7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-41592
Software Genérico Web
N/A
UNKNOWN
EPSS
2.2%
2023 3 PoCs

Froala Editor v4.0.1 to v4.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability.

CVE-2023-33621
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request when the OpenVPN Server config file is downloaded. The token is then left in the browser history or access logs, potentially allowing attackers to bypass authentication via session replay.

CVE-2023-4933
WP Job Openings Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WP Job Openings WordPress plugin before 3.4.3 does not block listing the contents of the directories where it stores attachments to job applications, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled.

CVE-2023-29799
Software Genérico General
N/A
UNKNOWN
EPSS
14.9%
2023 1 PoC

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.

CVE-2023-48810
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

CVE-2023-36499
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Netgear XR300 v1.0.3.78 was discovered to contain multiple buffer overflows via the wla_ssid and wlg_ssid parameters at genie_ap_wifi_change.cgi.

CVE-2023-51015
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

TOTOLINX EX1800T v9.1.0cu.2112_B20220316 is vulnerable to arbitrary command execution in the ‘enable parameter’ of the setDmzCfg interface of the cstecgi .cgi

CVE-2023-27655
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Sin descripción disponible.

CVE-2023-31753
Software Genérico Web Database
N/A
UNKNOWN
EPSS
3.7%
2023 2 PoCs

SQL injection vulnerability in diskusi.php in eNdonesia 8.7, allows an attacker to execute arbitrary SQL commands via the "rid=" parameter.

CVE-2023-40869
Software Genérico General
N/A
UNKNOWN
EPSS
5.6%
2023 1 PoC

Cross Site Scripting vulnerability in mooSocial mooSocial Software 3.1.6 and 3.1.7 allows a remote attacker to execute arbitrary code via a crafted script to the edit_menu, copuon, and group_categorias functions.

CVE-2023-37302
Software Genérico Web
N/A
UNKNOWN
EPSS
1.7%
2023 1 PoC

An issue was discovered in SiteLinksView.php in Wikibase in MediaWiki through 1.39.3. There is XSS via a crafted badge title attribute. This is also related to lack of escaping in wbTemplate (from resources/wikibase/templates.js) for quotes (which can be in a title attribute).

CVE-2023-20918
Android General
N/A
UNKNOWN
EPSS
1.4%
2023 2 PoCs

In getPendingIntentLaunchFlags of ActivityOptions.java, there is a possible elevation of privilege due to a confused deputy with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-33272
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2023 1 PoC

An issue was discovered in DTS Monitoring 3.57.0. The parameter ip within the Ping check function is vulnerable to OS command injection (blind).

CVE-2023-38379
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to change the admin password via a zero-length pass0 to the webcontrol changepwd.cgi application, i.e., the entered password only needs to match the first zero characters of the saved password.

CVE-2023-31068
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2023 2 PoCs

An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\UserDesktop\themes.

CVE-2023-45863
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

An issue was discovered in lib/kobject.c in the Linux kernel before 6.2.3. With root access, an attacker can trigger a race condition that results in a fill_kobj_path out-of-bounds write.

CVE-2023-0602
Twittee Text Tweet Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
7.4%
2023 1 PoC

The Twittee Text Tweet WordPress plugin through 1.0.8 does not properly escape POST values which are printed back to the user inside one of the plugin's administrative page, which allows reflected XSS attacks targeting administrators to happen.

CVE-2023-34935
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A stack overflow in the AddWlanMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2023-34837
Software Genérico General
N/A
UNKNOWN
EPSS
2.1%
2023 2 PoCs

A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a vulnerable parameter GrpPath.

CVE-2023-40136
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In setHeader of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.