7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-33264
Software Genérico General
N/A
UNKNOWN
EPSS
1.7%
2023 3 PoCs

In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.

CVE-2023-2803
Ultimate Addons for Contact Form 7 Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Ultimate Addons for Contact Form 7 WordPress plugin before 3.1.29 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-34834
Software Genérico General
N/A
UNKNOWN
EPSS
3.3%
2023 1 PoC

A Directory Browsing vulnerability in MCL-Net version 4.3.5.8788 webserver running on default port 5080, allows attackers to gain sensitive information about the configured databases via the "/file" endpoint.

CVE-2023-40448
iOS and iPadOS General
N/A
UNKNOWN
EPSS
0.9%
2023 1 PoC

The issue was addressed with improved handling of protocols. This issue is fixed in tvOS 17, iOS 16.7 and iPadOS 16.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. A remote attacker may be able to break out of Web Content sandbox.

CVE-2023-5672
WP Mail Log Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file path parameters when attaching files to emails, leading to local file inclusion, and allowing an attacker to leak the contents of arbitrary files.

CVE-2023-34581
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 3 PoCs

Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&id=2

CVE-2023-39341
FFRI yarai General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

"FFRI yarai", "FFRI yarai Home and Business Edition" and their OEM products handle exceptional conditions improperly, which may lead to denial-of-service (DoS) condition. Affected products and versions are as follows: FFRI yarai versions 3.4.0 to 3.4.6 and 3.5.0, FFRI yarai Home and Business Edition version 1.4.0, InfoTrace Mark II Malware Protection (Mark II Zerona) versions 3.0.1 to 3.2.2, Zerona / Zerona PLUS versions 3.2.32 to 3.2.36, ActSecure χ versions 3.4.0 to 3.4.6 and 3.5.0, Dual Safe Powered by FFRI yarai version 1.4.1, EDR Plus Pack (Bundled FFRI yarai versions 3.4.0 to 3.4.6 and

CVE-2023-36255
Software Genérico General
N/A
UNKNOWN
EPSS
89.5%
2023 2 PoCs

An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path parameter in the URL.

CVE-2023-37600
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Office Suite Premium Version v10.9.1.42602 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /api?path=profile.

CVE-2023-31852
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

Cudy LT400 1.13.4 is vulnerable to Cross Site Scripting (XSS) in cgi-bin/luci/admin/network/wireless/config via the iface parameter.

CVE-2023-37686
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Nurse Page in the Admin portal.

CVE-2023-47350
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in SwiftyEdit Content Management System prior to v1.2.0, allows remote attackers to escalate privileges via the user password update functionality.

CVE-2023-20568
Radeon™ RX 5000/6000/7000 Series Graphics Cards Windows
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch RadeonInstaller.exe without validating the file signature potentially leading to arbitrary code execution.

CVE-2023-41508
Software Genérico General
N/A
UNKNOWN
EPSS
7.2%
2023 2 PoCs

A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel.

CVE-2023-5884
Word Balloon Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Word Balloon WordPress plugin before 4.20.3 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to trick a logged in user to delete arbitrary avatars by clicking a link.

CVE-2023-48840
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.

CVE-2023-37305
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

An issue was discovered in the ProofreadPage (aka Proofread Page) extension for MediaWiki through 1.39.3. In includes/Page/PageContentHandler.php and includes/Page/PageDisplayHandler.php, hidden users can be exposed via public interfaces.

CVE-2023-20802
MT6879, MT6895, MT6983, MT8188, MT8195, MT8395, MT8781 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In imgsys, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07420968; Issue ID: ALPS07420976.

CVE-2023-21286
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-39598
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
56.4%
2023 2 PoCs

Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitrary code via a crafted payload to the mid parameter.