7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-5611
Seraphinite Accelerator Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Seraphinite Accelerator WordPress plugin before 2.20.32 does not have authorisation and CSRF checks when resetting and importing its settings, allowing unauthenticated users to reset them

CVE-2023-26913
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

EVOLUCARE ECSIMAGING (aka ECS Imaging) < 6.21.5 is vulnerable to Cross Site Scripting (XSS) via new_movie. php.

CVE-2023-3650
Bubble Menu Web Windows
N/A
UNKNOWN
EPSS
1.8%
2023 1 PoC

The Bubble Menu WordPress plugin before 3.0.5 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVE-2023-31492
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the authenticated users.

CVE-2023-22974
Software Genérico Web Database
N/A
UNKNOWN
EPSS
4.5%
2023 1 PoC

A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controlling a connection to an attacker-controlled MySQL server.

CVE-2023-21246
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In ShortcutInfo of ShortcutInfo.java, there is a possible way for an app to retain notification listening access due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-1208
HTTP Headers Web Windows
N/A
UNKNOWN
EPSS
3.7%
2023 1 PoC

This HTTP Headers WordPress plugin before 1.18.11 allows arbitrary data to be written to arbitrary files, leading to a Remote Code Execution vulnerability.

CVE-2023-6205
Firefox General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

CVE-2023-39004
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to privilege escalation.

CVE-2023-36217
Software Genérico Web
N/A
UNKNOWN
EPSS
5.1%
2023 1 PoC

Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function.

CVE-2023-38876
Software Genérico Web
N/A
UNKNOWN
EPSS
7.6%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'selector' parameter in '/reset-password'.

CVE-2023-37192
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

Memory management and protection issues in Bitcoin Core v22 allows attackers to modify the stored sending address within the app's memory, potentially allowing them to redirect Bitcoin transactions to wallets of their own choosing.

CVE-2023-5906
Job Manager & Career Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Job Manager & Career WordPress plugin before 1.4.4 contains a vulnerability in the Directory Listings system, which allows an unauthorized user to view and download private files of other users. This vulnerability poses a serious security threat because it allows an attacker to gain access to confidential data and files of other users without their permission.

CVE-2023-39000
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the component /ui/diagnostics/log/core/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to inject arbitrary JavaScript via the URL path.

CVE-2023-43357
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the Manage Shortcuts component.

CVE-2023-29998
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A Cross-site scripting (XSS) vulnerability in the content editor in Gis3W g3w-suite 3.5 allows remote authenticated users to inject arbitrary web script or HTML and gain privileges via the description parameter.

CVE-2023-21522
AtHoc Web
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

A Reflected Cross-site Scripting (XSS) vulnerability in the Management Console (Reports) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially control a script that is executed in the victim's browser then they can execute script commands in the context of the affected user account. 

CVE-2023-41616
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

A reflected cross-site scripting (XSS) vulnerability in the Search Student function of Student Management System v1.2.3 and before allows attackers to execute arbitrary Javascript in the context of a victim user's browser via a crafted payload.

CVE-2023-38430
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue was discovered in the Linux kernel before 6.3.9. ksmbd does not validate the SMB request protocol ID, leading to an out-of-bounds read.

CVE-2023-49964
Software Genérico General
N/A
UNKNOWN
EPSS
5.7%
2023 1 PoC

An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attacker may perform SSTI (Server-Side Template Injection) attacks, which can leverage FreeMarker exposed objects to bypass restrictions and achieve RCE (Remote Code Execution). NOTE: this issue exists because of an incomplete fix for CVE-2020-12873.