7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-35156
xwiki-platform Web ⚡ nuclei
9.7
CRITICAL
EPSS
12.1%
2023 CWE-87 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the delete template to perform a XSS, e.g. by using URL such as: > xwiki/bin/get/FlamingoThemes/Cerulean?xpage=xpart&vm=delete.vm&xredirect=javascript:alert(document.domain). This vulnerability exists since XWiki 6.0-rc-1. The vulnerability has been patched in XWiki 14.10.6 and 15.1. Note that a partial patch has been provided in 14.10.5 but wasn't enough to entirely fix t

CVE-2023-35160
xwiki-platform Web ⚡ nuclei
9.7
CRITICAL
EPSS
12.1%
2023 CWE-87 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the resubmit template to perform a XSS, e.g. by using URL such as: > xwiki/bin/view/XWiki/Main xpage=resubmit&resubmit=javascript:alert(document.domain)&xback=javascript:alert(document.domain). This vulnerability exists since XWiki 2.5-milestone-2. The vulnerability has been patched in XWiki 14.10.5 and 15.1-rc-1.

CVE-2023-1717
Bitrix24 Web
9.6
CRITICAL
EPSS
1.8%
2023 CWE-79 1 PoC

Prototype pollution in bitrix/templates/bitrix24/components/bitrix/menu/left_vertical/script.js in Bitrix24 22.0.300 allows remote attackers to execute arbitrary JavaScript code in the victim’s browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via polluting `__proto__[tag]` and `__proto__[text]`.

CVE-2023-27500
NetWeaver AS for ABAP and ABAP Platform (SAPRSBRO Program) General
9.6
CRITICAL
EPSS
0.3%
2023 CWE-22 1 PoC

An attacker with non-administrative authorizations can exploit a directory traversal flaw in program SAPRSBRO to over-write system files. In this attack, no data can be read but potentially critical OS files can be over-written making the system unavailable.

CVE-2023-22524
Companion for Mac General
9.6
CRITICAL
EPSS
32.0%
2023 2 PoCs

Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code.

CVE-2023-39216
Zoom Desktop Client for Windows Windows
9.6
CRITICAL
EPSS
0.4%
2023 CWE-80 1 PoC

Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access.

CVE-2023-28131
Expo AuthSession module General
9.6
CRITICAL
EPSS
1.3%
2023 2 PoCs

A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicious link. The link itself may be sent to the victim in various ways (including email, text message, an attacker-controlled website, etc).

CVE-2023-34990
FortiWLM Networking ⚡ nuclei
9.6
CRITICAL
EPSS
72.9%
2023 CWE-23 0 PoCs

A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted web requests.

CVE-2023-27269
NetWeaver Application Server for ABAP and ABAP Platform General
9.6
CRITICAL
EPSS
0.5%
2023 CWE-22 1 PoC

SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker with non-administrative authorizations to exploit a directory traversal flaw in an available service to overwrite the system files.  In this attack, no data can be read but potentially critical OS files can be overwritten making the system unavailable.

CVE-2023-0488
pyload/pyload Web
9.6
CRITICAL
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pyload/pyload prior to 0.5.0b3.dev42.

CVE-2023-28347
Software Genérico Web Windows
9.6
CRITICAL
EPSS
1.7%
2023 2 PoCs

An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a proof-of-concept script that functions similarly to a Student Console, providing unauthenticated attackers with the ability to exploit XSS vulnerabilities within the Teacher Console application and achieve remote code execution as NT AUTHORITY/SYSTEM on all connected Student Consoles and the Teacher Console in a Zero Click manner.

CVE-2023-48728
AVideo Web ⚡ nuclei
9.6
CRITICAL
EPSS
17.4%
2023 CWE-79 2 PoCs

A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.

CVE-2023-6753
mlflow/mlflow General
9.6
CRITICAL
EPSS
2.4%
2023 CWE-22 1 PoC

Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2.

CVE-2023-5820
Thumbnail Slider With Lightbox Web Windows
9.6
CRITICAL
EPSS
0.1%
2023 1 PoC

The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the addedit functionality. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-3526
CLOUD CLIENT 1101T-TX/TX Web Networking Cloud
9.6
CRITICAL
EPSS
0.7%
2023 CWE-79 2 PoCs

In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an unauthenticated remote attacker could use a reflective XSS within the license viewer page of the devices in order to execute code in the context of the user's browser.

CVE-2023-5212
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Web Windows
9.6
CRITICAL
EPSS
0.3%
2023 CWE-22 1 PoC

The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as well as version 4.9.2. This makes it possible for authenticated attackers with subscriber privileges to delete arbitrary files on the server, which makes it possible to take over affected sites as well as others sharing the same hosting account. Version 4.9.1 originally addressed the issue, but it was reintroduced in 4.9.2 and fixed again in 4.9.3.

CVE-2023-7018
huggingface/transformers General
9.6
CRITICAL
EPSS
0.2%
2023 CWE-502 1 PoC

Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.

CVE-2023-51219
Software Genérico Web
9.6
CRITICAL
EPSS
0.7%
2023 1 PoC

A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to run any attacker-controlled JavaScript within a WebView. The impact was further escalated by triggering another WebView that leaked its access token in a HTTP request header. Ultimately, this access token could be used to take over another user's account and read her/his chat messages.

CVE-2023-48974
Software Genérico General
9.6
CRITICAL
EPSS
6.6%
2023 1 PoC

Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script to the serverName_input parameter.

CVE-2023-33242
Wallet General
9.6
CRITICAL
EPSS
5.8%
2023 2 PoCs

Crypto wallets implementing the Lindell17 TSS protocol might allow an attacker to extract the full ECDSA private key by exfiltrating a single bit in every signature attempt (256 in total) because of not adhering to the paper's security proof's assumption regarding handling aborts after a failed signature.