1238 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-5209
WordPress Online Booking and Scheduling Plugin Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-2796
EventON Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
71.5%
2023 2 PoCs

The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.

CVE-2023-0539
GS Insever Portfolio Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The GS Insever Portfolio WordPress plugin before 1.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-1597
tagDiv Cloud Library Web Cloud Windows
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing unauthenticated users to change arbitrary user metadata, which could lead to privilege escalation by setting themselves as an admin of the blog.

CVE-2023-2296
Loginizer Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Loginizer WordPress plugin before 1.7.9 does not escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-0431
File Away Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The File Away WordPress plugin through 3.9.9.0.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2023-2223
Login rebuilder Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

The Login rebuilder WordPress plugin before 2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-0489
SlideOnline Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The SlideOnline WordPress plugin through 1.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-2122
Image Optimizer by 10web Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
17.8%
2023 1 PoC

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter before rendering it in the plugin admin panel, leading to a reflected Cross-Site Scripting vulnerability, allowing an attacker to trick a logged in admin to execute arbitrary javascript by clicking a link.

CVE-2023-0165
Cost Calculator Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Cost Calculator WordPress plugin through 1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-2580
AI Engine: ChatGPT Chatbot, Content Generator, GPT 3 & 4, Ultra-Customizable Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The AI Engine WordPress plugin before 1.6.83 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVE-2023-28661
WP Popup Banners WordPress Plugin Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

The WP Popup Banners WordPress Plugin, version <= 1.2.5, is affected by an authenticated SQL injection vulnerability in the 'value' parameter in the get_popup_data action.

CVE-2023-5952
Welcart e-Commerce Web Windows
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

The Welcart e-Commerce WordPress plugin before 2.9.5 unserializes user input from cookies, which could allow unautehtniacted users to perform PHP Object Injection when a suitable gadget is present on the blog

CVE-2023-0588
Catalyst Connect Zoho CRM Client Portal Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Catalyst Connect Zoho CRM Client Portal WordPress plugin before 2.1.0 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admin.

CVE-2023-5737
WordPress Backup & Migration Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users with a role as low as Subscriber to update some plugin settings.

CVE-2023-3131
MStore API Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both.

CVE-2023-0263
WP Yelp Review Slider Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

The WP Yelp Review Slider WordPress plugin before 7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

CVE-2023-5884
Word Balloon Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Word Balloon WordPress plugin before 4.20.3 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to trick a logged in user to delete arbitrary avatars by clicking a link.

CVE-2023-20567
Radeon™ RX 5000/6000/7000 Series Graphics Cards Windows
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareInstaller.exe without validating the file signature potentially leading to arbitrary code execution.

CVE-2023-38429
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allocation (because of ksmbd_smb2_check_message) that may lead to out-of-bounds access.