7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-24674
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2023 3 PoCs

Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter.

CVE-2023-33564
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3.

CVE-2023-1234
Chrome General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Inappropriate implementation in Intents in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2023-1201
Devolutions Server General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Improper access control in the secure messages feature in Devolutions Server 2022.3.12 and below allows an authenticated attacker that possesses the message UUID to access the data it contains.

CVE-2023-27213
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Online Student Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /eduauth/student/search.php.

CVE-2023-1891
Accordion & FAQ Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Accordion & FAQ WordPress plugin before 1.9.9 does not escape various generated URLs, before outputting them in attributes when some notices are displayed, leading to Reflected Cross-Site Scripting

CVE-2023-51204
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

Sin descripción disponible.

CVE-2023-27121
Software Genérico Web
N/A
UNKNOWN
EPSS
4.8%
2023 1 PoC

A cross-site scripting (XSS) vulnerability in the component /framework/cron/action/humanize of Pleasant Solutions Pleasant Password Server v7.11.41.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cronString parameter.

CVE-2023-43878
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a crafted payload into the Main Menu Items in the Administration Menu.

CVE-2023-46384
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. Cleartext storage of credentials allows remote attackers to disclose admin password and bypass an authentication to login Loytec device.

CVE-2023-38875
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.9%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'validator' parameter in '/reset-password'.

CVE-2023-0231
ShopLentor Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The ShopLentor WordPress plugin before 2.5.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-26958
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Phpgurukul Park Ticketing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Admin Name parameter.

CVE-2023-1203
Remote Desktop Manager PowerShell Module General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Improper removal of sensitive data in the entry edit feature of Hub Business submodule in Devolutions Remote Desktop Manager PowerShell Module 2022.3.1.5 and earlier allows an authenticated user to access sensitive data on entries that were edited using the affected submodule.

CVE-2023-21281
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In multiple functions of KeyguardViewMediator.java, there is a possible failure to lock after screen timeout due to a logic error in the code. This could lead to local escalation of privilege across users with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-38429
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allocation (because of ksmbd_smb2_check_message) that may lead to out-of-bounds access.

CVE-2023-44824
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploaded to the sign-up.php component.

CVE-2023-36969
Software Genérico Web
N/A
UNKNOWN
EPSS
71.5%
2023 1 PoC

CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.

CVE-2023-38591
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Netgear DG834Gv5 1.6.01.34 was discovered to contain multiple buffer overflows via the wla_ssid and wla_temp_ssid parameters at bsw_ssid.cgi.

CVE-2023-45867
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

ILIAS (2013-09-12 release) contains a medium-criticality Directory Traversal local file inclusion vulnerability in the ScormAicc module. An attacker with a privileged account, typically holding the tutor role, can exploit this to gain unauthorized access to and potentially retrieve confidential files stored on the web server. The attacker can access files that are readable by the web server user www-data; this may include sensitive configuration files and documents located outside the documentRoot. The vulnerability is exploited by an attacker who manipulates the file parameter in a URL, inser