7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-38926
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Netgear EX6200 v1.0.3.94 was discovered to contain a buffer overflow via the wla_temp_ssid parameter at acosNvramConfig_set.

CVE-2023-2028
Call Now Accessibility Button Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Call Now Accessibility Button WordPress plugin before 1.1 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-25281
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

A stack overflow vulnerability exists in pingV4Msg component in D-Link DIR820LA1_FW105B03, allows attackers to cause a denial of service via the nextPage parameter to ping.ccp.

CVE-2023-0145
Saan World Clock Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Saan World Clock WordPress plugin through 1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-36136
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

PHPJabbers Class Scheduling System 1.0 lacks encryption on the password when editing a user account (update user page) allowing an attacker to capture all user names and passwords in clear text.

CVE-2023-5809
Popup box Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-36135
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

User enumeration is found in in PHPJabbers Class Scheduling System v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-0925
webMethods OneData General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Version 10.11 of webMethods OneData runs an embedded instance of Azul Zulu Java 11.0.15 which hosts a Java RMI registry (listening on TCP port 2099 by default) and two RMI interfaces (listening on a single, dynamically assigned TCP high port). Port 2099 serves as a Java Remote Method Invocation (RMI) registry which allows for remotely loading and processing data via RMI interfaces. An unauthenticated attacker with network connectivity to the RMI registry and RMI interface ports can abuse this functionality to instruct the webMethods OneData application to load a malicious serialized Java ob

CVE-2023-36165
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Sin descripción disponible.

CVE-2023-21238
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

In visitUris of RemoteViews.java, there is a possible leak of images between users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-43353
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the extra parameter in the news menu component.

CVE-2023-37645
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
47.8%
2023 0 PoCs

eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.

CVE-2023-31714
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.3%
2023 2 PoCs

Chitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities.

CVE-2023-37455
Firefox for iOS General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The permission request prompt from the site in the background tab was overlaid on top of the site in the foreground tab. This vulnerability affects Firefox for iOS < 115.

CVE-2023-46389
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Incorrect Access Control via registry.xml file. This vulnerability allows remote attackers to disclose sensitive information on LINX configuration.

CVE-2023-20793
MT6853, MT6853T, MT6873, MT6875, MT6877, MT6883, MT6885, MT6889, MT6891, MT6893, MT8183, MT8188, MT8195 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In apu, there is a possible memory corruption due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767818; Issue ID: ALPS07767818.

CVE-2023-0890
WordPress Shortcodes Plugin — Shortcodes Ultimate Web Windows
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not ensure that posts to be displayed via some shortcodes are already public and can be accessed by the user making the request, allowing any authenticated users such as subscriber to view draft, private or even password protected posts. It is also possible to leak the password of protected posts

CVE-2023-44847
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ Weixin.php component.

CVE-2023-43469
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.4%
2023 1 PoC

SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the ForPass.php component.

CVE-2023-3130
Short URL Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Short URL WordPress plugin before 1.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).