7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-0063
WordPress Shortcodes Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The WordPress Shortcodes WordPress plugin through 1.6.36 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-48084
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
82.1%
2023 2 PoCs

Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.

CVE-2023-21400
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-2877
Formidable Forms Web Windows
N/A
UNKNOWN
EPSS
70.0%
2023 2 PoCs

The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository onto the site, leading to Remote Code Execution.

CVE-2023-46025
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL Injection vulnerability in teacher-info.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to obtain sensitive information via the 'editid' parameter.

CVE-2023-0099
Simple URLs Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
70.1%
2023 3 PoCs

The Simple URLs WordPress plugin before 115 does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2023-31698
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trusted by the administrator to insert arbitrary content (users cannot create their own accounts through self-registration).

CVE-2023-39321
crypto/tls General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Processing an incomplete post-handshake message for a QUIC connection can cause a panic.

CVE-2023-20519
3rd Gen AMD EPYC™ Processors General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's migration agent resulting in a potential loss of guest integrity.

CVE-2023-28871
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry information of the operating system by creating a symbolic link.

CVE-2023-36314
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

There is a Cross Site Scripting (XSS) vulnerability in the value-text-o_sms_email_request_message parameters of index.php in PHPJabbers Callback Widget v1.0.

CVE-2023-46451
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Best Courier Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the change username field.

CVE-2023-29491
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.

CVE-2023-39637
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2023 1 PoC

D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis.

CVE-2023-29689
Software Genérico Web
N/A
UNKNOWN
EPSS
51.3%
2023 1 PoC

PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.

CVE-2023-48121
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

An authentication bypass vulnerability in the Direct Connection Module in Ezviz CS-C6N-xxx prior to v5.3.x build 20230401, Ezviz CS-CV310-xxx prior to v5.3.x build 20230401, Ezviz CS-C6CN-xxx prior to v5.3.x build 20230401, Ezviz CS-C3N-xxx prior to v5.3.x build 20230401 allows remote attackers to obtain sensitive information by sending crafted messages to the affected devices.

CVE-2023-41444
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

An issue in Binalyze IREC.sys v.3.11.0 and before allows a local attacker to execute arbitrary code and escalate privileges via the fun_1400084d0 function in IREC.sys driver.

CVE-2023-21272
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 3 PoCs

In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-35826
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in cedrus_remove in drivers/staging/media/sunxi/cedrus/cedrus.c.

CVE-2023-4047
Firefox General
N/A
UNKNOWN
EPSS
0.6%
2023 2 PoCs

A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.