7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-43866
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2023 1 PoC

D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard7 function.

CVE-2023-43356
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Global Meatadata parameter in the Global Settings Menu component.

CVE-2023-38324
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

An issue was discovered in OpenNDS before 10.1.2. It allows users to skip the splash page sequence (and directly authenticate) when it is using the default FAS key and OpenNDS is configured as FAS. Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.

CVE-2023-43865
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2023 1 PoC

D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanPPTP function.

CVE-2023-30415
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /inquiries/view_inquiry.php.

CVE-2023-48806
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

CVE-2023-31717
Software Genérico Database
N/A
UNKNOWN
EPSS
30.8%
2023 2 PoCs

A SQL Injection attack in FUXA <= 1.1.12 allows exfiltration of confidential information from the database.

CVE-2023-37758
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 3 PoCs

D-LINK DIR-815 v1.01 was discovered to contain a buffer overflow via the component /web/captcha.cgi.

CVE-2023-20808
MT9011, MT9022, MT9618, MT9649, MT9653 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In OPTEE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03645895; Issue ID: DTV03645895.

CVE-2023-41166
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1. It's possible to know if a specific user account exists on the SNS firewall by using remote access commands.

CVE-2023-40748
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
44.5%
2023 2 PoCs

PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.

CVE-2023-38353
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

MiniTool Power Data Recovery version 11.6 and before contains an insecure in-app payment system that allows attackers to steal highly sensitive information through a man in the middle attack.

CVE-2023-3182
Membership Plugin Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Membership WordPress plugin before 3.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-20807
MT2713, MT6895, MT6983, MT8188, MT8195, MT8395, MT8673 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In dpe, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07608433; Issue ID: ALPS07608433.

CVE-2023-44758
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

GDidees CMS 3.0 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload to the Page Title.

CVE-2023-31754
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Optimizely CMS UI before v12.16.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Admin panel.

CVE-2023-37728
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
17.3%
2023 2 PoCs

IceWarp v10.2.1 was discovered to contain cross-site scripting (XSS) vulnerability via the color parameter.

CVE-2023-28876
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A Broken Access Control issue in comments to uploaded files in Filerun through Update 20220202 allows attackers to delete comments on files uploaded by other users.

CVE-2023-43877
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a payload crafted in the Home Page fields in the Administration menu.

CVE-2023-31606
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2023 2 PoCs

A Regular Expression Denial of Service (ReDoS) issue was discovered in the sanitize_html function of redcloth gem v4.0.0. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.