7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-36146
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

A Stored Cross-Site Scripting (XSS) vulnerability was found in Multilaser RE 170 using firmware 2.2.6733.

CVE-2023-48837
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Car Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.

CVE-2023-40037
Apache NiFi Web
N/A
UNKNOWN
EPSS
1.3%
2023 CWE-184 1 PoC

Apache NiFi 1.21.0 through 1.23.0 support JDBC and JNDI JMS access in several Processors and Controller Services with connection URL validation that does not provide sufficient protection against crafted inputs. An authenticated and authorized user can bypass connection URL validation using custom input formatting. The resolution enhances connection URL validation and introduces validation for additional related properties. Upgrading to Apache NiFi 1.23.1 is the recommended mitigation.

CVE-2023-51208
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

Sin descripción disponible.

CVE-2023-37202
Firefox General
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.

CVE-2023-44813
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
20.8%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in mooSocial v.3.1.8 allows a remote attacker to execute arbitrary code via a crafted payload to the mode parameter of the invite friend login function.

CVE-2023-29733
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

The Lock Master app 2.2.4 for Android allows unauthorized apps to modify the values in its SharedPreference files. These files hold data that affects many app functions. Malicious modifications by unauthorized apps can cause security issues, such as functionality manipulation, resulting in a severe escalation of privilege attack.

CVE-2023-30222
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password hashes for all users via eavesdropping.

CVE-2023-32209
Firefox General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A maliciously crafted favicon could have led to an out of memory crash. This vulnerability affects Firefox < 113.

CVE-2023-39711
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 3 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Subtotal and Paidbill parameters under the Add New Put section.

CVE-2023-45280
Software Genérico Web
N/A
UNKNOWN
EPSS
2.0%
2023 4 PoCs

Yamcs 5.8.6 allows XSS (issue 2 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to upload an HTML file containing arbitrary JavaScript and then navigate to it. Once the user opens the file, the browser will execute the arbitrary JavaScript.

CVE-2023-4252
EventPrime Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attacker to purchase bookings without payment.

CVE-2023-34724
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

An issue was discovered in TECHView LA5570 Wireless Gateway 1.0.19_T53, allows physical attackers to gain escalated privileges via the UART interface.

CVE-2023-1380
Kernel General
N/A
UNKNOWN
EPSS
0.0%
2023 CWE-125 2 PoCs

A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service.

CVE-2023-37151
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Sin descripción disponible.

CVE-2023-26759
Software Genérico General
N/A
UNKNOWN
EPSS
11.9%
2023 1 PoC

Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an OS command injection vulnerability via calls made to the XMService component.

CVE-2023-2178
Aajoda Testimonials Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.1%
2023 1 PoC

The Aajoda Testimonials WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-5749
EmbedPress Web Windows
N/A
UNKNOWN
EPSS
1.5%
2023 1 PoC

The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-7047
Remote Desktop Manager Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Inadequate validation of permissions when employing remote tools and macros via the context menu within Devolutions Remote Desktop Manager versions 2023.3.31 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature. This affects only SQL data sources.

CVE-2023-5141
BSK Contact Form 7 Blacklist Web Windows
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The BSK Contact Form 7 Blacklist WordPress plugin through 1.0.1 does not sanitise and escape the inserted_count parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin