7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-31320
Radeon™ RX 5000/6000/7000 Series Graphics Cards General
N/A
UNKNOWN
EPSS
5.2%
2023 2 PoCs

Improper input validation in the AMD RadeonTM Graphics display driver may allow an attacker to corrupt the display potentially resulting in denial of service.

CVE-2023-26088
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine system. It can also lead to privilege escalation in certain scenarios.

CVE-2023-23127
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

In Connectwise Control 22.8.10013.8329, the login page does not implement HSTS headers therefore not enforcing HTTPS. NOTE: the vendor's position is that, by design, this is controlled by a configuration option in which a customer can choose to use HTTP (rather than HTTPS) during troubleshooting.

CVE-2023-3175
AI ChatBot Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The AI ChatBot WordPress plugin before 4.6.1 does not adequately escape some settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2023-38351
Software Genérico General
N/A
UNKNOWN
EPSS
6.0%
2023 1 PoC

MiniTool Partition Wizard 12.8 contains an insecure installation mechanism that allows attackers to achieve remote code execution through a man in the middle attack.

CVE-2023-20583
Processors General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A potential power side-channel vulnerability in AMD processors may allow an authenticated attacker to monitor the CPU power consumption as the data in a cache line changes over time potentially resulting in a leak of sensitive information.

CVE-2023-24317
Software Genérico Web
N/A
UNKNOWN
EPSS
9.1%
2023 2 PoCs

Judging Management System 1.0 was discovered to contain an arbitrary file upload vulnerability via the component edit_organizer.php.

CVE-2023-51017
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanIp parameter’ of the setLanConfig interface of the cstecgi .cgi.

CVE-2023-37152
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2023 2 PoCs

Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This has been disputed as not a valid vulnerability.

CVE-2023-5340
Five Star Restaurant Menu and Food Ordering Web Windows
N/A
UNKNOWN
EPSS
1.0%
2023 1 PoC

The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticated users, allowing them to perform PHP Object Injection when a suitable gadget is present on the blog.

CVE-2023-31718
Software Genérico Web
N/A
UNKNOWN
EPSS
37.6%
2023 2 PoCs

FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.

CVE-2023-3134
Forminator Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

The Forminator WordPress plugin before 1.24.4 does not properly escape values that are being reflected inside form fields that use pre-populated query parameters, which could lead to reflected XSS attacks.

CVE-2023-36220
Software Genérico Web
N/A
UNKNOWN
EPSS
2.8%
2023 1 PoC

Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary code and gain access to sensitive information via the plugin Upload function.

CVE-2023-40764
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-0369
GoToWP Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The GoToWP WordPress plugin through 5.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-6253
Digital Guardian Agent General
N/A
UNKNOWN
EPSS
0.0%
2023 CWE-922 3 PoCs

A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file.

CVE-2023-33690
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

SonicJS up to v0.7.0 allows attackers to execute an authenticated path traversal when an attacker injects special characters into the filename of a backup CMS.

CVE-2023-3435
User Activity Log Web Database Windows
N/A
UNKNOWN
EPSS
0.8%
2023 1 PoC

The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before using it in a SQL statement as part of its exportation feature, allowing unauthenticated attackers to conduct SQL injection attacks.

CVE-2023-37628
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

Online Piggery Management System 1.0 is vulnerable to SQL Injection.

CVE-2023-33902
SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In bluetooth service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.