5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-7109
Library Management System Web Database
7.3
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability classified as critical was found in code-projects Library Management System 2.0. This vulnerability affects unknown code of the file /admin/login.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249004.

CVE-2023-0324
Online Tours & Travels Management System Web Database
7.3
HIGH
EPSS
0.4%
2023 CWE-89 1 PoC

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/page-login.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-218426 is the identifier assigned to this vulnerability.

CVE-2023-6007
UserPro - Community and User Profile WordPress Plugin Web Windows
7.3
HIGH
EPSS
0.2%
2023 CWE-862 1 PoC

The UserPro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 5.1.1. This makes it possible for unauthenticated attackers to add, modify, or delete user meta and plugin options.

CVE-2023-0917
Simple Customer Relationship Management System Web Database
7.3
HIGH
EPSS
0.3%
2023 CWE-89 1 PoC

A vulnerability, which was classified as critical, was found in SourceCodester Simple Customer Relationship Management System 1.0. This affects an unknown part of the file /php-scrm/login.php. The manipulation of the argument Password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221493 was assigned to this vulnerability.

CVE-2023-37219
Telecom Composit General
7.3
HIGH
EPSS
0.1%
2023 CWE-1236 1 PoC

Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV File

CVE-2023-1037
Dental Clinic Appointment Reservation System Web Database
7.3
HIGH
EPSS
0.4%
2023 CWE-89 1 PoC

A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /APR/login.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221795.

CVE-2023-7210
OneNav Web
7.3
HIGH
EPSS
0.1%
2023 CWE-287 1 PoC

A vulnerability was found in OneNav up to 0.9.33. It has been classified as critical. This affects an unknown part of the file /index.php?c=api of the component API. The manipulation of the argument X-Token leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249765 was assigned to this vulnerability.

CVE-2023-5521
tiann/kernelsu General
7.3
HIGH
EPSS
0.5%
2023 CWE-863 2 PoCs

Incorrect Authorization in GitHub repository tiann/kernelsu prior to v0.6.9.

CVE-2023-6651
Matrimonial Site Web Database
7.3
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability was found in code-projects Matrimonial Site 1.0. It has been classified as critical. Affected is an unknown function of the file /auth/auth.php?user=1. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247344.

CVE-2023-3643
Boss Mini General ⚡ nuclei
7.3
HIGH
EPSS
40.7%
2023 CWE-73 1 PoC

A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233889 was assigned to this vulnerability.

CVE-2023-0054
vim/vim General
7.3
HIGH
EPSS
0.0%
2023 CWE-787 1 PoC

Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145.

CVE-2023-0332
Online Food Ordering System Web Database
7.3
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been classified as critical. Affected is an unknown function of the file admin/manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-218472.

CVE-2023-6848
kodbox Web
7.3
HIGH
EPSS
1.0%
2023 CWE-77 1 PoC

A vulnerability was found in kalcaddle kodbox up to 1.48. It has been declared as critical. Affected by this vulnerability is the function check of the file plugins/officeViewer/controller/libreOffice/index.class.php. The manipulation of the argument soffice leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.48.04 is able to address this issue. The identifier of the patch is 63a4d5708d210f119c24afd941d01a943e25334c. It is recommended to upgrade the affected component. The identifier VDB-248209 wa

CVE-2023-4590
Frhed General
7.3
HIGH
EPSS
0.4%
2023 CWE-120 1 PoC

Buffer overflow vulnerability in Frhed hex editor, affecting version 1.6.0. This vulnerability could allow an attacker to execute arbitrary code via a long filename argument through the Structured Exception Handler (SEH) registers.

CVE-2023-3693
Life Insurance Management System Web Database
7.3
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability classified as critical was found in SourceCodester Life Insurance Management System 1.0. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-234244.

CVE-2023-1175
vim/vim General
7.3
HIGH
EPSS
0.0%
2023 CWE-131 1 PoC

Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.

CVE-2023-4415
RG-EW1200G Web ⚡ nuclei
7.3
HIGH
EPSS
90.0%
2023 CWE-287 2 PoCs

A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/sys/login. The manipulation leads to improper authentication. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-237518 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-1127
vim/vim General
7.3
HIGH
EPSS
0.0%
2023 CWE-369 1 PoC

Divide By Zero in GitHub repository vim/vim prior to 9.0.1367.

CVE-2023-22319
MilesightVPN Networking Database
7.3
HIGH
EPSS
0.0%
2023 CWE-89 2 PoCs

A sql injection vulnerability exists in the requestHandlers.js LoginAuth functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to authentication bypass. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2023-46047
Software Genérico General
7.3
HIGH
EPSS
0.0%
2023 1 PoC

An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function. NOTE: this is disputed because there is no expectation that the product should be starting with an attacker-controlled configuration file.