7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-43187
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.7%
2023 0 PoCs

A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests.

CVE-2023-2635
Call Now Accessibility Button Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Call Now Accessibility Button WordPress plugin before 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-38434
Software Genérico Web
N/A
UNKNOWN
EPSS
1.8%
2023 1 PoC

xHTTP 72f812d has a double free in close_connection in xhttp.c via a malformed HTTP request method.

CVE-2023-0844
Namaste! LMS Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Namaste! LMS WordPress plugin before 2.6 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-5653
WassUp Real Time Analytics Web Windows
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

The WassUp Real Time Analytics WordPress plugin through 1.9.4.5 does not escape IP address provided via some headers before outputting them back in an admin page, allowing unauthenticated users to perform Stored XSS attacks against logged in admins

CVE-2023-27169
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.

CVE-2023-33269
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2023 1 PoC

An issue was discovered in DTS Monitoring 3.57.0. The parameter options within the WGET check function is vulnerable to OS command injection (blind).

CVE-2023-27225
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in User Registration & Login and User Management System with Admin Panel v3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the first and last name field.

CVE-2023-51035
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

TOTOLINK EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution on the cstecgi.cgi NTPSyncWithHost interface.

CVE-2023-3179
POST SMTP Mailer Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged in users with the manage_postman_smtp capability resend an email to an arbitrary address (for example a password reset email could be resent to an attacker controlled email, and allow them to take over an account).

CVE-2023-31853
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Cudy LT400 1.13.4 is vulnerable Cross Site Scripting (XSS) in /cgi-bin/luci/admin/network/bandwidth via the icon parameter.

CVE-2023-2623
KiviCare Web Windows
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user data, allowing low privilege users such as subscriber to retrieve sensitive information such as the user email and hashed password of other users

CVE-2023-37596
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2023 2 PoCs

Cross Site Request Forgery (CSRF) vulnerability in issabel-pbx v.4.0.0-6 allows a remote attacker to cause a denial of service via a crafted script to the deleteuser function.

CVE-2023-38888
Software Genérico Web Database
N/A
UNKNOWN
EPSS
5.0%
2023 1 PoC

Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.

CVE-2023-0210
Linux Kernel Windows
N/A
UNKNOWN
EPSS
0.6%
2023 CWE-122 3 PoCs

A bug affects the Linux kernel’s ksmbd NTLMv2 authentication and is known to crash the OS immediately in Linux-based systems.

CVE-2023-44769
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2023 2 PoCs

A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted script to the Spare aliases from Alias.

CVE-2023-38971
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the rack number parameter in the add new rack function.

CVE-2023-32407
macOS General
N/A
UNKNOWN
EPSS
2.5%
2023 1 PoC

A logic issue was addressed with improved state management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to bypass Privacy preferences.

CVE-2023-45277
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2023 2 PoCs

Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the buckets, freely navigate system directories, and read arbitrary files.

CVE-2023-31069
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2023 2 PoCs

An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML source code of the login page.