7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-34569
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list at /goform/SetNetControlList.

CVE-2023-4417
Remote Desktop Manager Windows
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Improper access controls in the entry duplication component in Devolutions Remote Desktop Manager 2023.2.19 and earlier versions on Windows allows an authenticated user, under specific circumstances, to inadvertently share their personal vault entry with shared vaults via an incorrect vault in the duplication write process.

CVE-2023-43252
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow via a crafted image file.

CVE-2023-51765
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2023 2 PoCs

sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports <LF>.<CR><LF> but some other popular e-mail servers do not. This is resolved in 8.18 and later versions with 'o' in srv_features.

CVE-2023-44048
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Sourcecodester Expense Tracker App v1 is vulnerable to Cross Site Scripting (XSS) via add category.

CVE-2023-20569
Ryzen™ 3000 Series Desktop Processors General
N/A
UNKNOWN
EPSS
2.0%
2023 2 PoCs

A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.

CVE-2023-2271
Tiempo.com Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Tiempo.com WordPress plugin through 0.1.2 does not have CSRF check when deleting its shortcode, which could allow attackers to make logged in admins delete arbitrary shortcode via a CSRF attack

CVE-2023-39558
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

AudimexEE v15.0 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the Show Kai Data component.

CVE-2023-28467
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

In MyBB before 1.8.34, there is XSS in the User CP module via the user email field.

CVE-2023-44962
Software Genérico General
N/A
UNKNOWN
EPSS
3.2%
2023 1 PoC

File Upload vulnerability in Koha Library Software 23.05.04 and before allows a remote attacker to read arbitrary files via the upload-cover-image.pl component.

CVE-2023-47804
Apache OpenOffice Web
N/A
UNKNOWN
EPSS
2.3%
2023 CWE-20 1 PoC

Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. Links can be activated by clicks, or by automatic document events. The execution of such links must be subject to user approval. In the affected versions of OpenOffice, approval for certain links is not requested; when activated, such links could therefore result in arbitrary script execution. This is a corner case of CVE-2022-47502.

CVE-2023-46024
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.1%
2023 1 PoC

SQL Injection vulnerability in index.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to run arbitrary SQL commands and obtain sensitive information via the 'searchdata' parameter.

CVE-2023-44764
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A Cross Site Scripting (XSS) vulnerability in Concrete CMS before 9.2.3 exists via the Name parameter during installation (aka Site of Installation or Settings).

CVE-2023-28872
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic link from a %LOCALAPPDATA%\Temp\NcpSupport* location.

CVE-2023-40121
Android Database
N/A
UNKNOWN
EPSS
0.1%
2023 4 PoCs

In appendEscapedSQLString of DatabaseUtils.java, there is a possible SQL injection due to unsafe deserialization. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-5640
Article analytics Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2023 2 PoCs

The Article Analytics WordPress plugin does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection vulnerability.

CVE-2023-26469
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.0%
2023 2 PoCs

In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.

CVE-2023-41646
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 3 PoCs

Buttercup v2.20.3 allows attackers to obtain the hash of the master password for the password manager via accessing the file /vaults.json/

CVE-2023-46386
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via registry.xml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication.

CVE-2023-2026
Image Protector Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Image Protector WordPress plugin through 1.1 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).