7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-40766
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

User enumeration is found in in PHPJabbers Ticket Support Script v3.2. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-27641
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.7%
2023 0 PoCs

The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XSS attacks via a crafted URL.

CVE-2023-39643
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Bl Modules xmlfeeds before v3.9.8 was discovered to contain a SQL injection vulnerability via the component SearchApiXml::Xmlfeeds().

CVE-2023-40359
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e., neither alphanumeric nor underscore), aka a pointer/overflow issue. This can only occur for xterm installations that are configured at compile time to use a certain experimental feature.

CVE-2023-36347
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
84.5%
2023 2 PoCs

A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data.

CVE-2023-41080
Apache Tomcat Web
N/A
UNKNOWN
EPSS
11.6%
2023 CWE-601 1 PoC

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. Older, EOL versions may also be affected. The vulnerability is limited to the ROOT (default) web application.

CVE-2023-3732
Chrome General
N/A
UNKNOWN
EPSS
0.9%
2023 1 PoC

Out of bounds memory access in Mojo in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-29975
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.

CVE-2023-37689
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Booking Request page.

CVE-2023-39584
Software Genérico General
N/A
UNKNOWN
EPSS
4.1%
2023 1 PoC

Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability.

CVE-2023-36158
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 4 PoCs

Cross Site Scripting (XSS) vulnerability in sourcecodester Toll Tax Management System 1.0 allows remote attackers to run arbitrary code via the First Name and Last Name fields on the My Account page.

CVE-2023-47445
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Pre-School Enrollment version 1.0 is vulnerable to SQL Injection via the username parameter in preschool/admin/ page.

CVE-2023-40757
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

User enumeration is found in PHPJabbers Food Delivery Script v3.1. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-2156
Linux kernel (RPL protocol) General
N/A
UNKNOWN
EPSS
2.1%
2023 CWE-617 1 PoC

A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the system.

CVE-2023-35687
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In MtpPropertyValue of MtpProperty.h, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-29537
Firefox for Android General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

CVE-2023-45285
cmd/go Web Networking
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Using go get to fetch a module with the ".git" suffix may unexpectedly fallback to the insecure "git://" protocol if the module is unavailable via the secure "https://" and "git+ssh://" protocols, even if GOINSECURE is not set for said module. This only affects users who are not using the module proxy and are fetching modules directly (i.e. GOPROXY=off).

CVE-2023-2330
Caldera Forms Google Sheets Connector Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Caldera Forms Google Sheets Connector WordPress plugin before 1.3 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

CVE-2023-33563
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 2 PoCs

In PHP Jabbers Time Slots Booking Calendar 3.3 , lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.

CVE-2023-38334
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 4 PoCs

Omnis Studio 10.22.00 has incorrect access control. It advertises an irreversible feature for locking classes within Omnis libraries: it should be no longer possible to delete, view, change, copy, rename, duplicate, or print a locked class. Due to implementation issues, locked classes in Omnis libraries can be unlocked, and thus further analyzed and modified by Omnis Studio. This allows for further analyzing and also deleting, viewing, changing, copying, renaming, duplicating, or printing previously locked Omnis classes. This violates the expected behavior of an "irreversible operation."