7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-6861
Firefox ESR General
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.

CVE-2023-28870
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to configuration files from low-privileged user accounts.

CVE-2023-38969
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Cross Site Scripting vulnerabiltiy in Badaso v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the title parameter in the new book and edit book function.

CVE-2023-52588
Linux Networking
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to tag gcing flag on page during block migration It needs to add missing gcing flag on page during block migration, in order to garantee migrated data be persisted during checkpoint, otherwise out-of-order persistency between data and node may cause data corruption after SPOR. Similar issue was fixed by commit 2d1fe8a86bf5 ("f2fs: fix to tag gcing flag on page during file defragment").

CVE-2023-3983
Advantech iView Database
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authenticated remote attacker can bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform blind SQL injection.

CVE-2023-39147
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.

CVE-2023-36212
Software Genérico Web
N/A
UNKNOWN
EPSS
48.1%
2023 2 PoCs

File Upload vulnerability in Total CMS v.1.7.4 allows a remote attacker to execute arbitrary code via a crafted PHP file to the edit page function.

CVE-2023-39319
html/template Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The html/template package does not apply the proper rules for handling occurrences of "<script", "<!--", and "</script" within JS literals in <script> contexts. This may cause the template parser to improperly consider script contexts to be terminated early, causing actions to be improperly escaped. This could be leveraged to perform an XSS attack.

CVE-2023-40127
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 5 PoCs

In multiple locations, there is a possible way to access screenshots due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-24128
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey2 parameter at /goform/WifiBasicSet.

CVE-2023-37755
Software Genérico General
N/A
UNKNOWN
EPSS
1.4%
2023 4 PoCs

i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or prompt to ask users to change the default password and account name. Unauthenticated attackers can exploit this vulnerability to obtain Administrator privileges, resulting in them being able to perform arbitrary system operations or cause a Denial of Service (DoS).

CVE-2023-27847
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
73.1%
2023 1 PoC

SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges via the xipcategoryclass and xippostsclass components.

CVE-2023-47444
Software Genérico Web
N/A
UNKNOWN
EPSS
4.0%
2023 1 PoC

An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privilege can write arbitrary untrusted data inside config.php and admin/config.php, resulting in remote code execution on the underlying server.

CVE-2023-5757
WP Crowdfunding Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WP Crowdfunding WordPress plugin before 2.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2023-46858
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content, but students can not."

CVE-2023-37190
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Virtual Fax Name and Caller ID Name parameters under the New Virtual Fax feature.

CVE-2023-4514
Mmm Simple File List Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Mmm Simple File List WordPress plugin through 2.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-28343
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.2%
2023 4 PoCs

OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php.

CVE-2023-0285
Real Media Library: Media Library Folder & File Manager Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Real Media Library WordPress plugin before 4.18.29 does not sanitise and escape the created folder names, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-31704
Software Genérico General
N/A
UNKNOWN
EPSS
1.6%
2023 2 PoCs

Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate privileges to the administrator's role.