3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-5360
Royal Elementor Addons and Templates Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.5%
2023 12 PoCs

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

CVE-2023-34537
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
15.8%
2023 1 PoC

A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter to trick user on browser and/or exfiltrate data.

CVE-2023-39650
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
35.0%
2023 0 PoCs

Theme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /tvcmsblog/single.

CVE-2023-37599
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
85.6%
2023 1 PoC

An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory

CVE-2023-40748
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
44.5%
2023 2 PoCs

PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.

CVE-2023-39598
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
56.4%
2023 2 PoCs

Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitrary code via a crafted payload to the mid parameter.

CVE-2023-44812
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
36.7%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a crafted payload to the admin_redirect_url parameter of the user login function.

CVE-2023-40752
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.

CVE-2023-33568
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.8%
2023 1 PoC

An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.

CVE-2023-3219
EventON Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
74.0%
2023 2 PoCs

The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of the post.

CVE-2023-2813
Aapna Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2023 1 PoC

All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite WordPress theme before 2.1, Cafe Bistro WordPress theme before 1.1.4, College WordPress theme before 1.5.1, Connections Reloaded WordPress theme through 3.1, Counterpoint WordPress theme through 1.8.1, Digitally WordPress theme through 1.0.8, Directory WordPress theme before 3.0.2, Drop

CVE-2023-39110
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
80.1%
2023 0 PoCs

rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPath.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.

CVE-2023-26258
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
79.4%
2023 5 PoCs

Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be used to execute any task as administrator.

CVE-2023-45542
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
43.3%
2023 1 PoC

Cross Site Scripting vulnerability in mooSocial 3.1.8 allows a remote attacker to obtain sensitive information via a crafted script to the q parameter in the Search function.

CVE-2023-0630
Slimstat Analytics Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
90.2%
2023 2 PoCs

The Slimstat Analytics WordPress plugin before 4.9.3.3 does not prevent subscribers from rendering shortcodes that concatenates attributes directly into an SQL query.

CVE-2023-35813
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2023 2 PoCs

Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.

CVE-2023-5559
10Web Booster Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
52.5%
2023 1 PoC

The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.

CVE-2023-47248
PyArrow Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.4%
2023 CWE-502 1 PoC

Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (for example user-supplied input files). This vulnerability only affects PyArrow, not other Apache Arrow implementations or bindings. It is recommended that users of PyArrow upgrade to 14.0.1. Similarly, it is recommended that downstream libraries upgrade their dependency requirements to PyArrow 14.0.1 or later. PyPI packages are already available, and we hope that

CVE-2023-27922
Newsletter Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.8%
2023 0 PoCs

Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script.

CVE-2023-39002
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
23.6%
2023 1 PoC

A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.