7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-27212
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A cross-site scripting (XSS) vulnerability in /php-opos/signup.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the redirect parameter.

CVE-2023-38840
Software Genérico General
N/A
UNKNOWN
EPSS
2.4%
2023 1 PoC

Bitwarden Desktop 2023.7.0 and below allows an attacker with local access to obtain sensitive information via the Bitwarden.exe process.

CVE-2023-1110
Yellow Yard Searchbar Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Yellow Yard Searchbar WordPress plugin before 2.8.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-2709
AN_GradeBook Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The AN_GradeBook WordPress plugin through 5.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-26613
Software Genérico General
N/A
UNKNOWN
EPSS
63.5%
2023 1 PoC

An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorized attackers to execute arbitrary operating system commands via a crafted GET request to EXCU_SHELL.

CVE-2023-51199
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

Sin descripción disponible.

CVE-2023-34931
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A stack overflow in the EditWlanMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2023-38354
Software Genérico General
N/A
UNKNOWN
EPSS
6.0%
2023 1 PoC

MiniTool Shadow Maker version 4.1 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

CVE-2023-51202
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

Sin descripción disponible.

CVE-2023-49438
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2023 1 PoC

An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspecting users to malicious sites via a crafted URL by abusing the ?next parameter on the /login and /register routes.

CVE-2023-2701
gravityforms Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin.

CVE-2023-40039
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame.

CVE-2023-24609
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Matrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension parsing in the TLS 1.3 server. An attacked device calculates an SHA-2 hash over at least 65 KB (in RAM). With a large number of crafted TLS messages, the CPU becomes heavily loaded. This occurs in tls13VerifyBinder and tls13TranscriptHashUpdate.

CVE-2023-28485
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

A stored cross-site scripting (Stored XSS) vulnerability in file preview in WeKan before 6.75 allows remote authenticated users to inject arbitrary web script or HTML via names of file attachments. Any user can obtain the privilege to rename within their own board (where they have BoardAdmin access), and renameAttachment does not block XSS payloads.

CVE-2023-5674
WP Mail Log Web Database Windows
N/A
UNKNOWN
EPSS
11.0%
2023 1 PoC

The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Contributor.

CVE-2023-36664
Software Genérico General
N/A
UNKNOWN
EPSS
6.4%
2023 4 PoCs

Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).

CVE-2023-41364
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

In tine through 2023.01.14.325, the sort parameter of the /index.php endpoint allows SQL Injection.

CVE-2023-24733
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
14.9%
2023 0 PoCs

PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /admin/convert/export_z3950_new.php.

CVE-2023-34839
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2023 2 PoCs

A Cross Site Request Forgery (CSRF) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows a remote attacker to gain privileges via a Custom CSRF exploit to create new user function in the application.

CVE-2023-37685
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Page of the Admin portal.