7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-37635
Software Genérico General
N/A
UNKNOWN
EPSS
8.2%
2023 1 PoC

UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application.

CVE-2023-36630
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

In CloudPanel before 2.3.1, insecure file upload leads to privilege escalation and authentication bypass.

CVE-2023-42270
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Grocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF).

CVE-2023-38870
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book has a feature to list accomplishments by category, and the 'category_id' parameter is vulnerable to SQL Injection.

CVE-2023-40752
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.

CVE-2023-23301
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The `news` MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not extending past the end of the expected sections. A malicious CIQ application could craft a string that starts near the end of a section, and whose length extends past its end. Upon loading the string, the GarminOS TVM component may read out-of-bounds memory.

CVE-2023-44216
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2023 5 PoCs

PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text contained on a web page from one origin if they control a resource from a different origin.

CVE-2023-34669
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

TOTOLINK CP300+ V5.2cu.7594 contains a Denial of Service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system.

CVE-2023-41717
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Inappropriate file type control in Zscaler Proxy versions 3.6.1.25 and prior allows local attackers to bypass file download/upload restrictions.

CVE-2023-36669
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Missing Authentication for a Critical Function within the Kratos NGC Indoor Unit (IDU) before 11.4 allows remote attackers to obtain arbitrary control of the IDU/ODU system. Any attacker with layer-3 network access to the IDU can impersonate the Touch Panel Unit (TPU) within the IDU by sending crafted TCP requests to the IDU.

CVE-2023-48811
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution vulnerability.

CVE-2023-44763
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cross-Site Scripting (XSS). NOTE: the vendor's position is that a customer is supposed to know that "pdf" should be excluded from the allowed file types, even though pdf is one of the allowed file types in the default configuration.

CVE-2023-38571
macOS General
N/A
UNKNOWN
EPSS
10.5%
2023 1 PoC

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Big Sur 11.7.9, macOS Monterey 12.6.8, macOS Ventura 13.5. An app may be able to bypass Privacy preferences.

CVE-2023-37683
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Profile Page of the Admin.

CVE-2023-0264
Keycloak General
N/A
UNKNOWN
EPSS
3.9%
2023 1 PoC

A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availability.

CVE-2023-36624
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Loxone Miniserver Go Gen.2 through 14.0.3.28 allows an authenticated operating system user to escalate privileges via the Sudo configuration. This allows the elevated execution of binaries without a password requirement.

CVE-2023-49070
Apache OFBiz Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.0%
2023 CWE-94 7 PoCs

Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Users are recommended to upgrade to version 18.12.10

CVE-2023-2718
Contact Form Email Web Windows
N/A
UNKNOWN
EPSS
0.5%
2023 2 PoCs

The Contact Form Email WordPress plugin before 1.3.38 does not escape submitted values before displaying them in the HTML, leading to a Stored XSS vulnerability.

CVE-2023-0431
File Away Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The File Away WordPress plugin through 3.9.9.0.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

CVE-2023-27470
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at %PROGRAMDATA%\GetSupportService_N-Central\PushUpdates, leading to arbitrary file deletion.