7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-51198
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

Sin descripción disponible.

CVE-2023-43861
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2023 1 PoC

D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanPPPoE function.

CVE-2023-38891
Software Genérico Web Database
N/A
UNKNOWN
EPSS
3.4%
2023 1 PoC

SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php.

CVE-2023-38970
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the Name of member parameter in the add new member function.

CVE-2023-39320
cmd/go General
N/A
UNKNOWN
EPSS
0.8%
2023 2 PoCs

The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command from the module proxy, as well as modules downloaded directly using VCS software.

CVE-2023-42334
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An Indirect Object Reference (IDOR) in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to escalate privileges via the user parameter.

CVE-2023-36109
Software Genérico General
N/A
UNKNOWN
EPSS
20.4%
2023 2 PoCs

Buffer Overflow vulnerability in JerryScript version 3.0, allows remote attackers to execute arbitrary code via ecma_stringbuilder_append_raw component at /jerry-core/ecma/base/ecma-helpers-string.c.

CVE-2023-43868
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via websGetVar function.

CVE-2023-36089
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Authentication Bypass vulnerability in D-Link DIR-645 firmware version 1.03 allows remote attackers to gain escalated privileges via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-38879
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
12.0%
2023 1 PoC

The Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to read arbitrary files via a directory traversal vulnerability in the 'filename' parameter of 'DownloadWindow.php'.

CVE-2023-22956
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 4 PoCs

An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to decrypt encrypted configuration files and retrieve sensitive information.

CVE-2023-43148
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2023 1 PoC

SPA-Cart 1.9.0.3 has a Cross Site Request Forgery (CSRF) vulnerability that allows a remote attacker to delete all accounts.

CVE-2023-39650
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
35.0%
2023 0 PoCs

Theme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /tvcmsblog/single.

CVE-2023-48838
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Appointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code.

CVE-2023-39668
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the inet_ntoa() function.

CVE-2023-43147
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

PHPJabbers Limo Booking Software 1.0 is vulnerable to Cross Site Request Forgery (CSRF) to add an admin user via the Add Users Function, aka an index.php?controller=pjAdminUsers&action=pjActionCreate URI.

CVE-2023-27253
Software Genérico General
N/A
UNKNOWN
EPSS
77.7%
2023 1 PoC

A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.

CVE-2023-39675
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php.

CVE-2023-27214
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Online Student Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the fromdate and todate parameters at /eduauth/student/between-date-reprtsdetails.php.

CVE-2023-50011
Software Genérico Web
N/A
UNKNOWN
EPSS
3.3%
2023 1 PoC

PopojiCMS version 2.0.1 is vulnerable to remote command execution in the Meta Social field.