7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-1649
AI ChatBot Web Windows
4.8
MEDIUM
EPSS
0.3%
2023 1 PoC

The AI ChatBot WordPress plugin before 4.5.1 does not sanitise and escape numerous of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-2009
Pretty Url Web Windows ⚡ nuclei
4.8
MEDIUM
EPSS
3.0%
2023 1 PoC

Plugin does not sanitize and escape the URL field in the Pretty Url WordPress plugin through 1.5.4 settings, which could allow high-privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-43879
Software Genérico Web
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

Rite CMS 3.0 has a Cross-Site scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload into the Global Content Blocks in the Administration Menu.

CVE-2023-6626
Product Enquiry for WooCommerce Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-0543
Arigato Autoresponder and Newsletter Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Arigato Autoresponder and Newsletter WordPress plugin before 2.1.7.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2023-6783
WolfNet IDX for WordPress Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The WolfNet IDX for WordPress plugin through 1.19.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-4925
Easy Forms for Mailchimp Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Easy Forms for Mailchimp WordPress plugin through 6.8.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2023-4502
Translate WordPress with GTranslate Web Windows
4.8
MEDIUM
EPSS
0.1%
2023 1 PoC

The Translate WordPress with GTranslate WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). This vulnerability affects multiple parameters.

CVE-2023-29848
Software Genérico Web
4.8
MEDIUM
EPSS
1.4%
2023 1 PoC

Bang Resto 1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the itemName parameter in the admin/menu.php Add New Menu function.

CVE-2023-0605
Auto Rename Media On Upload Web Windows
4.8
MEDIUM
EPSS
0.2%
2023 1 PoC

The Auto Rename Media On Upload WordPress plugin before 1.1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-25585
binutils General
4.7
MEDIUM
EPSS
0.0%
2023 CWE-457 1 PoC

A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.

CVE-2023-0531
Online Tours & Travels Management System Web Database
4.7
MEDIUM
EPSS
0.2%
2023 CWE-89 1 PoC

A vulnerability classified as critical has been found in SourceCodester Online Tours & Travels Management System 1.0. Affected is an unknown function of the file admin/booking_report.php. The manipulation of the argument to_date leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-219600.

CVE-2023-0533
Online Tours & Travels Management System Web Database
4.7
MEDIUM
EPSS
0.2%
2023 CWE-89 1 PoC

A vulnerability, which was classified as critical, has been found in SourceCodester Online Tours & Travels Management System 1.0. Affected by this issue is some unknown functionality of the file admin/expense_report.php. The manipulation of the argument from_date leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-219602 is the identifier assigned to this vulnerability.

CVE-2023-0913
Auto Dealer Management System Database
4.7
MEDIUM
EPSS
0.5%
2023 CWE-89 1 PoC

A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0. This vulnerability affects unknown code of the file /adms/admin/?page=vehicles/sell_vehicle. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-221482 is the identifier assigned to this vulnerability.

CVE-2023-29204
xwiki-platform Web ⚡ nuclei
4.7
MEDIUM
EPSS
1.0%
2023 CWE-601 0 PoCs

XWiki Commons are technical libraries common to several other top level XWiki projects. It is possible to bypass the existing security measures put in place to avoid open redirect by using a redirect such as `//mydomain.com` (i.e. omitting the `http:`). It was also possible to bypass it when using URL such as `http:/mydomain.com`. The problem has been patched on XWiki 13.10.10, 14.4.4 and 14.8RC1.

CVE-2023-6188
GetSimpleCMS Web
4.7
MEDIUM
EPSS
0.1%
2023 CWE-94 1 PoC

A vulnerability was found in GetSimpleCMS 3.3.16/3.4.0a. It has been rated as critical. This issue affects some unknown processing of the file /admin/theme-edit.php. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-245735.

CVE-2023-21766
Windows 10 Version 1809 Windows
4.7
MEDIUM
EPSS
6.4%
2023 CWE-591 1 PoC

Windows Overlay Filter Information Disclosure Vulnerability

CVE-2023-2979
Pydio Cells General
4.7
MEDIUM
EPSS
0.0%
2023 CWE-284 1 PoC

A vulnerability classified as critical has been found in Abstrium Pydio Cells 4.2.0. This affects an unknown part of the component User Creation Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-230211.

CVE-2023-5339
Mattermost General
4.7
MEDIUM
EPSS
0.1%
2023 CWE-200 1 PoC

Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged. 

CVE-2023-3473
Retro Cellphone Online Store Web Database
4.7
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability, which was classified as critical, was found in Campcodes Retro Cellphone Online Store 1.0. Affected is an unknown function of the file /admin/edit_product.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-232752.