7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-6035
EazyDocs Web Database Windows
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The EazyDocs WordPress plugin before 2.3.4 does not properly sanitize and escape "data" parameter before using it in an SQL statement via an AJAX action, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks.

CVE-2023-39638
Software Genérico General
N/A
UNKNOWN
EPSS
2.4%
2023 1 PoC

D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 was discovered to contain a command injection vulnerability via the lxmldbc_system function at /htdocs/cgibin.

CVE-2023-32353
iTunes for Windows Windows
N/A
UNKNOWN
EPSS
1.5%
2023 1 PoC

A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.9 for Windows. An app may be able to elevate privileges.

CVE-2023-44796
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in LimeSurvey before version 6.2.9-230925 allows a remote attacker to escalate privileges via a crafted script to the _generaloptions_panel.php component.

CVE-2023-30451
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

In TYPO3 11.5.24, the filelist component allows attackers (who have access to the administrator panel) to read arbitrary files via directory traversal in the baseuri field, as demonstrated by POST /typo3/record/edit with ../../../ in data[sys_file_storage]*[data][sDEF][lDEF][basePath][vDEF].

CVE-2023-38646
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
94.3%
2023 45 PoCs

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

CVE-2023-2470
Add to Feedly Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Add to Feedly WordPress plugin through 1.2.11 does not sanitize and escape its settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2023-36252
Software Genérico General
N/A
UNKNOWN
EPSS
1.6%
2023 1 PoC

An issue in Ateme Flamingo XL v.3.6.20 and XS v.3.6.5 allows a remote authenticated attacker to execute arbitrary code and cause a denial of service via a the session expiration function.

CVE-2023-25206
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

PrestaShop ws_productreviews < 3.6.2 is vulnerable to SQL Injection.

CVE-2023-33253
Software Genérico Web
N/A
UNKNOWN
EPSS
44.4%
2023 1 PoC

LabCollector 6.0 though 6.15 allows remote code execution. An authenticated remote low-privileged user can upload an executable PHP file and execute system commands. The vulnerability is in the message function, and is due to insufficient validation of the file (such as shell.jpg.php.shell) being sent.

CVE-2023-2256
Product Addons & Fields for WooCommerce Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
21.2%
2023 1 PoC

The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting.

CVE-2023-37201
Firefox Web
N/A
UNKNOWN
EPSS
0.8%
2023 1 PoC

An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.

CVE-2023-24133
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey_5g parameter at /goform/WifiBasicSet.

CVE-2023-35801
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

A directory traversal vulnerability in Safe Software FME Server before 2022.2.5 allows an attacker to bypass validation when editing a network-based resource connection, resulting in the unauthorized reading and writing of arbitrary files. Successful exploitation requires an attacker to have access to a user account with write privileges. FME Flow 2023.0 is also a fixed version.

CVE-2023-38022
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

An issue was discovered in Fortanix EnclaveOS Confidential Computing Manager (CCM) Platform before 3.29 for Intel SGX. Insufficient pointer validation allows a local attacker to access unauthorized information. This relates to strlen and sgx_is_within_user.

CVE-2023-2605
wpbrutalai Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

The wpbrutalai WordPress plugin before 2.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a logged in high privilege users such as admin.

CVE-2023-41627
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

O-RAN Software Community ric-plt-lib-rmr v4.9.0 does not validate the source of the routing tables it receives, potentially allowing attackers to send forged routing tables to the device.

CVE-2023-52257
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

LogoBee 0.2 allows updates.php?id= XSS.

CVE-2023-38932
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Tenda F1202 V1.2.0.9, PA202 V1.1.2.5, PW201A V1.1.2.5 and FH1202 V1.2.0.9 were discovered to contain a stack overflow via the page parameter in the SafeEmailFilter function.

CVE-2023-39578
Software Genérico Web
N/A
UNKNOWN
EPSS
1.6%
2023 1 PoC

A stored cross-site scripting (XSS) vulnerability in the Create function of Zenario CMS v9.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Menu navigation text field.