7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-5874
Popup box Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-37543
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2023 2 PoCs

Cacti before 1.2.6 allows IDOR (Insecure Direct Object Reference) for accessing any graph via a modified local_graph_id parameter to graph_xport.php. This is a different vulnerability than CVE-2019-16723.

CVE-2023-40868
Software Genérico General
N/A
UNKNOWN
EPSS
3.8%
2023 1 PoC

Cross Site Request Forgery vulnerability in mooSocial MooSocial Software v.Demo allows a remote attacker to execute arbitrary code via the Delete Account and Deactivate functions.

CVE-2023-2624
KiviCare Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
9.3%
2023 2 PoCs

The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrator

CVE-2023-0439
NEX-Forms Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The NEX-Forms WordPress plugin before 8.4.4 does not escape its form name, which could lead to Stored Cross-Site Scripting issues. By default only SuperAdmins (in multisite) / admins (in single site) can create forms, however there is a settings allowing them to give lower roles access to such feature.

CVE-2023-27922
Newsletter Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.8%
2023 0 PoCs

Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script.

CVE-2023-50164
Apache Struts Web
N/A
UNKNOWN
EPSS
92.9%
2023 CWE-552 17 PoCs

An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue.

CVE-2023-20801
MT6879, MT6895, MT6983, MT8188, MT8195, MT8395, MT8781 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In imgsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07420968; Issue ID: ALPS07420968.

CVE-2023-51033
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi setOpModeCfg interface.

CVE-2023-40139
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-51021
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘merge’ parameter of the setRptWizardCfg interface of the cstecgi .cgi.

CVE-2023-25743
Firefox General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.<br>*This bug only affects Firefox Focus. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.

CVE-2023-4862
File Manager Pro Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The File Manager Pro WordPress plugin before 1.8.1 does not adequately validate and escape some inputs, leading to XSS by high-privilege users.

CVE-2023-32413
macOS General
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

A race condition was addressed with improved state handling. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to gain root privileges.

CVE-2023-38190
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Export SQL Injection via the size parameter.

CVE-2023-43326
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
34.6%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability exisits in multiple url of mooSocial v3.1.8 allows attackers to steal user's session cookies and impersonate their account via a crafted URL.

CVE-2023-31298
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the User ID field when creating a new system user.

CVE-2023-5940
WP Not Login Hide (WPNLH) Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WP Not Login Hide (WPNLH) WordPress plugin through 1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-36546
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Sin descripción disponible.

CVE-2023-20555
Ryzen™ 3000 Series Desktop Processors “Matisse” AM4 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM.