7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-2296
Loginizer Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Loginizer WordPress plugin before 1.7.9 does not escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-48830
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export.

CVE-2023-5729
Firefox General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A malicious web site can enter fullscreen mode while simultaneously triggering a WebAuthn prompt. This could have obscured the fullscreen notification and could have been leveraged in a spoofing attack. This vulnerability affects Firefox < 119.

CVE-2023-20586
Radeon™ Software Crimson ReLive Edition General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

A potential vulnerability was reported in Radeon™ Software Crimson ReLive Edition which may allow escalation of privilege. Radeon™ Software Crimson ReLive Edition falls outside of the security support lifecycle and AMD does not plan to release any mitigations

CVE-2023-0538
Campaign URL Builder Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Campaign URL Builder WordPress plugin before 1.8.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-4051
Firefox General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2.

CVE-2023-51200
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

Sin descripción disponible.

CVE-2023-36256
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

The Online Examination System Project 1.0 version is vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker can craft a malicious link that, when clicked by an admin user, will delete a user account from the database without the admin's consent. The email of the user to be deleted is passed as a parameter in the URL, which can be manipulated by the attacker. This could result in a loss of data.

CVE-2023-43875
Software Genérico Web
N/A
UNKNOWN
EPSS
2.6%
2023 2 PoCs

Multiple Cross-Site Scripting (XSS) vulnerabilities in installation of Subrion CMS v.4.2.1 allows a local attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost, dbname, dbuser, adminusername and adminemail.

CVE-2023-0489
SlideOnline Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The SlideOnline WordPress plugin through 1.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-40084
Android General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

In run of MDnsSdListener.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-22957
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.4%
2023 4 PoCs

An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or configuration files is able to decrypt encrypted values and retrieve sensitive information, e.g., the device root password.

CVE-2023-5609
Seraphinite Accelerator Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Seraphinite Accelerator WordPress plugin before 2.2.29 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-2122
Image Optimizer by 10web Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
17.8%
2023 1 PoC

The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter before rendering it in the plugin admin panel, leading to a reflected Cross-Site Scripting vulnerability, allowing an attacker to trick a logged in admin to execute arbitrary javascript by clicking a link.

CVE-2023-21292
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In openContentUri of ActivityManagerService.java, there is a possible way for a third party app to obtain restricted files due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-43263
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2023 2 PoCs

A Cross-site scripting (XSS) vulnerability in Froala Editor v.4.1.1 allows attackers to execute arbitrary code via the Markdown component.

CVE-2023-0588
Catalyst Connect Zoho CRM Client Portal Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Catalyst Connect Zoho CRM Client Portal WordPress plugin before 2.1.0 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admin.

CVE-2023-37206
Firefox General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Uploading files which contain symlinks may have allowed an attacker to trick a user into submitting sensitive data to a malicious website. This vulnerability affects Firefox < 115.

CVE-2023-37191
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2023 2 PoCs

A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Group and Description parameters.

CVE-2023-47254
Software Genérico General
N/A
UNKNOWN
EPSS
2.1%
2023 2 PoCs

An OS Command Injection in the CLI interface on DrayTek Vigor167 version 5.2.2, allows remote attackers to execute arbitrary system commands and escalate privileges via any account created within the web interface.