515 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-0602
Twittee Text Tweet Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.4%
2023 1 PoC

The Twittee Text Tweet WordPress plugin through 1.0.8 does not properly escape POST values which are printed back to the user inside one of the plugin's administrative page, which allows reflected XSS attacks targeting administrators to happen.

CVE-2023-2256
Product Addons & Fields for WooCommerce Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
21.2%
2023 1 PoC

The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting.

CVE-2023-43323
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
80.8%
2023 1 PoC

mooSocial 3.1.8 is vulnerable to external service interaction on post function. When executed, the server sends a HTTP and DNS request to external server. The Parameters effected are multiple - messageText, data[wall_photo], data[userShareVideo] and data[userShareLink].

CVE-2023-40748
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
44.5%
2023 2 PoCs

PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.

CVE-2023-3460
Ultimate Member Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2023 14 PoCs

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

CVE-2023-40779
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
35.9%
2023 2 PoCs

An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL.

CVE-2023-36934
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
90.9%
2023 0 PoCs

In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content.

CVE-2023-39598
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
56.4%
2023 2 PoCs

Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitrary code via a crafted payload to the mid parameter.

CVE-2023-38646
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
94.3%
2023 45 PoCs

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

CVE-2023-44812
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
36.7%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a crafted payload to the admin_redirect_url parameter of the user login function.

CVE-2023-41599
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.0%
2023 1 PoC

An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal.

CVE-2023-46574
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2023 0 PoCs

An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.

CVE-2023-40752
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.

CVE-2023-23063
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
30.4%
2023 0 PoCs

Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFileContent.cgi.

CVE-2023-34659
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
91.9%
2023 0 PoCs

jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.

CVE-2023-6063
WP Fastest Cache Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.4%
2023 6 PoCs

The WP Fastest Cache WordPress plugin before 1.2.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

CVE-2023-49494
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.4%
2023 0 PoCs

DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component select_media_post_wangEditor.php.

CVE-2023-40755
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.3%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Callback Widget v1.0.

CVE-2023-23161
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the artname parameter under ART TYPE option in the navigation bar.