7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-46020
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Cross Site Scripting (XSS) in updateprofile.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'rename', 'remail', 'rphone' and 'rcity' parameters.

CVE-2023-38315
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a try_to_authenticate NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing client token query string parameter. Triggering this issue results in crashing OpenNDS (a Denial-of-Service condition). Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.

CVE-2023-50449
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

JFinalCMS 5.0.0 could allow a remote attacker to read files via ../ Directory Traversal in the /common/down/file fileKey parameter.

CVE-2023-46157
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.6%
2023 2 PoCs

File-Manager in MGT CloudPanel 2.0.0 through 2.3.2 allows the lowest privilege user to achieve OS command injection by changing file ownership and changing file permissions to 4755.

CVE-2023-36319
Software Genérico Web
N/A
UNKNOWN
EPSS
25.4%
2023 1 PoC

File Upload vulnerability in Openupload Stable v.0.4.3 allows a remote attacker to execute arbitrary code via the action parameter of the compress-inc.php file.

CVE-2023-1166
Ultimate-Premium-Plugin Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The USM-Premium WordPress plugin before 16.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVE-2023-39115
Software Genérico Web
N/A
UNKNOWN
EPSS
2.2%
2023 3 PoCs

install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document.

CVE-2023-45880
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can create a new Asset Component. The templateFileDestination parameter can be set to an arbitrary pathname (and extension). This allows creation of PHP files outside of the uploads directory, directly in the webroot.

CVE-2023-40759
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-4808
WP Post Popup Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WP Post Popup WordPress plugin through 3.7.3 does not sanitise and escape some of its inputs, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-40138
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-27205
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php.

CVE-2023-40344
Jenkins Delphix Plugin DevOps
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A missing permission check in Jenkins Delphix Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

CVE-2023-4053
Firefox General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2.

CVE-2023-38998
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

An open redirect in the Login page of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL.

CVE-2023-49314
Software Genérico General
N/A
UNKNOWN
EPSS
17.6%
2023 2 PoCs

Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and EnableNodeCliInspectArguments, and thus r3ggi/electroniz3r can be used to perform an attack.

CVE-2023-4054
Firefox Windows
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 102.14, Firefox ESR < 115.1, Thunderbird < 102.14, and Thunderbird < 115.1.

CVE-2023-28864
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Progress Chef Infra Server before 15.7 allows a local attacker to exploit a /var/opt/opscode/local-mode-cache/backup world-readable temporary backup path to access sensitive information, resulting in the disclosure of all indexed node data, because OpenSearch credentials are exposed. (The data typically includes credentials for additional systems.) The attacker must wait for an admin to run the "chef-server-ctl reconfigure" command.

CVE-2023-40762
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

User enumeration is found in PHPJabbers Fundraising Script v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-37847
Software Genérico Database
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.