515 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-3848
mooDating General ⚡ nuclei
3.5
LOW
EPSS
7.6%
2023 CWE-79 2 PoCs

A vulnerability, which was classified as problematic, has been found in mooSocial mooDating 1.2. This issue affects some unknown processing of the file /users/view of the component URL Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-235199. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.

CVE-2023-6275
Fluig Platform General ⚡ nuclei
3.5
LOW
EPSS
52.5%
2023 CWE-79 3 PoCs

A vulnerability was found in TOTVS Fluig Platform 1.6.x/1.7.x/1.8.0/1.8.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /mobileredir/openApp.jsp of the component mobileredir. The manipulation of the argument redirectUrl/user with the input "><script>alert(document.domain)</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.7.1-231128, 1.8.0-231127 and 1.8.1-231127 is able to address this issue. It is recommended to upgrade the affec

CVE-2023-3849
mooDating General ⚡ nuclei
3.5
LOW
EPSS
5.8%
2023 CWE-79 1 PoC

A vulnerability, which was classified as problematic, was found in mooSocial mooDating 1.2. Affected is an unknown function of the file /find-a-match of the component URL Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-235200. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.

CVE-2023-4173
mooStore General ⚡ nuclei
3.5
LOW
EPSS
8.2%
2023 CWE-79 1 PoC

A vulnerability, which was classified as problematic, was found in mooSocial mooStore 3.1.6. Affected is an unknown function of the file /search/index. The manipulation of the argument q leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-236208.

CVE-2023-0527
Online Security Guards Hiring System Web ⚡ nuclei
3.5
LOW
EPSS
9.0%
2023 CWE-79 2 PoCs

A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file search-request.php. The manipulation of the argument searchdata with the input "><script>alert(document.domain)</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-219596.

CVE-2023-4174
mooStore General ⚡ nuclei
3.5
LOW
EPSS
57.8%
2023 CWE-79 3 PoCs

A vulnerability has been found in mooSocial mooStore 3.1.6 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. The identifier VDB-236209 was assigned to this vulnerability.

CVE-2023-4547
eCommerce CMS Web ⚡ nuclei
3.5
LOW
EPSS
9.1%
2023 CWE-79 1 PoC

A vulnerability was found in SPA-Cart eCommerce CMS 1.9.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /search. The manipulation of the argument filter[brandid]/filter[price] leads to cross site scripting. The attack may be launched remotely. VDB-238058 is the identifier assigned to this vulnerability.

CVE-2023-0563
Bank Locker Management System Web ⚡ nuclei
3.5
LOW
EPSS
32.7%
2023 CWE-79 0 PoCs

A vulnerability classified as problematic has been found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown part of the file add-locker-form.php of the component Assign Locker. The manipulation of the argument ahname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-219717 was assigned to this vulnerability.

CVE-2023-3845
mooDating General ⚡ nuclei
3.5
LOW
EPSS
7.6%
2023 CWE-79 1 PoC

A vulnerability was found in mooSocial mooDating 1.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /friends/ajax_invite of the component URL Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-235196. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.

CVE-2023-4973
LMS Windows ⚡ nuclei
3.5
LOW
EPSS
5.0%
2023 CWE-79 2 PoCs

A vulnerability was found in Academy LMS 6.2 on Windows. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /academy/tutor/filter of the component GET Parameter Handler. The manipulation of the argument searched_word/searched_tution_class_type[]/searched_price_type[]/searched_duration[] leads to cross site scripting. The attack can be launched remotely. The identifier VDB-239749 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-47643
SuiteCRM-Core Web ⚡ nuclei
3.1
LOW
EPSS
49.6%
2023 CWE-200 0 PoCs

SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.4.2, Graphql Introspection is enabled without authentication, exposing the scheme defining all object types, arguments, and functions. An attacker can obtain the GraphQL schema and understand the entire attack surface of the API, including sensitive fields such as UserHash. This issue is patched in version 8.4.2. There are no known workarounds.

CVE-2023-2252
Directorist Web Windows ⚡ nuclei
2.7
LOW
EPSS
7.8%
2023 1 PoC

The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.

CVE-2023-0676
phpipam/phpipam Web ⚡ nuclei
2.4
LOW
EPSS
1.0%
2023 CWE-79 2 PoCs

Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1.

CVE-2023-27847
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
73.1%
2023 1 PoC

SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges via the xipcategoryclass and xippostsclass components.

CVE-2023-34843
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2023 3 PoCs

Traggo Server 0.3.0 is vulnerable to directory traversal via a crafted GET request.

CVE-2023-39650
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
35.0%
2023 0 PoCs

Theme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /tvcmsblog/single.

CVE-2023-38879
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
12.0%
2023 1 PoC

The Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to read arbitrary files via a directory traversal vulnerability in the 'filename' parameter of 'DownloadWindow.php'.

CVE-2023-39109
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
78.5%
2023 0 PoCs

rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Function of /classes/compareClass.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.

CVE-2023-37599
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
85.6%
2023 1 PoC

An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory

CVE-2023-38192
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.4%
2023 1 PoC

An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords.