3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-0159
Extensive VC Addons for WPBakery page builder Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
92.7%
2023 1 PoC

The Extensive VC Addons for WPBakery page builder WordPress plugin before 1.9.1 does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated attacker to override the template path to read arbitrary files from the hosts file system. This may be escalated to RCE using PHP filter chains.

CVE-2023-40751
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.8%
2023 2 PoCs

PHPJabbers Fundraising Script v1.0 is vulnerable to Cross Site Scripting (XSS) via the "action" parameter of index.php.

CVE-2023-43177
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
76.1%
2023 2 PoCs

CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.

CVE-2023-50968
Apache OFBiz Web ⚡ nuclei
N/A
UNKNOWN
EPSS
83.9%
2023 CWE-200 0 PoCs

Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. The same uri can be operated to realize a SSRF attack also without authorizations. Users are recommended to upgrade to version 18.12.11, which fixes this issue.

CVE-2023-44813
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
20.8%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a crafted payload to the mode parameter of the invite friend login function.

CVE-2023-2178
Aajoda Testimonials Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.1%
2023 1 PoC

The Aajoda Testimonials WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-49230
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
31.1%
2023 0 PoCs

An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows attackers to modify the portals' configurations without prior authentication.

CVE-2023-34960
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2023 12 PoCs

A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.

CVE-2023-38194
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.3%
2023 1 PoC

An issue was discovered in SuperWebMailer 9.00.0.01710. It allows keepalive.php XSS via a GET parameter.

CVE-2023-2272
Tiempo.com Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
14.1%
2023 1 PoC

The Tiempo.com WordPress plugin through 0.1.2 does not sanitise and escape the page parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-45375
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
87.8%
2023 1 PoC

In the module "PireosPay" (pireospay) before version 1.7.10 from 01generator.com for PrestaShop, a guest can perform SQL injection via `PireosPayValidationModuleFrontController::postProcess().`

CVE-2023-24735
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.1%
2023 0 PoCs

PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerability allows attackers to redirect victim users to an external domain via a crafted URL.

CVE-2023-6065
Quttera Web Malware Scanner Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
37.5%
2023 2 PoCs

The Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 doesn't restrict access to detailed scan logs, which allows a malicious actor to discover local paths and portions of the site's code

CVE-2023-39141
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
85.6%
2023 2 PoCs

webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.

CVE-2023-26469
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.0%
2023 2 PoCs

In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.

CVE-2023-27847
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
73.1%
2023 1 PoC

SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges via the xipcategoryclass and xippostsclass components.

CVE-2023-34843
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2023 3 PoCs

Traggo Server 0.3.0 is vulnerable to directory traversal via a crafted GET request.

CVE-2023-38879
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
12.0%
2023 1 PoC

The Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to read arbitrary files via a directory traversal vulnerability in the 'filename' parameter of 'DownloadWindow.php'.

CVE-2023-39109
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
78.5%
2023 0 PoCs

rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Function of /classes/compareClass.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.

CVE-2023-38192
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.4%
2023 1 PoC

An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords.