7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-41149
F-RevoCRM General
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

F-RevoCRM version7.3.7 and version7.3.8 contains an OS command injection vulnerability. If this vulnerability is exploited, an attacker who can access the product may execute an arbitrary OS command on the server where the product is running.

CVE-2023-40779
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
35.9%
2023 2 PoCs

An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL.

CVE-2023-37599
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
85.6%
2023 1 PoC

An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory

CVE-2023-2225
SEO ALert Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The SEO ALert WordPress plugin through 1.59 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-41105
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejected a filename for security reasons in Python 3.10.x or earlier, but that filename is no longer rejected in Python 3.11.x.

CVE-2023-1103
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Sin descripción disponible.

CVE-2023-28508
UniData General
N/A
UNKNOWN
EPSS
0.5%
2023 CWE-120 1 PoC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based overflow vulnerability, where certain input can corrupt the heap and crash the forked process.

CVE-2023-41165
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and 4.4.0 through 4.6.8 before 4.6.9. An administrator with write access to the SNS firewall can configure a login disclaimer with malicious JavaScript elements that can result in data theft.

CVE-2023-33277
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 allows a remote attacker to read sensitive files via directory-traversal sequences in the URL.

CVE-2023-2010
Forminator Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Forminator WordPress plugin before 1.24.1 does not use an atomic operation to check whether a user has already voted, and then update that information. This leads to a Race Condition that may allow a single user to vote multiple times on a poll.

CVE-2023-46388
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via dpal_config.zml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication.

CVE-2023-47675
CubeCart General
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to execute an arbitrary OS command.

CVE-2023-27208
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A cross-site scripting (XSS) vulnerability in /php-opos/login.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the redirect parameter.

CVE-2023-36934
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
90.9%
2023 0 PoCs

In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content.

CVE-2023-43241
Software Genérico General
N/A
UNKNOWN
EPSS
2.5%
2023 1 PoC

D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter TXPower and GuardInt in SetWLanRadioSecurity.

CVE-2023-37207
Firefox General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.

CVE-2023-37307
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.

CVE-2023-38617
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Office Suite Premium Version v10.9.1.42602 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the filter parameter at /api?path=files.

CVE-2023-32521
Trend Micro Moibile Security for Enterprise General
N/A
UNKNOWN
EPSS
66.3%
2023 1 PoC

A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated remote attacker to delete arbitrary files.