5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-2302
Contact Form and Calls To Action by vcita Web Windows
6.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with the edit_posts capability, such as contributors and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2023-5817
Neon text Web Windows
6.4
MEDIUM
EPSS
0.1%
2023 CWE-79 2 PoCs

The Neon text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's neontext_box shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes (color). This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2023-4158
omeka/omeka-s Web
6.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.3.

CVE-2023-6335
Workforce Access Windows
6.4
MEDIUM
EPSS
0.1%
2023 CWE-59 1 PoC

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled Filename.This issue affects Workforce Access: before 8.7.

CVE-2023-5350
salesagility/suitecrm Database
6.4
MEDIUM
EPSS
15.3%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.

CVE-2023-33203
Software Genérico General
6.4
MEDIUM
EPSS
0.0%
2023 2 PoCs

The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/net/ethernet/qualcomm/emac/emac.c if a physically proximate attacker unplugs an emac based device.

CVE-2023-28153
Software Genérico General
6.4
MEDIUM
EPSS
0.1%
2023 1 PoC

An issue was discovered in the Kiddoware Kids Place Parental Control application before 3.8.50 for Android. The child can remove all restrictions temporarily without the parents noticing by rebooting into Android Safe Mode and disabling the "Display over other apps" permission.

CVE-2023-42961
iOS and iPadOS General
6.3
MEDIUM
EPSS
0.4%
2023 1 PoC

A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, iOS 16.7 and iPadOS 16.7, macOS Sonoma 14, macOS Ventura 13.6, macOS Monterey 12.7. A sandboxed process may be able to circumvent sandbox restrictions.

CVE-2023-6575
S210 Web Database
6.3
MEDIUM
EPSS
0.0%
2023 CWE-89 1 PoC

A vulnerability was found in Byzoro S210 up to 20231121. It has been classified as critical. This affects an unknown part of the file /Tool/repair.php of the component HTTP POST Request Handler. The manipulation of the argument txt leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-247155. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-4931
Plesk Installer Web
6.3
MEDIUM
EPSS
0.0%
2023 CWE-427 1 PoC

Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execute arbitrary code by injecting DLL files into the same folder where the application is installed, resulting in DLL hijacking in edputil.dll, samlib.dll, urlmon.dll, sspicli.dll, propsys.dll and profapi.dll files.

CVE-2023-3457
Shopping Website Web Database
6.3
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-232674 is the identifier assigned to this vulnerability.

CVE-2023-5471
Farmacia Web Database
6.3
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability, which was classified as critical, was found in codeprojects Farmacia 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument usario/senha leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-241608.

CVE-2023-2215
Coffee Shop POS System Web Database
6.3
MEDIUM
EPSS
4.7%
2023 CWE-89 1 PoC

A vulnerability classified as critical has been found in Campcodes Coffee Shop POS System 1.0. Affected is an unknown function of the file /admin/user/manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226980.

CVE-2023-2693
Online Exam System Database
6.3
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability was found in SourceCodester Online Exam System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /mahasiswa/data of the component POST Parameter Handler. The manipulation of the argument columns[1][data] leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-228974 is the identifier assigned to this vulnerability.

CVE-2023-2378
EdgeRouter X Networking
6.3
MEDIUM
EPSS
13.7%
2023 CWE-77 1 PoC

A vulnerability was found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. It has been rated as critical. Affected by this issue is some unknown functionality of the component Web Management Interface. The manipulation of the argument suffix-rate-up leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-227654 is the identifier assigned to this vulnerability.

CVE-2023-4448
RapidCMS Web
6.3
MEDIUM
EPSS
0.1%
2023 CWE-640 1 PoC

A vulnerability was found in OpenRapid RapidCMS 1.3.1 and classified as critical. This issue affects some unknown processing of the file admin/run-movepass.php. The manipulation of the argument password/password2 leads to weak password recovery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 4dff387283060961c362d50105ff8da8ea40bcbe. It is recommended to apply a patch to fix this issue. The identifier VDB-237569 was assigned to this vulnerability.

CVE-2023-0648
dst-admin General
6.3
MEDIUM
EPSS
6.3%
2023 CWE-77 1 PoC

A vulnerability, which was classified as critical, was found in dst-admin 1.5.0. This affects an unknown part of the file /home/masterConsole. The manipulation of the argument command leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-220035.

CVE-2023-3150
Online Discussion Forum Site Web Database
6.3
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file posts\manage_post.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-231019.

CVE-2023-6308
Video Surveillance Management System Web Cloud
6.3
MEDIUM
EPSS
0.3%
2023 CWE-434 1 PoC

A vulnerability, which was classified as critical, has been found in Xiamen Four-Faith Video Surveillance Management System 2016/2017. Affected by this issue is some unknown functionality of the component Apache Struts. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-246134 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-3850
Lost and Found Information System Web Database
6.3
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability has been found in SourceCodester Lost and Found Information System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=delete_category of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The identifier VDB-235201 was assigned to this vulnerability.