7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-31445
Software Genérico General
N/A
UNKNOWN
EPSS
2.8%
2023 3 PoCs

Cassia Access controller before 2.1.1.2203171453, was discovered to have a unprivileged -information disclosure vulnerability that allows read-only users have the ability to enumerate all other users and discover e-mail addresses, phone numbers, and privileges of all other users.

CVE-2023-2123
WP Inventory Manager Web Windows
N/A
UNKNOWN
EPSS
17.4%
2023 1 PoC

The WP Inventory Manager WordPress plugin before 2.1.0.13 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

CVE-2023-37684
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Details of the Admin portal.

CVE-2023-37692
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

An arbitrary file upload vulnerability in October CMS v3.4.4 allows attackers to execute arbitrary code via a crafted file.

CVE-2023-43909
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Hospital Management System thru commit 4770d was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.

CVE-2023-26258
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
79.4%
2023 5 PoCs

Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be used to execute any task as administrator.

CVE-2023-45690
Titan MFT General
N/A
UNKNOWN
EPSS
0.3%
2023 CWE-276 1 PoC

Default file permissions on South River Technologies' Titan MFT and Titan SFTP servers on Linux allows a user that's authentication to the OS to read sensitive files on the filesystem

CVE-2023-38925
Software Genérico Web
N/A
UNKNOWN
EPSS
27.3%
2023 1 PoC

Netgear DC112A 1.0.0.64, EX6200 1.0.3.94 and R6300v2 1.0.4.8 were discovered to contain a buffer overflow via the http_passwd parameter in password.cgi.

CVE-2023-36942
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the website title field.

CVE-2023-29856
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

D-Link DIR-868L Hardware version A1, firmware version 1.12 is vulnerable to Buffer Overflow. The vulnerability is in scandir.sgi binary.

CVE-2023-44771
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows a local attacker to execute arbitrary code via a crafted script to the Page Layout.

CVE-2023-34840
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

angular-ui-notification v0.1.0, v0.2.0, and v0.3.6 was discovered to contain a cross-site scripting (XSS) vulnerability.

CVE-2023-35668
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In visitUris of Notification.java, there is a possible way to display images from another user due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-33668
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2023 1 PoC

DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared computers.

CVE-2023-0365
React Webcam Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The React Webcam WordPress plugin through 1.2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-39677
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
77.2%
2023 1 PoC

MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php.

CVE-2023-27133
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

TSplus Remote Work 16.0.0.0 has weak permissions for .exe, .js, and .html files under the %PROGRAMFILES(X86)%\TSplus-RemoteWork\Clients\www folder. This may enable privilege escalation if a different local user modifies a file. NOTE: CVE-2023-31067 and CVE-2023-31068 are only about the TSplus Remote Access product, not the TSplus Remote Work product.

CVE-2023-31067
Software Genérico General
N/A
UNKNOWN
EPSS
1.6%
2023 2 PoCs

An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\Clients\www.

CVE-2023-36315
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Callback Widget v1.0.

CVE-2023-43201
Software Genérico General
N/A
UNKNOWN
EPSS
2.0%
2023 1 PoC

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the hi_up parameter in the qos_ext.asp function.