7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-26326
BuddyForms WordPress Plugin Web Windows
N/A
UNKNOWN
EPSS
45.0%
2023 3 PoCs

The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present.

CVE-2023-37361
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

REDCap 12.0.26 LTS and 12.3.2 Standard allows SQL Injection via scheduling, repeatforms, purpose, app_title, or randomization.

CVE-2023-20565
Ryzen™ 5000 Series Desktop Processor with Radeon™ Graphics “Cezanne” General
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.

CVE-2023-2359
Slider Revolution Web Windows
N/A
UNKNOWN
EPSS
6.3%
2023 2 PoCs

The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.

CVE-2023-46574
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2023 0 PoCs

An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.

CVE-2023-36306
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
5.3%
2023 1 PoC

A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the asktheoracle.php, details.php, index.php, search.php, export.php, reports.php, and statistics.php components.

CVE-2023-35793
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

An issue was discovered in Cassia Access Controller 2.1.1.2303271039. Establishing a web SSH session to gateways is vulnerable to Cross Site Request Forgery (CSRF) attacks.

CVE-2023-49006
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Cross Site Request Forgery (CSRF) vulnerability in Phpsysinfo version 3.4.3 allows a remote attacker to obtain sensitive information via a crafted page in the XML.php file.

CVE-2023-2989
Globalscape EFT General
N/A
UNKNOWN
EPSS
0.1%
2023 CWE-125 2 PoCs

Fortra Globalscape EFT versions before 8.1.0.16 suffer from an out of bounds memory read in their administration server, which can allow an attacker to crash the service or bypass authentication if successfully exploited

CVE-2023-39676
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
6.1%
2023 1 PoC

FieldPopupNewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback parameter at ajax.php.

CVE-2023-5958
POST SMTP Mailer Web Windows
N/A
UNKNOWN
EPSS
0.8%
2023 1 PoC

The POST SMTP Mailer WordPress plugin before 2.7.1 does not escape email message content before displaying it in the backend, allowing an unauthenticated attacker to perform XSS attacks against highly privileged users.

CVE-2023-33270
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2023 1 PoC

An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the Curl check function is vulnerable to OS command injection (blind).

CVE-2023-36672
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

An issue was discovered in the Clario VPN client through 5.9.1.1662 for macOS. The VPN client insecurely configures the operating system such that traffic to the local network is sent in plaintext outside the VPN tunnel even if the local network is using a non-RFC1918 IP subnet. This allows an adversary to trick the victim into sending arbitrary IP traffic in plaintext outside the VPN tunnel. NOTE: the tunnelcrack.mathyvanhoef.com website uses this CVE ID to refer more generally to "LocalNet attack resulting in leakage of traffic in plaintext" rather than to only Clario.

CVE-2023-28660
Events Made Easy WordPress Plugin Web Database Windows
N/A
UNKNOWN
EPSS
1.1%
2023 1 PoC

The Events Made Easy WordPress Plugin, version <= 2.3.14 is affected by an authenticated SQL injection vulnerability in the 'search_name' parameter in the eme_recurrences_list action.

CVE-2023-27211
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A cross-site scripting (XSS) vulnerability in /admin/navbar.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page parameter.

CVE-2023-43325
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
19.7%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the data[redirect_url] parameter of mooSocial v3.1.8 allows attackers to steal user's session cookies and impersonate their account via a crafted URL.

CVE-2023-39639
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

LeoTheme leoblog up to v3.1.2 was discovered to contain a SQL injection vulnerability via the component LeoBlogBlog::getListBlogs.

CVE-2023-5673
WP Mail Log Web Windows
N/A
UNKNOWN
EPSS
1.4%
2023 1 PoC

The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file extensions uploading files to attach to emails, allowing attackers to upload PHP files, leading to remote code execution.

CVE-2023-34659
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
91.9%
2023 0 PoCs

jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.

CVE-2023-40989
Software Genérico Database
N/A
UNKNOWN
EPSS
38.7%
2023 1 PoC

SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeecgboot/jmreport/queryFieldBySql component.