7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-36311
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

There is a SQL injection (SQLi) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0.

CVE-2023-46449
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 3 PoCs

Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function.

CVE-2023-38313
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

An issue was discovered in OpenNDS Captive Portal before 10.1.2. it has a do_binauth NULL pointer dereference that can be triggered with a crafted GET HTTP request with a missing client redirect query string parameter. Triggering this issue results in crashing openNDS (a Denial-of-Service condition). The issue occurs when the client is about to be authenticated, and can be triggered only when the BinAuth option is set. Affected OpenNDS Captive Portal before version 10.1.2 fixed infixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on28. August 2023 by updating OpenNDS to version 10.1.3.

CVE-2023-38194
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
4.3%
2023 1 PoC

An issue was discovered in SuperWebMailer 9.00.0.01710. It allows keepalive.php XSS via a GET parameter.

CVE-2023-40749
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
44.5%
2023 2 PoCs

PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.

CVE-2023-24127
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey1 parameter at /goform/WifiBasicSet.

CVE-2023-39599
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Cross-Site Scripting (XSS) vulnerability in CSZ CMS v.1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Social Settings parameter.

CVE-2023-23298
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2023 1 PoC

The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its parameters, which can result in integer overflows when allocating the underlying bitmap buffer. A malicious application could call the API method with specially crafted parameters and hijack the execution of the device's firmware.

CVE-2023-39138
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue in ZIPFoundation v0.9.16 allows attackers to execute a path traversal via extracting a crafted zip file.

CVE-2023-42882
macOS General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2. Processing an image may lead to arbitrary code execution.

CVE-2023-46015
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in index.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via 'msg' parameter in application URL.

CVE-2023-48929
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Session Fixation. The 'sid' parameter in the group_status.asp resource allows an attacker to escalate privileges and obtain sensitive information.

CVE-2023-40753
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
0.9%
2023 2 PoCs

There is a Cross Site Scripting (XSS) vulnerability in the message parameter of index.php in PHPJabbers Ticket Support Script v3.2.

CVE-2023-39641
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Active Design psaffiliate before v1.9.8 was discovered to contain a SQL injection vulnerability via the component PsaffiliateGetaffiliatesdetailsModuleFrontController::initContent().

CVE-2023-2802
Ultimate Addons for Contact Form 7 Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Ultimate Addons for Contact Form 7 WordPress plugin before 3.1.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-40453
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

Docker Machine through 0.16.2 allows an attacker, who has control of a worker node, to provide crafted version data, which might potentially trick an administrator into performing an unsafe action (via escape sequence injection), or might have a data size that causes a denial of service to a bastion node. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-40292
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Harman Infotainment 20190525031613 and later discloses the IP address via CarPlay CTRL packets.

CVE-2023-23294
Software Genérico General
N/A
UNKNOWN
EPSS
2.9%
2023 1 PoC

Korenix JetWave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection. An attacker can modify the file_name parameter to execute commands as root.

CVE-2023-48804
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.