7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-1030
Online Boat Reservation System Web
5.1
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

A vulnerability has been found in SourceCodester/code-projects Online Boat Reservation System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /boat/login.php of the component POST Parameter Handler. The manipulation of the argument un leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2023-28040
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-53977
myBB forums Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum management system that allows authenticated administrators to inject malicious scripts when creating new forums. Attackers can exploit this vulnerability by inserting script payloads in the forum title field when adding new forums through the 'Forums and Posts' > 'Forum Management' interface, causing arbitrary JavaScript to execute when the forum listing is viewed.

CVE-2023-25936
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-28060
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-28039
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-53976
myBB forums Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the template management system that allows authenticated administrators to inject malicious scripts when creating new templates. Attackers can exploit this vulnerability by inserting script payloads in the template title field when adding new templates through the 'Templates and Style' > 'Templates' > 'Manage Templates' > 'Global Templates' interface, causing arbitrary JavaScript to execute when the template is viewed.

CVE-2023-54358
WordPress adivaha Travel Plugin Web Windows
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the isMobile parameter. Attackers can craft malicious URLs containing JavaScript payloads in the isMobile GET parameter at the /mobile-app/v3/ endpoint to execute arbitrary code in victims' browsers and steal session tokens or credentials.

CVE-2023-28035
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-53884
Webedition CMS Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Webedition CMS v2.9.8.8 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files through the media upload feature to inject and execute arbitrary scripts when the file is viewed by other users.

CVE-2023-53915
Zenphoto Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Zenphoto 1.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting HTML content into album descriptions. Attackers can create albums with malicious iframe or script tags in the description field that execute when users view the album page.

CVE-2023-53928
PHPFusion Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

PHPFusion 9.10.30 contains a stored cross-site scripting vulnerability in the file manager that allows attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload SVG files with script tags that execute arbitrary JavaScript when viewed, potentially stealing user session information or performing client-side attacks.

CVE-2023-53925
Ulicms Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

UliCMS 2023.1 contains a stored cross-site scripting vulnerability that allows attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files through the file management interface that execute arbitrary scripts when viewed by other users.

CVE-2023-54337
Sysax Multi Server General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-1284 2 PoCs

Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the application. Attackers can overwrite the password field with 800 bytes of repeated characters to trigger an application crash and disrupt server functionality.

CVE-2023-49031
Software Genérico General
5.1
MEDIUM
EPSS
0.1%
2023 1 PoC

Directory Traversal (Local File Inclusion) vulnerability in Tikit (now Advanced) eMarketing platform 6.8.3.0 allows a remote attacker to read arbitrary files and obtain sensitive information via a crafted payload to the filename parameter to the OpenLogFile endpoint.

CVE-2023-53736
Xperience Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts in the administration interface. Attackers can exploit this vulnerability to execute arbitrary scripts within the administrative context.

CVE-2023-53919
PodcastGenerator Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the Freebox content field accessible through the theme customization interface (theme_freebox.php). Malicious JavaScript payloads injected into the Freebox content execute when users visit the application's home page.

CVE-2023-28050
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-53738
Xperience Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via page preview URLs. Attackers can exploit this vulnerability to execute arbitrary scripts in users' browsers during page preview interactions.

CVE-2023-30735
SAssistant General
5.1
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper Preservation of Permissions vulnerability in SAssistant prior to version 8.7 allows local attackers to access backup data in SAssistant.