7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-38904
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

A Cross Site Scripting (XSS) vulnerability in Netlify CMS v.2.10.192 allows a remote attacker to execute arbitrary code via a crafted payload to the body parameter of the new post function.

CVE-2023-32781
Software Genérico General
N/A
UNKNOWN
EPSS
47.2%
2023 1 PoC

A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed by the EXE/Script sensor. The severity of this vulnerability is high and received a score of 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CVE-2023-44812
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
36.7%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a crafted payload to the admin_redirect_url parameter of the user login function.

CVE-2023-35800
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, which could allow access to information reserved to administrators.

CVE-2023-37798
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A stored cross-site scripting (XSS) vulnerability in the new REDCap project creation function of Vanderbilt REDCap 13.1.35 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the project title parameter.

CVE-2023-47322
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the Silverpeas application, the CSRF with execute making the attacker an administrator user in the application.

CVE-2023-45887
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2023 1 PoC

DS Wireless Communication (DWC) with DWC_VERSION_3 and DWC_VERSION_11 allows remote attackers to execute arbitrary code on a game-playing client's machine via a modified GPCM message.

CVE-2023-36144
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
85.5%
2023 1 PoC

An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the device, exposing critical information about the device configuration.

CVE-2023-39712
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 3 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Put section.

CVE-2023-20562
μProf General
N/A
UNKNOWN
EPSS
10.2%
2023 3 PoCs

Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD uProf may allow an authenticated user to load an unsigned driver potentially leading to arbitrary kernel execution.

CVE-2023-27132
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

TSplus Remote Work 16.0.0.0 places a cleartext password on the "var pass" line of the HTML source code for the secure single sign-on web portal. NOTE: CVE-2023-31069 is only about the TSplus Remote Access product, not the TSplus Remote Work product.

CVE-2023-38890
Software Genérico Database
N/A
UNKNOWN
EPSS
5.6%
2023 2 PoCs

Online Shopping Portal Project 3.1 allows remote attackers to execute arbitrary SQL commands/queries via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username field, enabling SQL Injection attacks.

CVE-2023-40924
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
61.1%
2023 1 PoC

SolarView Compact < 6.00 is vulnerable to Directory Traversal.

CVE-2023-41614
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A stored cross-site scripting (XSS) vulnerability in the Add Animal Details function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description of Animal parameter.

CVE-2023-38830
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

An information leak in PHPJabbers Yacht Listing Script v1.0 allows attackers to export clients' credit card numbers from the Reservations module.

CVE-2023-4549
DoLogin Security Web Windows
N/A
UNKNOWN
EPSS
1.3%
2023 2 PoCs

The DoLogin Security WordPress plugin before 3.7 does not properly sanitize IP addresses coming from the X-Forwarded-For header, which can be used by attackers to conduct Stored XSS attacks via WordPress' login form.

CVE-2023-37208
Firefox General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.

CVE-2023-6870
Firefox General
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox. *This issue only affects Android versions of Firefox and Firefox Focus.* This vulnerability affects Firefox < 121.

CVE-2023-49052
Software Genérico General
N/A
UNKNOWN
EPSS
26.3%
2023 1 PoC

File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function in the created forms component.

CVE-2023-21145
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In updatePictureInPictureMode of ActivityRecord.java, there is a possible bypass of background launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.