7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-50070
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_ticket via department_id, customer_id, and subject.

CVE-2023-34725
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows physical attackers to gain escalated privileges via a telnet connection.

CVE-2023-38409
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon.c in the Linux kernel before 6.2.12. Because an assignment occurs only for the first vc, the fbcon_registered_fb and fbcon_display arrays can be desynchronized in fbcon_mode_deleted (the con2fb_map points at the old fb_info).

CVE-2023-0165
Cost Calculator Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Cost Calculator WordPress plugin through 1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-2580
AI Engine: ChatGPT Chatbot, Content Generator, GPT 3 & 4, Ultra-Customizable Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The AI Engine WordPress plugin before 1.6.83 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVE-2023-2906
Wireshark General
N/A
UNKNOWN
EPSS
0.2%
2023 CWE-369 2 PoCs

Due to a failure in validating the length provided by an attacker-crafted CP2179 packet, Wireshark versions 2.0.0 through 4.0.7 is susceptible to a divide by zero allowing for a denial of service attack.

CVE-2023-44767
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A File upload vulnerability in RiteCMS 3.0 allows a local attacker to upload a SVG file with XSS content.

CVE-2023-34132
GMS Networking
N/A
UNKNOWN
EPSS
70.3%
2023 CWE-836 1 PoC

Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

CVE-2023-41507
Software Genérico Database
N/A
UNKNOWN
EPSS
0.5%
2023 2 PoCs

Super Store Finder v3.6 was discovered to contain multiple SQL injection vulnerabilities in the store locator component via the products, distance, lat, and lng parameters.

CVE-2023-43860
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2023 1 PoC

D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanNonLogin function.

CVE-2023-28661
WP Popup Banners WordPress Plugin Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

The WP Popup Banners WordPress Plugin, version <= 1.2.5, is affected by an authenticated SQL injection vulnerability in the 'value' parameter in the get_popup_data action.

CVE-2023-5737
WordPress Backup & Migration Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users with a role as low as Subscriber to update some plugin settings.

CVE-2023-3131
MStore API Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both.

CVE-2023-24671
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

VX Search v13.8 and v14.7 was discovered to contain an unquoted service path vulnerability which allows attackers to execute arbitrary commands at elevated privileges via a crafted executable file.

CVE-2023-36310
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

There is a Cross Site Scripting (XSS) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0.

CVE-2023-45281
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file.

CVE-2023-40763
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

User enumeration is found in PHPJabbers Taxi Booking Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-35861
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2023 1 PoC

A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC.

CVE-2023-0263
WP Yelp Review Slider Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

The WP Yelp Review Slider WordPress plugin before 7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

CVE-2023-41597
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
11.5%
2023 0 PoCs

EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.