515 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-0159
Extensive VC Addons for WPBakery page builder Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
92.7%
2023 1 PoC

The Extensive VC Addons for WPBakery page builder WordPress plugin before 1.9.1 does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated attacker to override the template path to read arbitrary files from the hosts file system. This may be escalated to RCE using PHP filter chains.

CVE-2023-39677
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
77.2%
2023 1 PoC

MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php.

CVE-2023-31465
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
90.5%
2023 1 PoC

An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper streams, it is possible to find the getsamplebacklog call. Some query parameters are passed directly in the URL and named arg[x], with x an integer starting from 1; it is possible to modify arg[2] to insert Bash code that will be executed directly by the server.

CVE-2023-40751
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.8%
2023 2 PoCs

PHPJabbers Fundraising Script v1.0 is vulnerable to Cross Site Scripting (XSS) via the "action" parameter of index.php.

CVE-2023-50917
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.6%
2023 3 PoCs

MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majordomo mailing-list manager.

CVE-2023-43177
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
76.1%
2023 2 PoCs

CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.

CVE-2023-39600
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.7%
2023 2 PoCs

IceWarp 11.4.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the color parameter.

CVE-2023-50968
Apache OFBiz Web ⚡ nuclei
N/A
UNKNOWN
EPSS
83.9%
2023 CWE-200 0 PoCs

Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. The same uri can be operated to realize a SSRF attack also without authorizations. Users are recommended to upgrade to version 18.12.11, which fixes this issue.

CVE-2023-40749
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
44.5%
2023 2 PoCs

PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.

CVE-2023-40931
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
88.4%
2023 3 PoCs

A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php

CVE-2023-49438
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2023 1 PoC

An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspecting users to malicious sites via a crafted URL by abusing the ?next parameter on the /login and /register routes.

CVE-2023-40753
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the message parameter of index.php in PHPJabbers Ticket Support Script v3.2.

CVE-2023-44813
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
20.8%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a crafted payload to the mode parameter of the invite friend login function.

CVE-2023-39026
Software Genérico Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
83.9%
2023 2 PoCs

Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information via a crafted request to the /mgmt/ component.

CVE-2023-2178
Aajoda Testimonials Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.1%
2023 1 PoC

The Aajoda Testimonials WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-35708
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
75.6%
2023 0 PoCs

In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content. These are fixed versions of the DLL drop-in: 2020.1.10 (12.1.10), 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.

CVE-2023-38040
Revive Adserver Web ⚡ nuclei
N/A
UNKNOWN
EPSS
7.6%
2023 0 PoCs

A reflected XSS vulnerability exists in Revive Adserver 5.4.1 and earlier versions..

CVE-2023-43326
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
34.6%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability exisits in multiple url of mooSocial v3.1.8 allows attackers to steal user's session cookies and impersonate their account via a crafted URL.

CVE-2023-49230
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
31.1%
2023 0 PoCs

An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows attackers to modify the portals' configurations without prior authentication.