7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-36139
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2023 2 PoCs

In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.

CVE-2023-6063
WP Fastest Cache Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.4%
2023 6 PoCs

The WP Fastest Cache WordPress plugin before 1.2.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

CVE-2023-39908
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations on object metadata. This may lead to disclosure of uninitialized and previously used memory.

CVE-2023-49494
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.4%
2023 0 PoCs

DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component select_media_post_wangEditor.php.

CVE-2023-2991
Globalscape EFT General
N/A
UNKNOWN
EPSS
0.3%
2023 CWE-200 2 PoCs

Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial number of the harddrive that Globalscape is installed on can be remotely determined via a "trial extension request" message

CVE-2023-2068
file-manager-advanced-shortcode Web Windows
N/A
UNKNOWN
EPSS
70.4%
2023 2 PoCs

The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.

CVE-2023-24655
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Profile Update function.

CVE-2023-0551
REST API TO MiniProgram Web Windows
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

The REST API TO MiniProgram WordPress plugin through 4.6.1 does not have authorisation and CSRF checks in an AJAX action, allowing ay authenticated users, such as subscriber to call and delete arbitrary attachments

CVE-2023-0219
FluentSMTP Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The FluentSMTP WordPress plugin before 2.2.3 does not sanitize or escape email content, making it vulnerable to stored cross-site scripting attacks (XSS) when an administrator views the email logs. This exploit requires other plugins to enable users to send emails with unfiltered HTML.

CVE-2023-48205
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Jorani Leave Management System 1.0.2 allows a remote attacker to spoof a Host header associated with password reset emails.

CVE-2023-24040
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

dtprintinfo in Common Desktop Environment 1.6 has a bug in the parser of lpstat (an invoked external command) during listing of the names of available printers. This allows low-privileged local users to inject arbitrary printer names via the $HOME/.printers file. This injection allows those users to manipulate the control flow and disclose memory contents on Solaris 10 systems. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-34929
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A stack overflow in the AddMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2023-0539
GS Insever Portfolio Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The GS Insever Portfolio WordPress plugin before 1.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-40755
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.3%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Callback Widget v1.0.

CVE-2023-36309
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Document Creator v1.0.

CVE-2023-24134
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey3 parameter at /goform/WifiBasicSet.

CVE-2023-23161
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
2.2%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the artname parameter under ART TYPE option in the navigation bar.

CVE-2023-35799
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create arbitrary files with local system privileges.

CVE-2023-1597
tagDiv Cloud Library Web Cloud Windows
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The tagDiv Cloud Library WordPress plugin before 2.7 does not have authorisation and CSRF in an AJAX action accessible to both unauthenticated and authenticated users, allowing unauthenticated users to change arbitrary user metadata, which could lead to privilege escalation by setting themselves as an admin of the blog.

CVE-2023-47323
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2023 1 PoC

The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all messages sent between other users; including those sent only to administrators.