728 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-2227
modoboa/modoboa General ⚡ nuclei
9.1
CRITICAL
EPSS
90.5%
2023 CWE-285 1 PoC

Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0.

CVE-2023-23459
Priority for Windows Database Windows
9.1
CRITICAL
EPSS
0.4%
2023 CWE-89 1 PoC

Priority Windows may allow Command Execution via SQL Injection using an unspecified method.

CVE-2023-1722
Yoga Class Registration System General
9.1
CRITICAL
EPSS
0.1%
2023 CWE-352 2 PoCs

Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators.

CVE-2023-25725
Software Genérico Web
9.1
CRITICAL
EPSS
20.0%
2023 2 PoCs

HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3, the impact is limited because the headers disappear before being parsed and processed, as if they had not been sent by the client. The fixed versions are 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31

CVE-2023-32071
xwiki-platform Web Networking
9.1
CRITICAL
EPSS
46.8%
2023 CWE-116 1 PoC

XWiki Platform is a generic wiki platform. Starting in versions 2.2-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, it's possible to execute javascript with the right of any user by leading him to a special URL on the wiki targeting a page which contains an attachment. This has been patched in XWiki 15.0-rc-1, 14.10.4, and 14.4.8. The easiest possible workaround is to edit file `<xwiki app>/templates/importinline.vm` and apply the modification described in commit 28905f7f518cc6f21ea61fe37e9e1ed97ef36f01.

CVE-2023-29386
Manager for Icomoon General
9.1
CRITICAL
EPSS
0.3%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Julien Crego Manager for Icomoon.This issue affects Manager for Icomoon: from n/a through 2.0.

CVE-2023-36922
SAP ECC and SAP S/4HANA (IS-OIL) General
9.1
CRITICAL
EPSS
0.2%
2023 CWE-78 1 PoC

Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension.  On successful exploitation, the attacker can read or modify the system data as well as shut down the system.

CVE-2023-29201
xwiki-commons Web
9.1
CRITICAL
EPSS
9.3%
2023 CWE-79 1 PoC

XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1, only escaped `<script>` and `<style>`-tags but neither attributes that can be used to inject scripts nor other dangerous HTML tags like `<iframe>`. As a consequence, any code relying on this "restricted" mode for security is vulnerable to JavaScript injection ("cross-site scripting"/XSS). When a privileged user with programming rights visits such a comment in XWiki, the malicious JavaScript code is executed in the con

CVE-2023-7006
Kontrol Lux General
9.1
CRITICAL
EPSS
0.1%
2023 1 PoC

The unlockKey character in a lock using Sciener firmware can be brute forced through repeated challenge requests, compromising the locks integrity.

CVE-2023-31056
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2023 1 PoC

CloverDX before 5.17.3 writes passwords to the audit log in certain situations, if the audit log is enabled and single sign-on is not employed. The fixed versions are 5.15.4, 5.16.2, 5.17.3, and 6.0.x.

CVE-2023-1721
Yoga Class Registration System General
9.1
CRITICAL
EPSS
0.1%
2023 CWE-434 2 PoCs

Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators.

CVE-2023-29528
xwiki-commons Web
9.1
CRITICAL
EPSS
3.2%
2023 CWE-79 2 PoCs

XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1 and massively improved in version 14.6-rc-1, allowed the injection of arbitrary HTML code and thus cross-site scripting via invalid HTML comments. As a consequence, any code relying on this "restricted" mode for security is vulnerable to JavaScript injection ("cross-site scripting"/XSS). When a privileged user with programming rights visits such a comment in XWiki, the malicious JavaScript code is executed in the conte

CVE-2023-52735
Linux Web
9.1
CRITICAL
EPSS
0.0%
2023 1 PoC

In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Don't let sock_map_{close,destroy,unhash} call itself sock_map proto callbacks should never call themselves by design. Protect against bugs like [1] and break out of the recursive loop to avoid a stack overflow in favor of a resource leak. [1] https://lore.kernel.org/all/00000000000073b14905ef2e7401@google.com/

CVE-2023-36471
xwiki-commons General
9.1
CRITICAL
EPSS
0.9%
2023 CWE-74 1 PoC

Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki since version 14.6RC1 allowed form and input HTML tags. In the context of XWiki, this allows an attacker without script right to either create forms that can be used for phishing attacks or also in the context of a sheet, the attacker could add an input like `{{html}}<input type="hidden" name="content" value="{{groovy}}println(&quot;Hello from Groovy!&quot;)" />{{/html}}` that would allow remote code execution when it is submitted by an admin (the sheet is rendered as part o

CVE-2023-48023
Software Genérico General ⚡ nuclei
9.1
CRITICAL
EPSS
89.2%
2023 0 PoCs

Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment

CVE-2023-32070
xwiki-rendering Web
9.1
CRITICAL
EPSS
4.7%
2023 CWE-83 1 PoC

XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki syntax. This has been patched in XWiki 14.6-rc-1. There are no known workarounds apart from upgrading to a fixed version.

CVE-2023-29519
xwiki-platform General
9.1
CRITICAL
EPSS
4.7%
2023 CWE-74 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A registered user can perform remote code execution leading to privilege escalation by injecting the proper code in the "property" field of an attachment selector, as a gadget of their own dashboard. Note that the vulnerability does not impact comments of a wiki. The vulnerability has been patched in XWiki 13.10.11, 14.4.8, 14.10.2, 15.0-rc-1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2023-0306
thorsten/phpmyfaq Web
9.1
CRITICAL
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

CVE-2023-5832
mintplex-labs/anything-llm General
9.1
CRITICAL
EPSS
0.1%
2023 CWE-20 1 PoC

Improper Input Validation in GitHub repository mintplex-labs/anything-llm prior to 0.1.0.

CVE-2023-49785
NextChat Web ⚡ nuclei
9.1
CRITICAL
EPSS
90.4%
2023 CWE-918 1 PoC

NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 and prior are vulnerable to server-side request forgery and cross-site scripting. This vulnerability enables read access to internal HTTP endpoints but also write access using HTTP POST, PUT, and other methods. Attackers can also use this vulnerability to mask their source IP by forwarding malicious traffic intended for other Internet targets through these open proxies. As of time of publication, no patch is available, but other mitigation strategies are available. Users may