5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-23858
SAP NetWeaver AS for ABAP and ABAP Platform General
6.1
MEDIUM
EPSS
0.6%
2023 CWE-79 1 PoC

Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to send a crafted URL to a user, and by clicking the URL, the tricked user accesses SAP and might be directed with the response to somewhere out-side SAP and enter sensitive data. This could cause a limited impact on confidentiality and integrity of the application.

CVE-2023-2427
thorsten/phpmyfaq Web
6.1
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.13.

CVE-2023-4687
Page Builder: Pagelayer Web Windows
6.1
MEDIUM
EPSS
0.5%
2023 1 PoC

The Page Builder: Pagelayer WordPress plugin before 1.7.7 doesn't prevent unauthenticated attackers from updating a post's header or footer code on scheduled posts.

CVE-2023-24322
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
33.8%
2023 0 PoCs

A reflected cross-site scripting (XSS) vulnerability in the FileDialog.aspx component of mojoPortal v2.7.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ed and tbi parameters.

CVE-2023-21906
Banking Virtual Account Management Web Database
6.1
MEDIUM
EPSS
1.1%
2023 1 PoC

Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: SMS Module). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Virtual Acco

CVE-2023-24194
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in navbar.php.

CVE-2023-27666
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

Auto Dealer Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the name parameter at /classes/SystemSettings.php?f=update_settings.

CVE-2023-27739
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

easyXDM 2.5 allows XSS via the xdm_e parameter.

CVE-2023-4476
Locatoraid Store Locator Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The Locatoraid Store Locator WordPress plugin before 3.9.24 does not sanitise and escape the lpr-search parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-33763
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /scheduler/index.php.

CVE-2023-27499
GUI for HTML Web
6.1
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT does not sufficiently encode user-controlled inputs, resulting in a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could craft a malicious URL and lure the victim to click, the script supplied by the attacker will execute in the victim user's browser. The information from the victim's web browser can either be modified or read and sent to the attacker.

CVE-2023-3320
WP Sticky Social Web Windows
6.1
MEDIUM
EPSS
1.2%
2023 1 PoC

The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing nonce validation in the ~/admin/views/admin.php file. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-27293
OpenCATS Web
6.1
MEDIUM
EPSS
3.0%
2023 1 PoC

Improper neutralization of input during web page generation allows an unauthenticated attacker to submit malicious Javascript as the answer to a questionnaire which would then be executed when an authenticated user reviews the candidate's submission. This could be used to steal other users’ cookies and force users to make actions without their knowledge.

CVE-2023-0899
Steveas WP Live Chat Shoutbox Web Windows
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before outputting it back in the Shoutbox, leading to Stored Cross-Site Scripting which could be used against high privilege users such as admins.

CVE-2023-49540
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2023 2 PoCs

Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/history. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the history parameter.

CVE-2023-0187
vGPU software (guest driver - Windows), NVIDIA Cloud Gaming (guest driver - Windows) Cloud Windows
6.1
MEDIUM
EPSS
0.1%
2023 CWE-125 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds read can lead to denial of service.

CVE-2023-36918
SAP Enable Now Web
6.1
MEDIUM
EPSS
0.6%
2023 CWE-79 1 PoC

In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-Content-Type-Options response header is not implemented, allowing an unauthenticated attacker to trigger MIME type sniffing, which leads to Cross-Site Scripting, which could result in disclosure or modification of information.

CVE-2023-4294
URL Shortify Web Windows
6.1
MEDIUM
EPSS
32.4%
2023 2 PoCs

The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing an unauthenticated attacker to inject malicious javascript that will trigger in the plugins admin panel with statistics of the created short link.

CVE-2023-0186
vGPU software (guest driver - Windows), NVIDIA Cloud Gaming (guest driver - Windows) Cloud Windows
6.1
MEDIUM
EPSS
0.1%
2023 CWE-787 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an out-of-bounds write can lead to denial of service and data tampering.

CVE-2023-48903
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

Stored Cross-Site Scripting (XSS) vulnerability in tramyardg autoexpress 1.3.0, allows remote unauthenticated attackers to inject arbitrary web script or HTML within parameter "imgType" via in uploadCarImages.php.