version 1.0 is vulnerable to Cross Site Scripting (XSS) on the profile.php page via fullname parameter.

CVE-2023-27210
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/view_order.php.

CVE-2023-37728
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
17.3%
2023 2 PoCs

IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter.

CVE-2023-43354
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Profiles parameter in the Extensions -MicroTiny WYSIWYG editor component.

CVE-2023-27208
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A cross-site scripting (XSS) vulnerability in /php-opos/login.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the redirect parameter.