7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-36936
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

Cross-Site Scripting (XSS) vulnerability in PHPGurukul Online Security Guards Hiring System using PHP and MySQL 1.0 allows attackers to execute arbitrary code via a crafted payload to the search booking box.

CVE-2023-20588
EPYC™ 7001 Processors General
N/A
UNKNOWN
EPSS
6.7%
2023 1 PoC

A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. 

CVE-2023-42470
Software Genérico Web
N/A
UNKNOWN
EPSS
10.6%
2023 1 PoC

The Imou Life com.mm.android.smartlifeiot application through 6.8.0 for Android allows Remote Code Execution via a crafted intent to an exported component. This relates to the com.mm.android.easy4ip.MainActivity activity. JavaScript execution is enabled in the WebView, and direct web content loading occurs.

CVE-2023-41108
Software Genérico General
N/A
UNKNOWN
EPSS
2.2%
2023 2 PoCs

TEF portal 2023-07-17 is vulnerable to authenticated remote code execution.

CVE-2023-6250
BestWebSoft's Like & Share Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthenticated users via a meta tag

CVE-2023-27204
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.

CVE-2023-45857
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 3 PoCs

An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.

CVE-2023-23163
Software Genérico Database
N/A
UNKNOWN
EPSS
4.4%
2023 1 PoC

Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter.

CVE-2023-39144
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Element55 KnowMore appliances version 21 and older was discovered to store passwords in plaintext.

CVE-2023-26612
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the HostName field in SetParentsControlInfo.

CVE-2023-36166
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Sin descripción disponible.

CVE-2023-33567
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

Sin descripción disponible.

CVE-2023-43319
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

Cross Site Scripting (XSS) vulnerability in the Sign-In page of IceWarp WebClient 10.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter.

CVE-2023-31465
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
90.5%
2023 1 PoC

An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper streams, it is possible to find the getsamplebacklog call. Some query parameters are passed directly in the URL and named arg[x], with x an integer starting from 1; it is possible to modify arg[2] to insert Bash code that will be executed directly by the server.

CVE-2023-20806
MT2713, MT6879, MT6895, MT6983, MT8188, MT8195, MT8395, MT8673 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In hcp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07537437.

CVE-2023-27206
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A cross-site scripting (XSS) vulnerability in /kruxton/navbar.php of Best POS Management System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page parameter.

CVE-2023-45253
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue was discovered in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, allows attackers to manipulate files and escalate privileges via RollingFileAppender.DeleteFile method performed by the log4net library.

CVE-2023-20786
MT2713, MT6580, MT6739, MT6761, MT6765, MT6768, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6855, MT6873, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6893, MT6895, MT6983, MT6985, MT8167, MT8167S, MT8168, MT8175, MT8188, MT8195, MT8362A, MT8365, MT8673 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767811; Issue ID: ALPS07767811.

CVE-2023-3129
URL Shortify Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The URL Shortify WordPress plugin before 1.7.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-38922
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Netgear JWNR2000v2 v1.0.0.11, XWN5001 v0.4.1.1, and XAVN2001v2 v0.4.0.7 were discovered to contain multiple buffer overflows via the http_passwd and http_username parameters in the update_auth function.