13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-20891
VMware Tanzu Application Service for VMs Web
6.5
MEDIUM
EPSS
0.3%
2023 CWE-532 1 PoC

The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials in hex encoding in platform system audit logs. A malicious non-admin user who has access to the platform system audit logs can access hex encoded CF API admin credentials and can push new malicious versions of an application. In a default deployment non-admin users do not have access to the platform system audit logs.

CVE-2023-3073
tsolucio/corebos Web
6.5
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8 via evvtgendoc.

CVE-2023-42579
Samsung Keyboard Web
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45 in Android 13 allows adjacent attackers to access keystroke data using Man-in-the-Middle attack.

CVE-2023-35840
Software Genérico Web
6.5
MEDIUM
EPSS
6.3%
2023 1 PoC

_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.

CVE-2023-49985
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cname parameter.

CVE-2023-2446
UserPro - Community and User Profile WordPress Plugin Web Windows
6.5
MEDIUM
EPSS
0.3%
2023 CWE-200 2 PoCs

The UserPro plugin for WordPress is vulnerable to sensitive information disclosure via the 'userpro' shortcode in versions up to, and including 5.1.1. This is due to insufficient restriction on sensitive user meta values that can be called via that shortcode. This makes it possible for authenticated attackers, with subscriber-level permissions, and above to retrieve sensitive user meta that can be used to gain access to a high privileged user account.

CVE-2023-6821
Error Log Viewer by BestWebSoft Web Windows
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

The Error Log Viewer by BestWebSoft WordPress plugin before 1.1.3 is affected by a Directory Listing issue, allowing users to read and download PHP logs without authorization

CVE-2023-27163
Software Genérico Web ⚡ nuclei
6.5
MEDIUM
EPSS
93.3%
2023 23 PoCs

request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.

CVE-2023-27073
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

A Cross-Site Request Forgery (CSRF) in Online Food Ordering System v1.0 allows attackers to change user details and credentials via a crafted POST request.

CVE-2023-41336
ux-autocomplete Web
6.5
MEDIUM
EPSS
1.1%
2023 CWE-20 1 PoC

ux-autocomplete is a JavaScript Autocomplete functionality for Symfony. Under certain circumstances, an attacker could successfully submit an entity id for an `EntityType` that is *not* part of the valid choices. The problem has been fixed in `symfony/ux-autocomplete` version 2.11.2.

CVE-2023-39422
IRM Next Generation Web
6.5
MEDIUM
EPSS
0.1%
2023 CWE-798 1 PoC

The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering this extra safety mechanism useless.

CVE-2023-3125
B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

The B2BKing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'b2bking_save_price_import' function in versions up to, and including, 4.6.00. This makes it possible for Authenticated attackers with subscriber or customer-level permissions to modify the pricing of any product on the site.

CVE-2023-51504
Dan's Embedder for Google Calendar Web
6.5
MEDIUM
EPSS
1.9%
2023 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Dulaney Dan's Embedder for Google Calendar allows Stored XSS.This issue affects Dan's Embedder for Google Calendar: from n/a through 1.2.

CVE-2023-2179
WooCommerce Order Status Change Notifier Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an AJAX action available to any authenticated users, which could allow low privilege users such as subscriber to update arbitrary order status, making them paid without actually paying for them for example

CVE-2023-24366
Software Genérico Web
6.5
MEDIUM
EPSS
0.6%
2023 1 PoC

An arbitrary file download vulnerability in rConfig v6.8.0 allows attackers to download sensitive files via a crafted HTTP request.

CVE-2023-1430
FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution Web Windows
6.5
MEDIUM
EPSS
1.6%
2023 CWE-759 1 PoC

The FluentCRM - Marketing Automation For WordPress plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 2.8.01 due to the use of an MD5 hash without a salt to control subscriptions. This makes it possible for unauthenticated attackers to unsubscribe users from lists and manage subscriptions, granted they gain access to any targeted subscribers email address.

CVE-2023-1129
WP FEvents Book Web Windows
6.5
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP FEvents Book WordPress plugin through 0.46 does not ensures that bookings to be updated belong to the user making the request, allowing any authenticated user to book, add notes, or cancel booking on behalf of other users.

CVE-2023-0749
Ocean Extra Web Windows
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually a template, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, such as draft, private or even password protected ones.

CVE-2023-45826
leantime Web Database ⚡ nuclei
6.5
MEDIUM
EPSS
34.4%
2023 CWE-89 0 PoCs

Leantime is an open source project management system. A 'userId' variable in `app/domain/files/repositories/class.files.php` is not parameterized. An authenticated attacker can send a carefully crafted POST request to `/api/jsonrpc` to exploit an SQL injection vulnerability. Confidentiality is impacted as it allows for dumping information from the database. This issue has been addressed in version 2.4-beta-4. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2023-6277
Red Hat Enterprise Linux 6 Web
6.5
MEDIUM
EPSS
3.8%
2023 CWE-400 5 PoCs

An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.