33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-0488
pyload/pyload Web
9.6
CRITICAL
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pyload/pyload prior to 0.5.0b3.dev42.

CVE-2023-28347
Software Genérico Web Windows
9.6
CRITICAL
EPSS
1.7%
2023 2 PoCs

An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a proof-of-concept script that functions similarly to a Student Console, providing unauthenticated attackers with the ability to exploit XSS vulnerabilities within the Teacher Console application and achieve remote code execution as NT AUTHORITY/SYSTEM on all connected Student Consoles and the Teacher Console in a Zero Click manner.

CVE-2023-48728
AVideo Web ⚡ nuclei
9.6
CRITICAL
EPSS
17.4%
2023 CWE-79 2 PoCs

A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.

CVE-2023-6753
mlflow/mlflow General
9.6
CRITICAL
EPSS
2.4%
2023 CWE-22 1 PoC

Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2.

CVE-2023-5820
Thumbnail Slider With Lightbox Web Windows
9.6
CRITICAL
EPSS
0.1%
2023 1 PoC

The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the addedit functionality. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-3526
CLOUD CLIENT 1101T-TX/TX Web Networking Cloud
9.6
CRITICAL
EPSS
0.7%
2023 CWE-79 2 PoCs

In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an unauthenticated remote attacker could use a reflective XSS within the license viewer page of the devices in order to execute code in the context of the user's browser.

CVE-2023-5212
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Web Windows
9.6
CRITICAL
EPSS
0.3%
2023 CWE-22 1 PoC

The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as well as version 4.9.2. This makes it possible for authenticated attackers with subscriber privileges to delete arbitrary files on the server, which makes it possible to take over affected sites as well as others sharing the same hosting account. Version 4.9.1 originally addressed the issue, but it was reintroduced in 4.9.2 and fixed again in 4.9.3.

CVE-2023-7018
huggingface/transformers General
9.6
CRITICAL
EPSS
0.2%
2023 CWE-502 1 PoC

Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.

CVE-2023-51219
Software Genérico Web
9.6
CRITICAL
EPSS
0.7%
2023 1 PoC

A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to run any attacker-controlled JavaScript within a WebView. The impact was further escalated by triggering another WebView that leaked its access token in a HTTP request header. Ultimately, this access token could be used to take over another user's account and read her/his chat messages.

CVE-2023-48974
Software Genérico General
9.6
CRITICAL
EPSS
6.6%
2023 1 PoC

Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script to the serverName_input parameter.

CVE-2023-33242
Wallet General
9.6
CRITICAL
EPSS
5.8%
2023 2 PoCs

Crypto wallets implementing the Lindell17 TSS protocol might allow an attacker to extract the full ECDSA private key by exfiltrating a single bit in every signature attempt (256 in total) because of not adhering to the paper's security proof's assumption regarding handling aborts after a failed signature.

CVE-2023-1720
Bitrix24 Web
9.6
CRITICAL
EPSS
1.0%
2023 CWE-434 1 PoC

Lack of mime type response header in Bitrix24 22.0.300 allows authenticated remote attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via uploading a crafted HTML file through /desktop_app/file.ajax.php?action=uploadfile.

CVE-2023-5241
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Web Windows
9.6
CRITICAL
EPSS
2.4%
2023 CWE-22 1 PoC

The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level attackers to append "<?php" to any existing file on the server resulting in potential DoS when appended to critical files such as wp-config.php.

CVE-2023-41265
🔥 KEV Software Genérico Web Windows ⚡ nuclei
9.6
CRITICAL
EPSS
92.4%
2023 1 PoC

An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their privilege by tunneling HTTP requests in the raw HTTP request. This allows them to send requests that get executed by the backend server hosting the repository application. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.

CVE-2023-33241
Wallet General
9.6
CRITICAL
EPSS
0.3%
2023 1 PoC

Crypto wallets implementing the GG18 or GG20 TSS protocol might allow an attacker to extract a full ECDSA private key by injecting a malicious pallier key and cheating in the range proof. Depending on the Beta parameters chosen in the protocol implementation, the attack might require 16 signatures or more fully exfiltrate the other parties' private key shares.

CVE-2023-39213
Zoom Desktop Client for Windows and Zoom VDI Client Windows
9.6
CRITICAL
EPSS
1.0%
2023 CWE-176 1 PoC

Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticated user to enable an escalation of privilege via network access.

CVE-2024-38889
Software Genérico Database
9.6
CRITICAL
EPSS
0.3%
2024 1 PoC

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of special elements used in an SQL command.

CVE-2024-9148
FlowiseChatEmbed Web
9.6
CRITICAL
EPSS
1.9%
2024 CWE-79 1 PoC

Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.

CVE-2024-12641
TenderDocTransfer Web
9.6
CRITICAL
EPSS
35.7%
2024 CWE-79 1 PoC

TenderDocTransfer from Chunghwa Telecom has a Reflected Cross-site scripting vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use specific APIs through phishing to execute arbitrary JavaScript code in the user’s browser. Since the web server set by the application supports Node.Js features, attackers can further leverage this to run OS commands.

CVE-2024-23674
Software Genérico General
9.6
CRITICAL
EPSS
0.1%
2024 1 PoC

The Online-Ausweis-Funktion eID scheme in the German National Identity card through 2024-02-15 allows authentication bypass by spoofing. A man-in-the-middle attacker can assume a victim's identify for access to government, medical, and financial resources, and can also extract personal data from the card, aka the "sPACE (Spoofing Password Authenticated Connection Establishment)" issue. This occurs because of a combination of factors, such as insecure PIN entry (for basic readers) and eid:// deeplinking. The victim must be using a modified eID kernel, which may occur if the victim is tricked in