7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-37772
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Online Shopping Portal Project v3.1 was discovered to contain a SQL injection vulnerability via the Email parameter at /shopping/login.php.

CVE-2023-46010
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.

CVE-2023-23162
Software Genérico Web Database
N/A
UNKNOWN
EPSS
3.3%
2023 1 PoC

Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php.

CVE-2023-36126
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Appointment Scheduler v3.0

CVE-2023-39062
Software Genérico Web
N/A
UNKNOWN
EPSS
35.5%
2023 1 PoC

Cross Site Scripting vulnerability in Spipu HTML2PDF before v.5.2.8 allows a remote attacker to execute arbitrary code via a crafted script to the forms.php.

CVE-2023-5605
URL Shortify Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The URL Shortify WordPress plugin before 1.7.9.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-1977
Booking Manager Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Booking Manager WordPress plugin before 2.0.29 does not validate URLs input in it's admin panel or in shortcodes for showing events from a remote .ics file, allowing an attacker with privileges as low as Subscriber to perform SSRF attacks on the sites internal network.

CVE-2023-3510
FTP Access Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The FTP Access WordPress plugin through 1.0 does not have authorisation and CSRF checks when updating its settings and is missing sanitisation as well as escaping in them, allowing any authenticated users, such as subscriber to update them with XSS payloads, which will be triggered when an admin will view the settings of the plugin. The attack could also be perform via CSRF against any authenticated user.

CVE-2023-44276
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.

CVE-2023-45912
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 fails to validate user sessions, allowing unauthenticated attackers to read files from the underlying operating system and obtain directory listings.

CVE-2023-36168
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Sin descripción disponible.

CVE-2023-47283
CubeCart General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to obtain files in the system.

CVE-2023-34723
Software Genérico General
N/A
UNKNOWN
EPSS
3.4%
2023 2 PoCs

An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information via /config/system.conf.

CVE-2023-2627
KiviCare Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The KiviCare WordPress plugin before 3.2.1 does not have proper CSRF and authorisation checks in various AJAX actions, allowing any authenticated users, such as subscriber to call them. Attacks include but are not limited to: Add arbitrary Clinic Admin/Doctors/etc and update plugin's settings

CVE-2023-44760
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS v.9.2.1 allow an attacker to execute arbitrary code via a crafted script to the Header and Footer Tracking Codes of the SEO & Statistics. NOTE: the vendor disputes this because these header/footer changes can only be made by an admin, and allowing an admin to place JavaScript there is an intentional customization feature. Also, the exploitation method claimed by "sromanhu" does not provide any access to a Concrete CMS session, because the Concrete CMS session cookie is configured as HttpOnly.

CVE-2023-43873
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Name filed in the Manage Menu.

CVE-2023-48826
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List.

CVE-2023-36127
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-28121
WooCommerce Payments WordPress Plugin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.7%
2023 CWE-287 8 PoCs

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

CVE-2023-36375
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 3 PoCs

Cross Site Scripting vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the Guardian name, Guardian relation, complimentary address, city, permanent address, and city parameters in the Book Hostel & Room Details page.