515 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2023-1730
SupportCandy Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
81.8%
2023 1 PoC

The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks

CVE-2023-34362
🔥 KEV Software Genérico Database Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2023 15 PoCs

In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, and execute SQL statements that alter or delete database elements. NOTE: this is exploited in the wild in M

CVE-2023-32243
Essential Addons for Elementor General ⚡ nuclei
9.8
CRITICAL
EPSS
93.6%
2023 CWE-287 11 PoCs

Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1.

CVE-2023-27350
🔥 KEV NG General ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2023 CWE-284 20 PoCs

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.

CVE-2023-48022
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
92.2%
2023 4 PoCs

Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment. (Also, within that environment, customers at version 2.52.0 and later can choose to use token authentication.)

CVE-2023-2734
MStore API – Create Native Android & iOS Apps On The Cloud Web Cloud Windows ⚡ nuclei
9.8
CRITICAL
EPSS
63.1%
2023 CWE-288 0 PoCs

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart sync from mobile REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.

CVE-2023-34752
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
30.2%
2023 1 PoC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.

CVE-2023-25135
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.3%
2023 1 PoC

vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserialization. This occurs because verify_serialized checks that a value is serialized by calling unserialize and then checking for errors. The fixed versions are 5.6.7 PL1, 5.6.8 PL1, and 5.6.9 PL1.

CVE-2023-29300
🔥 KEV ColdFusion General ⚡ nuclei
9.8
CRITICAL
EPSS
93.7%
2023 CWE-502 0 PoCs

Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

CVE-2023-38035
🔥 KEV MobileIron Sentry Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2023 4 PoCs

A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

CVE-2023-1698
Compact Controller CC100 General ⚡ nuclei
9.8
CRITICAL
EPSS
93.8%
2023 CWE-78 6 PoCs

In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.

CVE-2023-2437
UserPro - Community and User Profile WordPress Plugin Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
76.8%
2023 CWE-288 3 PoCs

The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email. An attacker can leverage CVE-2023-2448 and CVE-2023-2446 to get the user's email address to successfully exploit this vulnerability.

CVE-2023-3368
Chamilo Web ⚡ nuclei
9.8
CRITICAL
EPSS
89.0%
2023 CWE-78 1 PoC

Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960.

CVE-2023-39361
cacti Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
92.3%
2023 CWE-89 2 PoCs

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an enabled state, there could be the potential for significant damage. Attackers may exploit this vulnerability, and there may be possibilities for actions such as the usurpation of administrative privileges or remote code execution. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no

CVE-2023-3277
MStore API – Create Native Android & iOS Apps On The Cloud Web Cloud Windows ⚡ nuclei
9.8
CRITICAL
EPSS
47.2%
2023 CWE-288 0 PoCs

The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows unauthenticated attackers to log in as any user as long as they know the user's email address.

CVE-2023-37999
HT Mega General ⚡ nuclei
9.8
CRITICAL
EPSS
53.8%
2023 CWE-269 0 PoCs

Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega: from n/a through 2.2.0.

CVE-2023-1020
Steveas WP Live Chat Shoutbox Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
82.2%
2023 1 PoC

The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2023-30194
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
75.2%
2023 1 PoC

Prestashop posstaticfooter <= 1.0.0 is vulnerable to SQL Injection via posstaticfooter::getPosCurrentHook().

CVE-2023-27638
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
39.0%
2023 1 PoC

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised tshirtecommerce_design_cart_id GET parameter in order to exploit an insecure parameter in the functions hookActionCartSave and updateCustomizationTable, which could lead to a SQL injection. This is exploited in the wild in March 2023.