7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-51012
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanGateway parameter’ of the setLanConfig interface of the cstecgi .cgi.

CVE-2023-33565
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

Sin descripción disponible.

CVE-2023-0179
kernel General
N/A
UNKNOWN
EPSS
0.6%
2023 CWE-190 4 PoCs

A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execution.

CVE-2023-35811
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. Two SQL Injection vectors have been identified in the REST API. By using crafted requests, custom SQL code can be injected through the REST API because of missing input validation. Regular user privileges can use used for exploitation. Editions other than Enterprise are also affected.

CVE-2023-6210
Firefox Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

When an https: web page created a pop-up from a "javascript:" URL, that pop-up was incorrectly allowed to load blockable content such as iframes from insecure http: URLs This vulnerability affects Firefox < 120.

CVE-2023-23303
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying various attributes. A malicious application could call the API method with specially crafted object and hijack the execution of the device's firmware.

CVE-2023-37734
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 3 PoCs

EZ softmagic MP3 Audio Converter 2.7.3.700 was discovered to contain a buffer overflow.

CVE-2023-42362
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

An arbitrary file upload vulnerability in Teller Web App v.4.4.0 allows a remote attacker to execute arbitrary commands and obtain sensitive information via uploading a crafted file.

CVE-2023-2711
Ultimate Product Catalog Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Ultimate Product Catalog WordPress plugin before 5.2.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-20780
MT6580, MT6731, MT6735, MT6737, MT6739, MT6753, MT6757, MT6757C, MT6757CD, MT6757CH, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6891, MT6893, MT6895, MT6983, MT6985, MT8185, MT8321, MT8385, MT8666, MT8673, MT8675, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8797 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In keyinstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017756; Issue ID: ALPS08017756.

CVE-2023-45542
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
43.3%
2023 1 PoC

Cross Site Scripting vulnerability in mooSocial 3.1.8 allows a remote attacker to obtain sensitive information via a crafted script to the q parameter in the Search function.

CVE-2023-0377
Scriptless Social Sharing Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Scriptless Social Sharing WordPress plugin before 3.2.2 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-45471
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

The QAD Search Server is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to, and including, 1.0.0.315 due to insufficient checks on indexes. This makes it possible for unauthenticated attackers to create a new index and inject a malicious web script into its name, that will execute whenever a user accesses the search page.

CVE-2023-36968
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A SQL Injection vulnerability detected in Food Ordering System v1.0 allows attackers to run commands on the database by sending crafted SQL queries to the ID parameter.

CVE-2023-47464
Software Genérico Web
N/A
UNKNOWN
EPSS
70.1%
2023 1 PoC

Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via the upload API function.

CVE-2023-27083
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev5 allows remote attackers to run arbitrary code via manage file functionality.

CVE-2023-43355
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the password and password again parameters in the My Preferences - Add user component.

CVE-2023-34853
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Buffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of SmcSecurityEraseSetupVar variable.

CVE-2023-2029
PrePost SEO Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

The PrePost SEO WordPress plugin through 3.0 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-45688
Titan MFT General
N/A
UNKNOWN
EPSS
0.3%
2023 CWE-22 1 PoC

Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Linux allows an authenticated attacker to get the size of an arbitrary file on the filesystem using path traversal in the ftp "SIZE" command