7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-37800
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Sin descripción disponible.

CVE-2023-2842
WP Inventory Manager Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WP Inventory Manager WordPress plugin before 2.1.0.14 does not have CSRF checks, which could allow attackers to make logged-in admins delete Inventory Items via a CSRF attack

CVE-2023-20789
MT6789, MT6835, MT6855, MT6879, MT6886, MT6895, MT6983, MT6985, MT8188, MT8195, MT8195Z General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In jpeg, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07693193; Issue ID: ALPS07693193.

CVE-2023-20057
Cisco Email Security Appliance (ESA) Networking
N/A
UNKNOWN
EPSS
1.0%
2023 CWE-792 1 PoC

A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. This vulnerability is due to improper processing of URLs. An attacker could exploit this vulnerability by crafting a URL in a particular way. A successful exploit could allow the attacker to bypass the URL reputation filters that are configured for an affected device, which could allow malicious URLs to pass through the device.

CVE-2023-37306
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.

CVE-2023-2324
Elementor Forms Google Sheet Connector Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Elementor Forms Google Sheet Connector WordPress plugin before 1.0.7, gsheetconnector-for-elementor-forms-pro WordPress plugin through 1.0.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-23130
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext) with SSL disabled. OTE: the vendor's position is that, by design, this is controlled by a configuration option in which a customer can choose to use HTTP (rather than HTTPS) during troubleshooting.

CVE-2023-48003
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' in the WebSocket messages.

CVE-2023-38412
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Netgear R6900P v1.3.3.154 was discovered to contain multiple buffer overflows via the wla_ssid and wlg_ssid parameters at ia_ap_setting.cgi.

CVE-2023-5979
eCommerce Product Catalog Plugin for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The eCommerce Product Catalog Plugin for WordPress plugin before 3.3.26 does not have CSRF checks in some of its admin pages, which could allow attackers to make logged-in users perform unwanted actions via CSRF attacks, such as delete all products

CVE-2023-0579
YARPP Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscribers to perform SQL Injection attacks.

CVE-2023-3139
Protect WP Admin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.4%
2023 1 PoC

The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered.

CVE-2023-28868
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operating system by creating a symbolic link.

CVE-2023-46475
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

A Stored Cross-Site Scripting vulnerability was discovered in ZenTao 18.3 where a user can create a project, and in the name field of the project, they can inject malicious JavaScript code.

CVE-2023-41013
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Cross Site Scripting (XSS) in Webmail Calendar in IceWarp 10.3.1 allows remote attackers to inject arbitrary web script or HTML via the "p4" field.

CVE-2023-34836
Software Genérico General
N/A
UNKNOWN
EPSS
2.1%
2023 2 PoCs

A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Dtltyp and ListName parameters.

CVE-2023-40760
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

User enumeration is found in PHP Jabbers Hotel Booking System v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-36090
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Authentication Bypass vulnerability in D-Link DIR-885L FW102b01 allows remote attackers to gain escalated privileges via phpcgi. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-2495
Greeklish-permalink Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Greeklish-permalink WordPress plugin through 3.3 does not implement correct authorization or nonce checks in the cyrtrans_ajax_old AJAX action, allowing unauthenticated and low-privilege users to trigger the plugin's functionality to change Post slugs either directly or through CSRF.

CVE-2023-31546
Software Genérico Web
N/A
UNKNOWN
EPSS
21.2%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature.