7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-5949
SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The SmartCrawl WordPress plugin before 3.8.3 does not prevent unauthorised users from accessing password-protected posts' content.

CVE-2023-29734
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

An issue found in edjing Mix v.7.09.01 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the database.

CVE-2023-36941
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the team name, leader, and member fields.

CVE-2023-20596
Ryzen™ 5000 Series Desktop Processor with Radeon™ Graphics Formerly codenamed “Cezanne” AM4 General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 access potentially leading to arbitrary code execution.

CVE-2023-22955
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 4 PoCs

An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. The validation of firmware images only consists of simple checksum checks for different firmware components. Thus, by knowing how to calculate and where to store the required checksums for the flasher tool, an attacker is able to store malicious firmware.

CVE-2023-36345
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2023 2 PoCs

A Cross-Site Request Forgery (CSRF) in POS Codekop v2.0 allows attackers to escalate privileges.

CVE-2023-2320
CF7 Google Sheets Connector Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The CF7 Google Sheets Connector WordPress plugin before 5.0.2, cf7-google-sheets-connector-pro WordPress plugin through 5.0.2 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-3133
Tutor LMS Web Windows
N/A
UNKNOWN
EPSS
1.5%
2023 1 PoC

The Tutor LMS WordPress plugin before 2.2.1 does not implement adequate permission checks for REST API endpoints, allowing unauthenticated attackers to access information from Lessons that should not be publicly available.

CVE-2023-48812
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution vulnerability.

CVE-2023-0865
WooCommerce Multiple Customer Addresses & Shipping Web Windows
N/A
UNKNOWN
EPSS
8.5%
2023 1 PoC

The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to add/update/retrieve/delete and duplicate belong to the user making the request, or is from a high privilege users, allowing any authenticated users, such as subscriber to add/update/duplicate/delete as well as retrieve addresses of other users.

CVE-2023-29459
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The laola.redbull application through 5.1.9-R for Android exposes the exported activity at.redbullsalzburg.android.AppMode.Default.Splash.SplashActivity, which accepts a data: URI. The target of this URI is subsequently loaded into the application's webview, thus allowing the loading of arbitrary content into the context of the application. This can occur via the fcrbs schema or an explicit intent invocation.

CVE-2023-24212
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the timeType function at /goform/SetSysTimeCfg.

CVE-2023-46014
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

SQL Injection vulnerability in hospitalLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'hemail' and 'hpassword' parameters.

CVE-2023-24731
Software Genérico Database
N/A
UNKNOWN
EPSS
0.9%
2023 2 PoCs

Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the query parameter in the user profile update function.

CVE-2023-39137
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.

CVE-2023-39600
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.7%
2023 2 PoCs

IceWarp 11.4.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the color parameter.

CVE-2023-43320
Software Genérico General
N/A
UNKNOWN
EPSS
3.2%
2023 1 PoC

An issue in Proxmox Server Solutions GmbH Proxmox VE v.5.4 thru v.8.0, Proxmox Backup Server v.1.1 thru v.3.0, and Proxmox Mail Gateway v.7.1 thru v.8.0 allows a remote authenticated attacker to escalate privileges via bypassing the two-factor authentication component.

CVE-2023-43944
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability was found in SourceCodester Task Management System 1.0. It allows attackers to execute arbitrary code via parameter field in index.php?page=project_list.

CVE-2023-48805
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

CVE-2023-6077
Slider Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Slider WordPress plugin before 3.5.12 does not ensure that posts to be accessed via an AJAX action are slides and can be viewed by the user making the request, allowing any authenticated users, such as subscriber to access the content arbitrary post such as private, draft and password protected