7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-46383
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

LOYTEC electronics GmbH LINX Configurator (all versions) uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the password and gain full control of Loytec device configuration.

CVE-2023-23315
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The PrestaShop e-commerce platform module stripejs contains a Blind SQL injection vulnerability up to version 4.5.5. The method `stripejsValidationModuleFrontController::initContent()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

CVE-2023-38355
Software Genérico General
N/A
UNKNOWN
EPSS
6.0%
2023 1 PoC

MiniTool Movie Maker 7.0 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

CVE-2023-31719
Software Genérico Web Database
N/A
UNKNOWN
EPSS
65.5%
2023 2 PoCs

FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.

CVE-2023-6860
Firefox ESR General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.

CVE-2023-43906
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Xolo CMS v0.11 was discovered to contain a reflected cross-site scripting (XSS) vulnerability.

CVE-2023-21274
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-5209
WordPress Online Booking and Scheduling Plugin Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-31293
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to obtain sensitive information and bypass profile restriction via improper access control in the Reader system user's web browser, allowing the journal to be displayed, despite the option being disabled.

CVE-2023-36317
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in sourcecodester Student Study Center Desk Management System 1.0 allows attackers to run arbitrary code via crafted GET request to web application URL.

CVE-2023-48208
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php.

CVE-2023-6295
SiteOrigin Widgets Bundle Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The SiteOrigin Widgets Bundle WordPress plugin before 1.51.0 does not validate user input before using it to generate paths passed to include function/s, allowing users with the administrator role to perform LFI attacks in the context of Multisite WordPress sites.

CVE-2023-39909
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application.

CVE-2023-40754
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 2 PoCs

In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.

CVE-2023-43494
Jenkins DevOps
N/A
UNKNOWN
EPSS
49.1%
2023 1 PoC

Jenkins 2.50 through 2.423 (both inclusive), LTS 2.60.1 through 2.414.1 (both inclusive) does not exclude sensitive build variables (e.g., password parameter values) from the search in the build history widget, allowing attackers with Item/Read permission to obtain values of sensitive variables used in builds by iteratively testing different characters until the correct sequence is discovered.

CVE-2023-2223
Login rebuilder Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

The Login rebuilder WordPress plugin before 2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-46288
Apache Airflow Web
N/A
UNKNOWN
EPSS
0.6%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.4.0 to 2.7.0. Sensitive configuration information has been exposed to authenticated users with the ability to read configuration via Airflow REST API for configuration even when the expose_config option is set to non-sensitive-only. The expose_config option is False by default. It is recommended to upgrade to a version that is not affected if you set expose_config to non-sensitive-only configuration. This is a different error than CVE-2023-45348 which allows auth

CVE-2023-30367
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Multi-Remote Next Generation Connection Manager (mRemoteNG) is free software that enables users to store and manage multi-protocol connection configurations to remotely connect to systems. mRemoteNG configuration files can be stored in an encrypted state on disk. mRemoteNG version <= v1.76.20 and <= 1.77.3-dev loads configuration files in plain text into memory (after decrypting them if necessary) at application start-up, even if no connection has been established yet. This allows attackers to access contents of configuration files in plain text through a memory dump and thus compromise user c

CVE-2023-46382
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) use cleartext HTTP for login.

CVE-2023-36344
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue in Diebold Nixdorf Vynamic View Console v.5.3.1 and before allows a local attacker to execute arbitrary code via not restricting the search path for required DLLs and not verifying the signature.