3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-49293
vite General ⚡ nuclei
6.1
MEDIUM
EPSS
7.8%
2023 CWE-79 0 PoCs

Vite is a website frontend framework. When Vite's HTML transformation is invoked manually via `server.transformIndexHtml`, the original request URL is passed in unmodified, and the `html` being transformed contains inline module scripts (`<script type="module">...</script>`), it is possible to inject arbitrary HTML into the transformed output by supplying a malicious URL query string to `server.transformIndexHtml`. Only apps using `appType: 'custom'` and using the default Vite HTML middleware are affected. The HTML entry must also contain an inline script. The attack requires a user to click o

CVE-2023-1877
microweber/microweber General
6.1
MEDIUM
EPSS
4.7%
2023 CWE-77 1 PoC

Command Injection in GitHub repository microweber/microweber prior to 1.3.3.

CVE-2023-46950
Software Genérico General
6.1
MEDIUM
EPSS
0.3%
2023 1 PoC

Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted URL to the filter functions.

CVE-2023-21496
Samsung Mobile Devices General
6.1
MEDIUM
EPSS
0.2%
2023 CWE-489 1 PoC

Active Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows attacker to use debug function via setting debug level.

CVE-2023-41703
OX App Suite General
6.1
MEDIUM
EPSS
0.7%
2023 CWE-79 1 PoC

User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with a malicious document. Please deploy the provided updates and patch releases. User-defined content like comments and mentions are now filtered to avoid potentially malicious content. No publicly available exploits are known.

CVE-2023-32218
IX Workforce Engagement General
6.1
MEDIUM
EPSS
0.1%
2023 CWE-601 1 PoC

Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

CVE-2023-23853
NetWeaver Application Server for ABAP and ABAP Platform General
6.1
MEDIUM
EPSS
0.5%
2023 CWE-601 1 PoC

An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, can craft a link which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or modify some sensitive information or expose the victim to a phishing attack. Vulnerability has no direct impact on availability.

CVE-2023-23858
SAP NetWeaver AS for ABAP and ABAP Platform General
6.1
MEDIUM
EPSS
0.6%
2023 CWE-79 1 PoC

Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to send a crafted URL to a user, and by clicking the URL, the tricked user accesses SAP and might be directed with the response to somewhere out-side SAP and enter sensitive data. This could cause a limited impact on confidentiality and integrity of the application.

CVE-2023-28850
perspective-editor General
6.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Pimcore Perspective Editor provides an editor for Pimcore that allows users to add/remove/edit custom views and perspectives. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other malicious sites. Version 1.5.1 has a patch. As a workaround, one may apply the patch manually.

CVE-2023-30677
Samsung Pass General
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass on a certain state of an unlocked device.

CVE-2023-47488
Software Genérico General
6.1
MEDIUM
EPSS
4.6%
2023 3 PoCs

Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive information via a crafted script to the attrib_manager_id parameter in the General Information page and the id parameter in the contact page.

CVE-2023-48928
Software Genérico General
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Open Redirect. The 'path' parameter of the prefs.asp resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.

CVE-2023-48104
Software Genérico General
6.1
MEDIUM
EPSS
15.4%
2023 2 PoCs

Alinto SOGo before 5.9.1 is vulnerable to HTML Injection.

CVE-2023-33405
Software Genérico General ⚡ nuclei
6.1
MEDIUM
EPSS
51.4%
2023 1 PoC

Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect.

CVE-2023-24521
NetWeaver AS ABAP (BSP Framework) General
6.1
MEDIUM
EPSS
1.4%
2023 CWE-79 1 PoC

Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This may lead to a limited impact on the confidentiality and the integrity of the application.

CVE-2023-20533
Ryzen™ 3000 series Desktop Processors “Matisse" General
6.1
MEDIUM
EPSS
0.0%
2023 3 PoCs

Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.

CVE-2023-31406
SAP BusinessObjects Business Intelligence Platform General
6.1
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

Due to insufficient input validation, SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an unauthenticated attacker to redirect users to untrusted site using a malicious link. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

CVE-2023-39218
Zoom Clients General
6.1
MEDIUM
EPSS
0.4%
2023 CWE-602 1 PoC

Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access.

CVE-2023-41787
Pandora FMS General
6.0
MEDIUM
EPSS
0.1%
2023 CWE-427 1 PoC

Uncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File Search Paths. This vulnerability allows access to files with sensitive information. This issue affects Pandora FMS: from 700 through 772.

CVE-2023-6832
microweber/microweber General
6.0
MEDIUM
EPSS
0.1%
2023 CWE-840 1 PoC

Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.