7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-43149
Software Genérico Web
N/A
UNKNOWN
EPSS
1.1%
2023 1 PoC

SPA-Cart 1.9.0.3 is vulnerable to Cross Site Request Forgery (CSRF) that allows a remote attacker to add an admin user with role status.

CVE-2023-39776
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2023-33580
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2023 2 PoCs

Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" field on Admin Profile page.

CVE-2023-2309
wpForo Forum Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
15.2%
2023 1 PoC

The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability.

CVE-2023-47324
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Silverpeas Core 6.3.1 is vulnerable to Cross Site Scripting (XSS) via the message/notification feature.

CVE-2023-5765
Remote Desktop Manager Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to bypass permissions via data source switching.

CVE-2023-36631
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0 allows local unprivileged users to bypass Windows Firewall restrictions via the user interface's rules tab. NOTE: the vendor's perspective is "this is intended behavior as the application can be locked using a password."

CVE-2023-48124
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2023 2 PoCs

Cross Site Scripting in SUP Online Shopping v.1.0 allows a remote attacker to execute arbitrary code via the Name, Email and Address parameters in the Register New Account component.

CVE-2023-43457
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2023 2 PoCs

An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin/?page=user/ endpoint.

CVE-2023-46497
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information via a crafted request to the mkdirSync function in the folderCreate/createFolder.js endpoint.

CVE-2023-37679
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.4%
2023 2 PoCs

A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.

CVE-2023-20592
1st Gen AMD EPYC™ Processors General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.

CVE-2023-29737
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause a denial of service via the database files.

CVE-2023-2398
Icegram Engage Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-52489
Linux General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In the Linux kernel, the following vulnerability has been resolved: mm/sparsemem: fix race in accessing memory_section->usage The below race is observed on a PFN which falls into the device memory region with the system memory configuration where PFN's are such that [ZONE_NORMAL ZONE_DEVICE ZONE_NORMAL]. Since normal zone start and end pfn contains the device memory PFN's as well, the compaction triggered will try on the device memory PFN's too though they end up in NOP(because pfn_to_online_page() returns NULL for ZONE_DEVICE memory sections). When from other core, the section mappings ar

CVE-2023-33281
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

The remote keyfob system on Nissan Sylphy Classic 2021 sends the same RF signal for each door-open request, which allows for a replay attack. NOTE: the vendor's position is that this cannot be reproduced with genuine Nissan parts: for example, the combination of keyfob and door handle shown in the exploit demonstration does not match any technology that Nissan provides to customers.

CVE-2023-34635
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or sanitizing the user input in the username field of the login page.

CVE-2023-36376
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Cross-Site Scripting (XSS) vulnerability in Hostel Management System v.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the add course section.

CVE-2023-39709
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 3 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Member section.

CVE-2023-37602
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

An arbitrary file upload vulnerability in the component /workplace#!explorer of Alkacon OpenCMS v15.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.