7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-39110
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
80.1%
2023 0 PoCs

rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPath.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.

CVE-2023-24729
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2023 2 PoCs

Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the address parameter in the user profile update function.

CVE-2023-26760
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an information disclosure vulnerability via the /debug endpoint. This vulnerability allows attackers to access cleartext credentials needed to authenticate to the AS400 system.

CVE-2023-20567
Radeon™ RX 5000/6000/7000 Series Graphics Cards Windows
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareInstaller.exe without validating the file signature potentially leading to arbitrary code execution.

CVE-2023-40293
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Harman Infotainment 20190525031613 and later allows command injection via unauthenticated RPC with a D-Bus connection object.

CVE-2023-37205
Firefox General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The use of RTL Arabic characters in the address bar may have allowed for URL spoofing. This vulnerability affects Firefox < 115.

CVE-2023-44846
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 2 PoCs

An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ notify.php component.

CVE-2023-48925
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

SQL injection vulnerability in Buy Addons bavideotab before version 1.0.6, allows attackers to escalate privileges and obtain sensitive information via the component BaVideoTabSaveVideoModuleFrontController::run().

CVE-2023-2482
Responsive CSS EDITOR Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Responsive CSS EDITOR WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admin.

CVE-2023-40791
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

extract_user_to_sg in lib/scatterlist.c in the Linux kernel before 6.4.12 fails to unpin pages in a certain situation, as demonstrated by a WARNING for try_grab_page.

CVE-2023-45311
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.9%
2023 2 PoCs

fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adversary to execute arbitrary code if any JavaScript project (that depends on fsevents) distributes code that was obtained from that URL at a time when it was controlled by an adversary. NOTE: some sources feel that this means that no version is affected any longer, because the URL is not controlled by an adversary.

CVE-2023-46324
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key that has not been validated. An attacker can send arbitrary SUCIs to the UDM, which tries to decrypt them via both its private key and the attacker's public key.

CVE-2023-5458
CITS Support svg, webp Media and TTF,OTF File Upload Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The CITS Support svg, webp Media and TTF,OTF File Upload WordPress plugin before 3.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2023-51028
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

TOTOLINK EX1800T 9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the apcliChannel parameter of the setWiFiExtenderConfig interface of the cstecgi.cgi.

CVE-2023-0873
Kanban Boards for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Kanban Boards for WordPress plugin before 2.5.21 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-31923
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Suprema BioStar 2 before 2022 Q4, v2.9.1 has Insecure Permissions. A vulnerability in the web application allows an authenticated attacker with "User Operator" privileges to create a highly privileged user account. The vulnerability is caused by missing server-side validation, which can be exploited to gain full administrator privileges on the system.

CVE-2023-0419
Shortcode for Font Awesome Web Windows
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The Shortcode for Font Awesome WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-20810
MT5221, MT5583, MT5691, MT5695, MT9010, MT9011, MT9012, MT9016, MT9020, MT9021, MT9022, MT9030, MT9031, MT9032, MT9216, MT9218, MT9220, MT9221, MT9222, MT9255, MT9256, MT9266, MT9269, MT9286, MT9288, MT9602, MT9610, MT9611, MT9612, MT9613, MT9615, MT9617, MT9618, MT9629, MT9630, MT9631, MT9632, MT9636, MT9638, MT9639, MT9649, MT9650, MT9652, MT9653, MT9666, MT9667, MT9669, MT9671, MT9675, MT9685, MT9686, MT9688 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In IOMMU, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03692061; Issue ID: DTV03692061.

CVE-2023-38435
Apache Felix Healthcheck Webconsole Plugin Web
N/A
UNKNOWN
EPSS
1.4%
2023 CWE-79 1 PoC

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack. Upgrade to Apache Felix Healthcheck Webconsole Plugin 2.1.0 or higher.

CVE-2023-34553
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

An issue was discovered in WAFU Keyless Smart Lock v1.0 allows attackers to unlock a device via code replay attack.