515 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-43187
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.7%
2023 0 PoCs

A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests.

CVE-2023-39108
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
78.5%
2023 0 PoCs

rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Function of /classes/compareClass.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.

CVE-2023-33568
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.8%
2023 1 PoC

An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.

CVE-2023-36144
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
85.5%
2023 1 PoC

An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the device, exposing critical information about the device configuration.

CVE-2023-27641
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.7%
2023 0 PoCs

The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XSS attacks via a crafted URL.

CVE-2023-40924
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
61.1%
2023 1 PoC

SolarView Compact < 6.00 is vulnerable to Directory Traversal.

CVE-2023-40750
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Yacht Listing Script v1.0.

CVE-2023-49070
Apache OFBiz Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2023 CWE-94 7 PoCs

Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Users are recommended to upgrade to version 18.12.10

CVE-2023-2122
Image Optimizer by 10web Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
17.8%
2023 1 PoC

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter before rendering it in the plugin admin panel, leading to a reflected Cross-Site Scripting vulnerability, allowing an attacker to trick a logged in admin to execute arbitrary javascript by clicking a link.

CVE-2023-3219
EventON Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
74.0%
2023 2 PoCs

The EventON WordPress plugin before 2.1.2 does not validate that the event_id parameter in its eventon_ics_download ajax action is a valid Event, allowing unauthenticated visitors to access any Post (including unpublished or protected posts) content via the ics export functionality by providing the numeric id of the post.

CVE-2023-41597
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
11.5%
2023 0 PoCs

EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.

CVE-2023-38875
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.9%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'validator' parameter in '/reset-password'.

CVE-2023-0099
Simple URLs Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
70.1%
2023 3 PoCs

The Simple URLs WordPress plugin before 115 does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-2813
Aapna Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2023 1 PoC

All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite WordPress theme before 2.1, Cafe Bistro WordPress theme before 1.1.4, College WordPress theme before 1.5.1, Connections Reloaded WordPress theme through 3.1, Counterpoint WordPress theme through 1.8.1, Digitally WordPress theme through 1.0.8, Directory WordPress theme before 3.0.2, Drop

CVE-2023-24737
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.4%
2023 0 PoCs

PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /admin/convert/export_z3950.php.

CVE-2023-39110
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
80.1%
2023 0 PoCs

rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPath.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.

CVE-2023-36306
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
5.3%
2023 1 PoC

A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the asktheoracle.php, details.php, index.php, search.php, export.php, reports.php, and statistics.php components.

CVE-2023-39676
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
6.1%
2023 1 PoC

FieldPopupNewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback parameter at ajax.php.

CVE-2023-24733
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
14.9%
2023 0 PoCs

PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /admin/convert/export_z3950_new.php.

CVE-2023-43325
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
19.7%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the data[redirect_url] parameter of mooSocial v3.1.8 allows attackers to steal user's session cookies and impersonate their account via a crafted URL.