515 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-37728
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
17.3%
2023 2 PoCs

IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter.

CVE-2023-41642
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
17.0%
2023 1 PoC

Multiple reflected cross-site scripting (XSS) vulnerabilities in the ErroreNonGestito.aspx component of GruppoSCAI RealGimm 1.1.37p38 allow attackers to execute arbitrary Javascript in the context of a victim user's browser via a crafted payload injected into the VIEWSTATE parameter.

CVE-2023-26258
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
79.4%
2023 5 PoCs

Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be used to execute any task as administrator.

CVE-2023-6114
Duplicator Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
61.3%
2023 2 PoCs

The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup-pro/tmp` directory in the Pro version), which temporarily stores files containing sensitive data. When directory listing is enabled in the web server, this allows unauthenticated attackers to discover and access these sensitive files, which include a full database dump and a zip archive of the site.

CVE-2023-38992
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
64.1%
2023 0 PoCs

jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.

CVE-2023-38433
IP-HE950E General ⚡ nuclei
N/A
UNKNOWN
EPSS
53.2%
2023 0 PoCs

Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or reboot the products, and as a result, terminate the video transmission. Affected products and versions are as follows: IP-HE950E firmware versions V01L001 to V01L053, IP-HE950D firmware versions V01L001 to V01L053, IP-HE900E firmware versions V01L001 to V01L010, IP-HE900D firmware versions V01L001 to V01L004, IP-900E / IP-920E firmware versions V01L001 to V02L061, IP-900D / IP-900ⅡD / IP-920D firmware versions V01L001 to V02L061, IP-90 firmware ve

CVE-2023-45542
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
43.3%
2023 1 PoC

Cross Site Scripting vulnerability in mooSocial 3.1.8 allows a remote attacker to obtain sensitive information via a crafted script to the q parameter in the Search function.

CVE-2023-39121
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
2.7%
2023 0 PoCs

emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.

CVE-2023-28121
WooCommerce Payments WordPress Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.7%
2023 CWE-287 8 PoCs

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

CVE-2023-0630
Slimstat Analytics Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
90.2%
2023 2 PoCs

The Slimstat Analytics WordPress plugin before 4.9.3.3 does not prevent subscribers from rendering shortcodes that concatenates attributes directly into an SQL query.

CVE-2023-35813
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2023 2 PoCs

Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.

CVE-2023-2624
KiviCare Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
9.3%
2023 2 PoCs

The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrator

CVE-2023-5559
10Web Booster Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
52.5%
2023 1 PoC

The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.

CVE-2023-48084
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
82.1%
2023 2 PoCs

Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.

CVE-2023-47248
PyArrow Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.4%
2023 CWE-502 1 PoC

Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (for example user-supplied input files). This vulnerability only affects PyArrow, not other Apache Arrow implementations or bindings. It is recommended that users of PyArrow upgrade to 14.0.1. Similarly, it is recommended that downstream libraries upgrade their dependency requirements to PyArrow 14.0.1 or later. PyPI packages are already available, and we hope that

CVE-2023-36347
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
84.5%
2023 2 PoCs

A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data.

CVE-2023-27922
Newsletter Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.8%
2023 0 PoCs

Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script.

CVE-2023-37679
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.4%
2023 2 PoCs

A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.

CVE-2023-39002
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
23.6%
2023 1 PoC

A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2023-5652
WP Hotel Booking Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
66.6%
2023 1 PoC

The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a function hooked to admin_init, allowing unauthenticated users to perform SQL injections