7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-36619
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2023 2 PoCs

Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users.

CVE-2023-43346
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Backend - Dashboard parameter in the Languages Menu component.

CVE-2023-36621
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictions temporarily or uninstall the application without the parents noticing.

CVE-2023-34830
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2023 2 PoCs

i-doit Open v24 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the timeout parameter on the login page.

CVE-2023-27974
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Bitwarden through 2023.2.1 offers password auto-fill when the second-level domain matches, e.g., a password stored for an example.com hosting provider when customer-website.example.com is visited. NOTE: the vendor's position is that "Auto-fill on page load" is not enabled by default.

CVE-2023-5173
Firefox Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a local unprivileged webpage), leading to an out-of-bounds write to privileged process memory. *This bug only affects Firefox if a non-standard preference allowing non-HTTPS Alternate Services (`network.http.altsvc.oe`) is enabled.* This vulnerability affects Firefox < 118.

CVE-2023-34934
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A stack overflow in the Edit_BasicSSID_5G function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2023-44047
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Sourcecodester Toll Tax Management System v1 is vulnerable to SQL Injection.

CVE-2023-44275
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

OPNsense before 23.7.5 allows XSS via the index.php column_count parameter to the Lobby Dashboard.

CVE-2023-44838
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the TXPower parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-5509
Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The myStickymenu WordPress plugin before 2.6.5 does not adequately authorize some ajax calls, allowing any logged-in user to perform the actions.

CVE-2023-38928
Software Genérico General
N/A
UNKNOWN
EPSS
1.6%
2023 1 PoC

Netgear R7100LG 1.0.0.78 was discovered to contain a command injection vulnerability via the password parameter at usb_remote_invite.cgi.

CVE-2023-20781
MT6580, MT6731, MT6735, MT6737, MT6739, MT6753, MT6757, MT6757C, MT6757CD, MT6757CH, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6891, MT6893, MT6895, MT6983, MT6985, MT8185, MT8321, MT8385, MT8666, MT8673, MT8675, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8797 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In keyinstall, there is a possible memory corruption due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017756; Issue ID: ALPS07905323.

CVE-2023-5610
Seraphinite Accelerator Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Seraphinite Accelerator WordPress plugin before 2.2.29 does not validate the URL to redirect any authenticated user to, leading to an arbitrary redirect

CVE-2023-41637
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

An arbitrary file upload vulnerability in the Carica immagine function of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted HTML file.

CVE-2023-43345
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Content - Name parameter in the Pages Menu component.

CVE-2023-2255
LibreOffice General
N/A
UNKNOWN
EPSS
42.5%
2023 CWE-264 5 PoCs

Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of LibreOffice documents that used "floating frames" linked to external files, would load the contents of those frames without prompting the user for permission to do so. This was inconsistent with the treatment of other linked content in LibreOffice. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.7; 7.5 versions prior to 7.5.3.

CVE-2023-4262
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Sin descripción disponible.

CVE-2023-2628
KiviCare Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The KiviCare WordPress plugin before 3.2.1 does not have CSRF checks (either flawed or missing completely) in various AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. This includes, but is not limited to: Delete arbitrary appointments/medical records/etc, create/update various users (patients, doctors etc)

CVE-2023-39121
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
2.7%
2023 0 PoCs

emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.