3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-0099
Simple URLs Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
70.1%
2023 3 PoCs

The Simple URLs WordPress plugin before 115 does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-2624
KiviCare Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
9.3%
2023 2 PoCs

The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrator

CVE-2023-5652
WP Hotel Booking Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
66.6%
2023 1 PoC

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a function hooked to admin_init, allowing unauthenticated users to perform SQL injections

CVE-2023-45852
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2023 0 PoCs

In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell metacharacters in the ipaddr params JSON data for the put method.

CVE-2023-3139
Protect WP Admin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.4%
2023 1 PoC

The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered.

CVE-2023-2256
Product Addons & Fields for WooCommerce Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
21.2%
2023 1 PoC

The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting.

CVE-2023-46574
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2023 0 PoCs

An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.

CVE-2023-34659
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
91.9%
2023 0 PoCs

jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.

CVE-2023-43187
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.7%
2023 0 PoCs

A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests.

CVE-2023-27641
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.7%
2023 0 PoCs

The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XSS attacks via a crafted URL.

CVE-2023-40750
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Yacht Listing Script v1.0.

CVE-2023-24733
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
14.9%
2023 0 PoCs

PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /admin/convert/export_z3950_new.php.

CVE-2023-37679
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.4%
2023 2 PoCs

A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.

CVE-2023-40749
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
44.5%
2023 2 PoCs

PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.

CVE-2023-40753
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the message parameter of index.php in PHPJabbers Ticket Support Script v3.2.

CVE-2023-38040
Revive Adserver Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.6%
2023 0 PoCs

A reflected XSS vulnerability exists in Revive Adserver 5.4.1 and earlier versions..

CVE-2023-5991
Hotel Booking Lite Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
78.3%
2023 1 PoC

The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server

CVE-2023-39560
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
68.4%
2023 0 PoCs

ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php.

CVE-2023-28343
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.2%
2023 4 PoCs

OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php.