7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-38911
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A Cross-Site Scripting (XSS) vulnerability in CSZ CMS 1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Gallery parameter in the YouTube URL fields.

CVE-2023-0076
Download Attachments Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Download Attachments WordPress plugin before 1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-33568
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.8%
2023 1 PoC

An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.

CVE-2023-33336
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

Reflected cross site scripting (XSS) vulnerability was discovered in Sophos Web Appliance v4.3.9.1 that allows for arbitrary code to be inputted via the double quotes.

CVE-2023-40817
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

OpenCRX version 5.2.0 is vulnerable to HTML injection via the Product Configuration Name Field.

CVE-2023-36211
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Barebones CMS v2.0.2 is vulnerable to Stored Cross-Site Scripting (XSS) when an authenticated user interacts with certain features on the admin panel.

CVE-2023-47250
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 3 PoCs

In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, broken Access Control on X11 server sockets allows authenticated attackers (with access to a VNC session) to access the X11 desktops of other users by specifying their DISPLAY ID. This allows complete control of their desktop, including the ability to inject keystrokes and perform a keylogging attack.

CVE-2023-24728
Software Genérico Database
N/A
UNKNOWN
EPSS
0.9%
2023 2 PoCs

Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the contact parameter in the user profile update function.

CVE-2023-50495
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().

CVE-2023-5799
WP Hotel Booking Web Windows
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing Contributor and above roles to delete posts that do no belong to them

CVE-2023-41642
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
17.0%
2023 1 PoC

Multiple reflected cross-site scripting (XSS) vulnerabilities in the ErroreNonGestito.aspx component of GruppoSCAI RealGimm 1.1.37p38 allow attackers to execute arbitrary Javascript in the context of a victim user's browser via a crafted payload injected into the VIEWSTATE parameter.

CVE-2023-36123
Software Genérico General
N/A
UNKNOWN
EPSS
11.9%
2023 1 PoC

Directory Traversal vulnerability in Hex-Dragon Plain Craft Launcher 2 version Alpha 1.3.9, allows local attackers to execute arbitrary code and gain sensitive information.

CVE-2023-36163
Software Genérico General
N/A
UNKNOWN
EPSS
16.7%
2023 2 PoCs

Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the mc parameter of the URL.

CVE-2023-3356
Subscribers Text Counter Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Subscribers Text Counter WordPress plugin before 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

CVE-2023-6114
Duplicator Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
61.3%
2023 2 PoCs

The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup-pro/tmp` directory in the Pro version), which temporarily stores files containing sensitive data. When directory listing is enabled in the web server, this allows unauthenticated attackers to discover and access these sensitive files, which include a full database dump and a zip archive of the site.

CVE-2023-48799
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2023 2 PoCs

TOTOLINK-X6000R Firmware-V9.4.0cu.852_B20230719 is vulnerable to Command Execution.

CVE-2023-35695
Trend Micro Moibile Security for Enterprise General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A remote attacker could leverage a vulnerability in Trend Micro Mobile Security (Enterprise) 9.8 SP5 to download a particular log file which may contain sensitive information regarding the product.

CVE-2023-29487
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to cause a denial of service (DoS) via the Threat To Process Correlation threat prevention module. NOTE: Heimdal asserts this is not a valid vulnerability. Their DNS Security for Endpoint solution includes an optional feature to provide extra information on the originating process that made a DNS request. The lack of process identification in DNS logs is therefore falsely categorized as a DoS issue.

CVE-2023-21389
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In Settings, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-27207
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php.