7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-37690
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Search Maid page.

CVE-2023-36134
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2023 2 PoCs

In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.

CVE-2023-36970
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function.

CVE-2023-39707
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 3 PoCs

A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Add Expense parameter under the Expense section.

CVE-2023-43352
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager Menu component.

CVE-2023-44848
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_template.php component.

CVE-2023-38193
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2023 1 PoC

An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command line.

CVE-2023-30223
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packets containing requests to perform arbitrary actions.

CVE-2023-48199
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2023 2 PoCs

HTML Injection vulnerability in the 'manageApiKeys' component in Grocy <= 4.0.3 allows attackers to inject arbitrary HTML content without script execution. This occurs when user-supplied data is not appropriately sanitized, enabling the injection of HTML tags through parameter values. The attacker can then manipulate page content in the QR code detail popup, often coupled with social engineering tactics, exploiting both the trust of users and the application's lack of proper input handling.

CVE-2023-34835
Software Genérico Web
N/A
UNKNOWN
EPSS
1.7%
2023 2 PoCs

A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary JavaScript code via a vulnerable delete_file parameter.

CVE-2023-33817
Software Genérico Database
N/A
UNKNOWN
EPSS
12.1%
2023 1 PoC

hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability.

CVE-2023-45376
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

In the module "Carousels Pack - Instagram, Products, Brands, Supplier" (hicarouselspack) for PrestaShop up to version 1.5.0 from HiPresta for PrestaShop, a guest can perform SQL injection via HiCpProductGetter::getViewedProduct().`

CVE-2023-41150
F-RevoCRM Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

F-RevoCRM 7.3 series prior to version7.3.8 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the product.

CVE-2023-39075
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 3 PoCs

Renault Zoe EV 2021 automotive infotainment system versions 283C35202R to 283C35519R (builds 11.10.2021 to 16.01.2023) allows attackers to crash the infotainment system by sending arbitrary USB data via a USB device.

CVE-2023-2321
WPForms Google Sheet Connector Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WPForms Google Sheet Connector WordPress plugin before 3.4.6, gsheetconnector-wpforms-pro WordPress plugin through 3.4.6 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-3460
Ultimate Member Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
92.8%
2023 14 PoCs

The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

CVE-2023-48207
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.

CVE-2023-37624
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Netdisco before v2.063000 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.

CVE-2023-36348
Software Genérico General
N/A
UNKNOWN
EPSS
5.5%
2023 3 PoCs

POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter.

CVE-2023-33744
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671.