7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-46998
Software Genérico General
N/A
UNKNOWN
EPSS
38.9%
2023 2 PoCs

Cross Site Scripting vulnerability in BootBox Bootbox.js v.3.2 through 6.0 allows a remote attacker to execute arbitrary code via a crafted payload to alert(), confirm(), prompt() functions.

CVE-2023-48866
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 2 PoCs

A Cross-Site Scripting (XSS) vulnerability in the recipe preparation component within /api/objects/recipes and note component within /api/objects/shopping_lists/ of Grocy <= 4.0.3 allows attackers to obtain the victim's cookies.

CVE-2023-39710
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 3 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Customer section.

CVE-2023-43468
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.8%
2023 1 PoC

SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the login.php component.

CVE-2023-23192
Software Genérico General
N/A
UNKNOWN
EPSS
12.0%
2023 1 PoC

IS Decisions UserLock MFA 11.01 is vulnerable to authentication bypass using scheduled task.

CVE-2023-40361
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

SECUDOS Qiata (DOMOS OS) 4.13 has Insecure Permissions for the previewRm.sh daily cronjob. To exploit this, an attacker needs access as a low-privileged user to the underlying DOMOS system. Every user on the system has write permission for previewRm.sh, which is executed by the root user.

CVE-2023-41107
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2023 2 PoCs

TEF portal 2023-07-17 is vulnerable to a persistent cross site scripting (XSS)attack.

CVE-2023-39810
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.

CVE-2023-46450
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 3 PoCs

Sourcecodester Free and Open Source inventory management system 1.0 is vulnerable to Cross Site Scripting (XSS) via the Add supplier function.

CVE-2023-35866
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In KeePassXC through 2.7.5, a local attacker can make changes to the Database security settings, including master password and second-factor authentication, within an authenticated KeePassXC Database session, without the need to authenticate these changes by entering the password and/or second-factor authentication to confirm changes. NOTE: the vendor's position is "asking the user for their password prior to making any changes to the database settings adds no additional protection against a local attacker."

CVE-2023-34260
Software Genérico General
N/A
UNKNOWN
EPSS
3.4%
2023 1 PoC

Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow a denial of service (service outage) via /wlmdeu%2f%2e%2e%2f%2e%2e followed by a directory reference such as %2fetc%00index.htm to try to read the /etc directory.

CVE-2023-45279
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Yamcs 5.8.6 allows XSS (issue 1 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to upload a display referencing a malicious JavaScript file to the bucket. The user can then open the uploaded display by selecting Telemetry from the menu and navigating to the display.

CVE-2023-40305
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

GNU indent 2.2.13 has a heap-based buffer overflow in search_brace in indent.c via a crafted file.

CVE-2023-38633
Software Genérico General
N/A
UNKNOWN
EPSS
43.6%
2023 2 PoCs

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.

CVE-2023-51019
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘key5g’ parameter of the setWiFiExtenderConfig interface of the cstecgi .cgi.

CVE-2023-20593
Ryzen™ 3000 Series Desktop Processors “Matisse” AM4 General
N/A
UNKNOWN
EPSS
5.9%
2023 3 PoCs

An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.

CVE-2023-2601
wpbrutalai Web Database Windows
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

The wpbrutalai WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin via CSRF.

CVE-2023-45158
web2py General
N/A
UNKNOWN
EPSS
15.0%
2023 1 PoC

An OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifySendHandler for logging (not the default configuration), a crafted web request may execute an arbitrary OS command on the web server using the product.

CVE-2023-37605
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Weak Exception Handling vulnerability in baramundi software GmbH EMM Agent 23.1.50 and before allows an attacker to cause a denial of service via a crafted request to the password parameter.