7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-29485
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to bypass network filtering, execute arbitrary code, and obtain sensitive information via DarkLayer Guard threat prevention module. NOTE: Heimdal disputes the validity of this issue arguing that their DNS Security for Endpoint filters DNS traffic on the endpoint by intercepting system-generated DNS requests. The product was not designed to intercept DNS requests from third-party solutions.

CVE-2023-41640
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An improper error handling vulnerability in the component ErroreNonGestito.aspx of GruppoSCAI RealGimm 1.1.37p38 allows attackers to obtain sensitive technical information via a crafted SQL query.

CVE-2023-0212
Advanced Recent Posts Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The Advanced Recent Posts WordPress plugin through 0.6.14 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-43144
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.8%
2023 1 PoC

Projectworldsl Assets-management-system-in-php 1.0 is vulnerable to SQL Injection via the "id" parameter in delete.php.

CVE-2023-45868
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Learning Module in ILIAS 7.25 (2023-09-12 release) allows an attacker (with basic user privileges) to achieve a high-impact Directory Traversal attack on confidentiality and availability. By exploiting this network-based vulnerability, the attacker can move specified directories, normally outside the documentRoot, to a publicly accessible location via the PHP function rename(). This results in a total loss of confidentiality, exposing sensitive resources, and potentially denying access to the affected component and the operating system's components. To exploit this, an attacker must manipu

CVE-2023-28875
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A Stored XSS issue in shared files download terms in Filerun Update 20220202 allows attackers to inject JavaScript code that is executed when a user follows the crafted share link.

CVE-2023-38316
Software Genérico Web
N/A
UNKNOWN
EPSS
1.2%
2023 1 PoC

An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrary OS commands by inserting them into the URL portion of HTTP GET requests. Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.

CVE-2023-1982
Guest posting / Frontend Posting wordpress plugin Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Front Editor WordPress plugin through 4.0.4 does not sanitize and escape some of its form settings, which could allow high-privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-39008
Software Genérico Web
N/A
UNKNOWN
EPSS
5.1%
2023 1 PoC

A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands.

CVE-2023-21275
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In decideCancelProvisioningDialog of AdminIntegratedFlowPrepareActivity.java, there is a possible way to bypass factory reset protections due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-40133
Android General
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

In multiple locations of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-23126
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.

CVE-2023-2248
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Sin descripción disponible.

CVE-2023-36076
Software Genérico Web Database
N/A
UNKNOWN
EPSS
43.9%
2023 1 PoC

SQL Injection vulnerability in smanga version 3.1.9 and earlier, allows remote attackers to execute arbitrary code and gain sensitive information via mediaId, mangaId, and userId parameters in php/history/add.php.

CVE-2023-30347
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

Cross Site Scripting (XSS) vulnerability in Neox Contact Center 2.3.9, via the serach_sms_api_name parameter to the SMA API search.

CVE-2023-43359
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Page Specific Metadata and Smarty data parameters in the Content Manager Menu component.

CVE-2023-40756
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

User enumeration is found in PHPJabbers Callback Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

CVE-2023-44770
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows an attacker to execute arbitrary code via a crafted script to the Organizer - Spare alias.

CVE-2023-6264
Server General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Information leak in Content-Security-Policy header in Devolutions Server 2023.3.7.0 allows an unauthenticated attacker to list the configured Devolutions Gateways endpoints.

CVE-2023-6166
Quiz Maker Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Quiz Maker WordPress plugin before 6.4.9.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting