7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-36313
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

PHPJabbers Document Creator v1.0 is vulnerable to Cross Site Scripting (XSS) via all post parameters of "Export Requests" aside from "request_feed".

CVE-2023-33566
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

Sin descripción disponible.

CVE-2023-27210
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/view_order.php.

CVE-2023-43340
Software Genérico Web
N/A
UNKNOWN
EPSS
1.4%
2023 1 PoC

Cross-site scripting (XSS) vulnerability in evolution v.3.2.3 allows a local attacker to execute arbitrary code via a crafted payload injected into the cmsadmin, cmsadminemail, cmspassword and cmspasswordconfim parameters

CVE-2023-40997
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Buffer Overflow vulnerability in O-RAN Software Community ric-plt-lib-rmr v.4.9.0 allows a remote attacker to cause a denial of service via a crafted packet.

CVE-2023-38357
Software Genérico General
N/A
UNKNOWN
EPSS
4.2%
2023 3 PoCs

Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized access to user sessions.

CVE-2023-21282
Android General
N/A
UNKNOWN
EPSS
1.7%
2023 6 PoCs

In TRANSPOSER_SETTINGS of lpp_tran.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.

CVE-2023-5738
WordPress Backup & Migration Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WordPress Backup & Migration WordPress plugin before 1.4.4 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.

CVE-2023-24249
Software Genérico Web
N/A
UNKNOWN
EPSS
48.2%
2023 3 PoCs

An arbitrary file upload vulnerability in laravel-admin v1.8.19 allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2023-6288
Remote Desktop Manager General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Code injection in Remote Desktop Manager 2023.3.9.3 and earlier on macOS allows an attacker to execute code via the DYLIB_INSERT_LIBRARIES environment variable.

CVE-2023-41593
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Multiple cross-site scripting (XSS) vulnerabilities in Dairy Farm Shop Management System Using PHP and MySQL v1.1 allow attackers to execute arbitrary web scripts and HTML via a crafted payload injected into the Category and Category Field parameters.

CVE-2023-31705
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

A Reflected Cross-site scripting (XSS) vulnerability in Sourcecodester Task Reminder System 1.0 allows an authenticated user to inject malicious javascript into the page parameter.

CVE-2023-48042
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Cross Site Scripting (XSS) in Search filters in Prestashop Amazzing filter version up to version 3.2.5, allows remote attackers to inject arbitrary JavaScript code.

CVE-2023-43323
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
80.8%
2023 1 PoC

mooSocial 3.1.8 is vulnerable to external service interaction on post function. When executed, the server sends a HTTP and DNS request to external server. The Parameters effected are multiple - messageText, data[wall_photo], data[userShareVideo] and data[userShareLink].

CVE-2023-49948
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

Forgejo before 1.20.5-1 allows remote attackers to test for the existence of private user accounts by appending .rss (or another extension) to a URL.

CVE-2023-1648
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Sin descripción disponible.

CVE-2023-38921
Software Genérico General
N/A
UNKNOWN
EPSS
1.8%
2023 1 PoC

Netgear WG302v2 v5.2.9 and WAG302v2 v5.1.19 were discovered to contain multiple command injection vulnerabilities in the upgrade_handler function via the firmwareRestore and firmwareServerip parameters.

CVE-2023-23634
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.2%
2023 1 PoC

SQL Injection vulnerability in Documize version 5.4.2, allows remote attackers to execute arbitrary code via the user parameter of the /api/dashboard/activity endpoint.

CVE-2023-39070
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

An issue in Cppcheck 2.12 dev allows a local attacker to execute arbitrary code via the removeContradiction parameter in token.cpp:1934.

CVE-2023-21144
Android General
N/A
UNKNOWN
EPSS
20.1%
2023 3 PoCs

In doInBackground of NotificationContentInflater.java, there is a possible temporary denial or service due to long running operations. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-252766417