3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-30805
Net-Gen Application Firewall Web Networking
9.8
CRITICAL
EPSS
14.8%
2023 CWE-78 1 PoC

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /LogInOut.php endpoint. This is due to mishandling of shell meta-characters in the "un" parameter.

CVE-2023-46347
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
76.3%
2023 1 PoC

In the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL injection. The method `NdkSpack::getPacks()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

CVE-2023-0224
GiveWP Web Database Windows
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could let unauthenticated attackers perform SQL Injection attacks

CVE-2023-3277
MStore API – Create Native Android & iOS Apps On The Cloud Web Cloud Windows ⚡ nuclei
9.8
CRITICAL
EPSS
47.2%
2023 CWE-288 0 PoCs

The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows unauthenticated attackers to log in as any user as long as they know the user's email address.

CVE-2023-5601
WooCommerce Ninja Forms Product Add-ons Web Windows
9.8
CRITICAL
EPSS
0.8%
2023 2 PoCs

The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE.

CVE-2023-32645
YF325 Web
9.8
CRITICAL
EPSS
0.1%
2023 CWE-489 2 PoCs

A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to authentication bypass. An attacker can send a network request to trigger this vulnerability.

CVE-2023-30185
Software Genérico Web
9.8
CRITICAL
EPSS
0.6%
2023 2 PoCs

CRMEB v4.4 to v4.6 was discovered to contain an arbitrary file upload vulnerability via the component \attachment\SystemAttachmentServices.php.

CVE-2023-4634
Media Library Assistant Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
92.1%
2023 CWE-73 3 PoCs

The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the ~/includes/mla-stream-image.php file, where images are processed via Imagick(). This makes it possible for unauthenticated attackers to supply files via FTP that will make directory lists, local file inclusion, and remote code execution possible.

CVE-2023-35966
YF325 Web
9.8
CRITICAL
EPSS
0.3%
2023 CWE-190 1 PoC

Two heap-based buffer overflow vulnerabilities exist in the httpd manage_post functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as argument for the realloc function.

CVE-2023-2732
MStore API – Create Native Android & iOS Apps On The Cloud Web Cloud Windows ⚡ nuclei
9.8
CRITICAL
EPSS
90.3%
2023 CWE-288 5 PoCs

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.

CVE-2023-36091
Software Genérico Web
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

Authentication Bypass vulnerability in D-Link DIR-895 FW102b07 allows remote attackers to gain escalated privileges via via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-24201
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at get_ticket.php.

CVE-2023-27569
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header.

CVE-2023-3545
Chamilo Web Windows
9.8
CRITICAL
EPSS
3.0%
2023 CWE-178 1 PoC

Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of `.htaccess` file. This vulnerability may be exploited by privileged attackers or chained with unauthenticated arbitrary file write vulnerabilities, such as CVE-2023-3533, to achieve remote code execution.

CVE-2023-49989
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.5%
2023 1 PoC

Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at update.php.

CVE-2023-5204
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
87.0%
2023 CWE-89 2 PoCs

The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and including, 4.8.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2023-25207
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php.

CVE-2023-30806
Net-Gen Application Firewall Web Networking
9.8
CRITICAL
EPSS
14.8%
2023 CWE-78 1 PoC

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /cgi-bin/login.cgi endpoint. This is due to mishandling of shell meta-characters in the PHPSESSID cookie.

CVE-2023-6553
BackupBliss – Backup & Migration with Free Cloud Storage Web Cloud Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.5%
2023 CWE-94 7 PoCs

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated attackers to easily execute code on the server.