3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-0602
Twittee Text Tweet Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.4%
2023 1 PoC

The Twittee Text Tweet WordPress plugin through 1.0.8 does not properly escape POST values which are printed back to the user inside one of the plugin's administrative page, which allows reflected XSS attacks targeting administrators to happen.

CVE-2023-43323
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
80.8%
2023 1 PoC

mooSocial 3.1.8 is vulnerable to external service interaction on post function. When executed, the server sends a HTTP and DNS request to external server. The Parameters effected are multiple - messageText, data[wall_photo], data[userShareVideo] and data[userShareLink].

CVE-2023-3460
Ultimate Member Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2023 14 PoCs

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

CVE-2023-40779
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
35.9%
2023 2 PoCs

An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL.

CVE-2023-36934
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
90.9%
2023 0 PoCs

In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content.

CVE-2023-38646
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
94.3%
2023 45 PoCs

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

CVE-2023-41599
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.0%
2023 1 PoC

An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal.

CVE-2023-23063
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
30.4%
2023 0 PoCs

Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFileContent.cgi.

CVE-2023-6063
WP Fastest Cache Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.4%
2023 6 PoCs

The WP Fastest Cache WordPress plugin before 1.2.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

CVE-2023-49494
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.4%
2023 0 PoCs

DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component select_media_post_wangEditor.php.

CVE-2023-40755
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.3%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Callback Widget v1.0.

CVE-2023-23161
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the artname parameter under ART TYPE option in the navigation bar.

CVE-2023-39108
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
78.5%
2023 0 PoCs

rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Function of /classes/compareClass.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.

CVE-2023-36144
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
85.5%
2023 1 PoC

An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the device, exposing critical information about the device configuration.

CVE-2023-40924
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
61.1%
2023 1 PoC

SolarView Compact < 6.00 is vulnerable to Directory Traversal.

CVE-2023-49070
Apache OFBiz Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2023 CWE-94 7 PoCs

Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Users are recommended to upgrade to version 18.12.10

CVE-2023-2122
Image Optimizer by 10web Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
17.8%
2023 1 PoC

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter before rendering it in the plugin admin panel, leading to a reflected Cross-Site Scripting vulnerability, allowing an attacker to trick a logged in admin to execute arbitrary javascript by clicking a link.

CVE-2023-41597
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
11.5%
2023 0 PoCs

EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.

CVE-2023-38875
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.9%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'validator' parameter in '/reset-password'.

CVE-2023-24737
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.4%
2023 0 PoCs

PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /admin/convert/export_z3950.php.