7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-28343
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.2%
2023 4 PoCs

OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php.

CVE-2023-0285
Real Media Library: Media Library Folder & File Manager Web Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The Real Media Library WordPress plugin before 4.18.29 does not sanitise and escape the created folder names, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-31704
Software Genérico General
N/A
UNKNOWN
EPSS
1.6%
2023 2 PoCs

Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate privileges to the administrator's role.

CVE-2023-34843
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2023 3 PoCs

Traggo Server 0.3.0 is vulnerable to directory traversal via a crafted GET request.

CVE-2023-31301
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Stored Cross Site Scripting (XSS) Vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code and obtain sensitive information via the Username field of the login form and application log.

CVE-2023-45852
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2023 0 PoCs

In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell metacharacters in the ipaddr params JSON data for the put method.

CVE-2023-5360
Royal Elementor Addons and Templates Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.5%
2023 12 PoCs

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

CVE-2023-45391
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A stored cross-site scripting (XSS) vulnerability in the Create A New Employee function of Granding UTime Master v9.0.7-Build:Apr 4,2023 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the First Name parameter.

CVE-2023-48849
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.8%
2023 1 PoC

Ruijie EG Series Routers version EG_3.0(1)B11P216 and before allows unauthenticated attackers to remotely execute arbitrary code due to incorrect filtering.

CVE-2023-33570
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).

CVE-2023-39714
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2023 3 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Member section.

CVE-2023-37790
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Jaspersoft Clarity PPM version 14.3.0.298 was discovered to contain an arbitrary file upload vulnerability via the Profile Picture Upload function.

CVE-2023-2592
FormCraft Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The FormCraft WordPress plugin before 3.9.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-48835
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.

CVE-2023-38909
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the IV component in the AES128-CBC function.

CVE-2023-42471
Software Genérico Web
N/A
UNKNOWN
EPSS
3.1%
2023 1 PoC

The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It contains a manifest entry that exports the wave.ai.browser.ui.splash.SplashScreen activity. This activity uses a WebView component to display web content and doesn't adequately validate or sanitize the URI or any extra data passed in the intent by a third party application (with no permissions).

CVE-2023-46865
Software Genérico Web
N/A
UNKNOWN
EPSS
70.2%
2023 2 PoCs

/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image.

CVE-2023-2493
All In One Redirection Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

The All In One Redirection WordPress plugin before 2.2.0 does not properly sanitise and escape multiple parameters before using them in an SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2023-1273
ND Shortcodes Web Windows
N/A
UNKNOWN
EPSS
12.8%
2023 2 PoCs

The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks

CVE-2023-46857
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2023 1 PoC

Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomplete blacklist in the SVG inspection, allowing JavaScript in the SRC attribute of an IFRAME element. An authenticated attack with assets.create permission is required for exploitation.