7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-0068
Product GTIN (EAN, UPC, ISBN) for WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Product GTIN (EAN, UPC, ISBN) for WooCommerce WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-43838
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar.

CVE-2023-31294
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the Delivery Name field.

CVE-2023-41621
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.2%
2023 0 PoCs

A Cross Site Scripting (XSS) vulnerability was discovered in Emlog Pro v2.1.14 via the component /admin/store.php.

CVE-2023-37210
Firefox General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A website could prevent a user from exiting full-screen mode via alert and prompt calls. This could lead to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115.

CVE-2023-38883
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'ajax' parameter in 'ParentLookup.php'.

CVE-2023-43959
Software Genérico General
N/A
UNKNOWN
EPSS
8.0%
2023 3 PoCs

An issue in YeaLinkSIP-T19P-E2 v.53.84.0.15 allows a remote privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.

CVE-2023-31302
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Teller field.

CVE-2023-2796
EventON Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
71.5%
2023 2 PoCs

The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id.

CVE-2023-39006
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Crash Reporter (crash_reporter.php) component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 mishandles input sanitization.

CVE-2023-37629
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.1%
2023 3 PoCs

Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to "add-pig.php."

CVE-2023-27890
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The Export User plugin through 2.0 for MyBB allows XSS during the process of an admin generating DSGVO data for a user, via the Custom User Title, Location, or Bio field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-20800
MT6879, MT6895, MT6983, MT8188, MT8195, MT8395, MT8781 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In imgsys, there is a possible system crash due to a mssing ptr check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07420968; Issue ID: ALPS07420955.

CVE-2023-50089
Software Genérico Web
N/A
UNKNOWN
EPSS
3.1%
2023 1 PoC

A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication.

CVE-2023-5750
EmbedPress Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape a parameter before outputting it back in the page containing a specific content, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-30146
Software Genérico General
N/A
UNKNOWN
EPSS
1.9%
2023 1 PoC

Assmann Digitus Plug&View IP Camera HT-IP211HDP, version 2.000.022 allows unauthenticated attackers to download a copy of the camera's settings and the administrator credentials.

CVE-2023-40295
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2023 1 PoC

libboron in Boron 2.0.8 has a heap-based buffer overflow in ur_strInitUtf8 at string.c.

CVE-2023-46455
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
40.1%
2023 0 PoCs

In GL.iNET GL-AR300M routers with firmware v4.3.7 it is possible to write arbitrary files through a path traversal attack in the OpenVPN client file upload functionality.

CVE-2023-43872
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

A File upload vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).

CVE-2023-45278
Software Genérico Web
N/A
UNKNOWN
EPSS
3.2%
2023 1 PoC

Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafted HTTP DELETE request.