3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-49969
Software Genérico Web Database
4.3
MEDIUM
EPSS
0.2%
2023 2 PoCs

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer.

CVE-2023-5713
System Dashboard Web Windows
4.3
MEDIUM
EPSS
0.3%
2023 CWE-862 1 PoC

The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve potentially sensitive option values, and deserialize the content of those values.

CVE-2023-30534
cacti Web ⚡ nuclei
4.3
MEDIUM
EPSS
54.9%
2023 CWE-502 0 PoCs

Cacti is an open source operational monitoring and fault management framework. There are two instances of insecure deserialization in Cacti version 1.2.24. While a viable gadget chain exists in Cacti’s vendor directory (phpseclib), the necessary gadgets are not included, making them inaccessible and the insecure deserializations not exploitable. Each instance of insecure deserialization is due to using the unserialize function without sanitizing the user input. Cacti has a “safe” deserialization that attempts to sanitize the content and check for specific values before calling unserialize, but

CVE-2023-6741
WP Customer Area Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Customer Area WordPress plugin before 8.2.1 does not properly validate users capabilities in some of its AJAX actions, allowing malicious users to edit other users' account address.

CVE-2023-3479
hestiacp/hestiacp Web ⚡ nuclei
4.3
MEDIUM
EPSS
23.5%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8.

CVE-2023-0496
HT Event Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The HT Event WordPress plugin before 1.4.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-6070
Trellix Enterprise Security Manager (ESM) Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-918 1 PoC

A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where the API accepts uploaded content and doesn't parse for invalid data

CVE-2023-4868
Contact Manager App Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

A vulnerability was found in SourceCodester Contact Manager App 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file add.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239353 was assigned to this vulnerability.

CVE-2023-3244
Comments Like Dislike Web Windows
4.3
MEDIUM
EPSS
3.3%
2023 CWE-862 1 PoC

The Comments Like Dislike plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the restore_settings function called via an AJAX action in versions up to, and including, 1.2.0. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to reset the plugin's settings. NOTE: this issue is was only partially patched in version 1.2.0, as the nonce is still present to subscriber-level users.

CVE-2023-47858
Mattermost Web
4.3
MEDIUM
EPSS
0.2%
2023 CWE-284 1 PoC

Mattermost fails to properly verify the permissions needed for viewing archived public channels,  allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams/<team-id>/channels/deleted endpoint.

CVE-2023-4114
Night Club Booking Software Web ⚡ nuclei
4.3
MEDIUM
EPSS
6.8%
2023 CWE-79 2 PoCs

A vulnerability was found in PHP Jabbers Night Club Booking Software 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-235961 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-3056
YFCMF Web
4.3
MEDIUM
EPSS
0.2%
2023 CWE-24 1 PoC

A vulnerability was found in YFCMF up to 3.0.4. It has been declared as problematic. This vulnerability affects unknown code of the file index.php. The manipulation leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-230542 is the identifier assigned to this vulnerability.

CVE-2023-1680
CMS Web
4.3
MEDIUM
EPSS
0.3%
2023 CWE-200 1 PoC

A vulnerability, which was classified as problematic, has been found in Xunrui CMS 4.61. This issue affects some unknown processing of the file /dayrui/My/View/main.html. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-224237 was assigned to this vulnerability.

CVE-2023-4150
User Activity Tracking and Log Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The User Activity Tracking and Log WordPress plugin before 4.0.9 does not have proper CSRF checks when managing its license, which could allow attackers to make logged in admins update and deactivate the plugin's license via CSRF attacks

CVE-2023-7139
Client Details System Web Database
4.3
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability has been found in code-projects Client Details System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/regester.php of the component HTTP POST Request Handler. The manipulation of the argument fname/lname/email/contact leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-249142 is the identifier assigned to this vulnerability.

CVE-2023-1858
Earnings and Expense Tracker App Web
4.3
MEDIUM
EPSS
0.2%
2023 CWE-200 1 PoC

A vulnerability was found in SourceCodester Earnings and Expense Tracker App 1.0. It has been classified as problematic. This affects an unknown part of the file index.php. The manipulation of the argument page leads to information disclosure. It is possible to initiate the attack remotely. The identifier VDB-224997 was assigned to this vulnerability.

CVE-2023-0761
Clock In Portal- Staff & Attendance Management Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Staff members, which could allow attackers to make logged in admins delete arbitrary Staff via a CSRF attack

CVE-2023-5329
DataCube4 Web
4.3
MEDIUM
EPSS
0.2%
2023 CWE-287 1 PoC

A vulnerability classified as problematic was found in Field Logic DataCube4 up to 20231001. This vulnerability affects unknown code of the file /api/ of the component Web API. The manipulation leads to improper authentication. The exploit has been disclosed to the public and may be used. VDB-241030 is the identifier assigned to this vulnerability.

CVE-2023-0503
Free WooCommerce Theme 99fy Extension Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Free WooCommerce Theme 99fy Extension WordPress plugin before 1.2.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-4209
POEditor Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The POEditor WordPress plugin before 0.9.8 does not have CSRF checks in various places, which could allow attackers to make logged in admins perform unwanted actions, such as reset the plugin's settings and update its API key via CSRF attacks.