3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-1788
firefly-iii/firefly-iii General
5.4
MEDIUM
EPSS
0.2%
2023 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository firefly-iii/firefly-iii prior to 6.

CVE-2023-34732
Software Genérico General
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c allows attackers to execute brute force attacks to discover user passwords.

CVE-2023-29918
Software Genérico General
5.4
MEDIUM
EPSS
5.9%
2023 1 PoC

RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.

CVE-2023-30787
MonicaHQ General
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/introductions` endpoint and first_met_additional_info parameter.

CVE-2023-24203
Software Genérico General
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

Cross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitary code via the company or query parameter(s).

CVE-2023-6127
salesagility/suitecrm General
5.4
MEDIUM
EPSS
0.2%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

CVE-2023-3227
fossbilling/fossbilling General
5.4
MEDIUM
EPSS
0.1%
2023 CWE-1220 1 PoC

Insufficient Granularity of Access Control in GitHub repository fossbilling/fossbilling prior to 0.5.0.

CVE-2023-47325
Software Genérico General
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces.

CVE-2023-3580
squidex/squidex General
5.4
MEDIUM
EPSS
0.1%
2023 CWE-167 1 PoC

Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.

CVE-2023-27292
OpenCATS General ⚡ nuclei
5.4
MEDIUM
EPSS
1.7%
2023 1 PoC

An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters.

CVE-2023-51281
Software Genérico General
5.4
MEDIUM
EPSS
0.2%
2023 2 PoCs

Cross Site Scripting vulnerability in Customer Support System v.1.0 allows a remote attacker to escalate privileges via a crafted script firstname, "lastname", "middlename", "contact" and address parameters.

CVE-2023-3229
fossbilling/fossbilling General
5.4
MEDIUM
EPSS
0.1%
2023 CWE-840 1 PoC

Business Logic Errors in GitHub repository fossbilling/fossbilling prior to 0.5.0.

CVE-2023-0643
squidex/squidex General
5.4
MEDIUM
EPSS
0.4%
2023 CWE-167 1 PoC

Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.

CVE-2023-29052
OX App Suite General
5.4
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added sanitization for this content. No publicly available exploits are known.

CVE-2023-42575
Samsung Pass General
5.4
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid flag setting.

CVE-2023-29983
Software Genérico General
5.4
MEDIUM
EPSS
40.8%
2023 3 PoCs

Cross Site Scripting vulnerability found in Maximilian Vogt cmaps v.8.0 allows a remote attacker to execute arbitrary code via the auditlog tab in the admin panel.

CVE-2023-42143
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8@5afc928c allows malicious users to create a backdoor by redirecting the device to an attacker-controlled machine which serves the manipulated firmware file. The device is updated with the manipulated firmware.

CVE-2023-42554
Samsung Pass General
5.4
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication.

CVE-2023-0434
pyload/pyload General
5.4
MEDIUM
EPSS
0.5%
2023 CWE-20 1 PoC

Improper Input Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev40.

CVE-2023-2105
alextselegidis/easyappointments General
5.4
MEDIUM
EPSS
0.8%
2023 CWE-384 1 PoC

Session Fixation in GitHub repository alextselegidis/easyappointments prior to 1.5.0.