3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-4114
Night Club Booking Software Web ⚡ nuclei
4.3
MEDIUM
EPSS
6.8%
2023 CWE-79 2 PoCs

A vulnerability was found in PHP Jabbers Night Club Booking Software 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-235961 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-4381
instantsoft/icms2 Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-620 1 PoC

Unverified Password Change in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

CVE-2023-1337
RapidLoad AI – Optimize Web Vitals Automatically Web Windows
4.3
MEDIUM
EPSS
3.7%
2023 CWE-862 1 PoC

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the clear_uucss_logs function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to delete plugin log files.

CVE-2023-5498
chiefonboarding/chiefonboarding Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository chiefonboarding/chiefonboarding prior to v2.0.47.

CVE-2023-6257
Inline Related Posts Web Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The Inline Related Posts WordPress plugin before 3.6.0 is missing authorization in an AJAX action to ensure that users are allowed to see the content of the posts displayed, allowing any authenticated user, such as subscriber to retrieve the content of password protected posts

CVE-2023-46089
Userback Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in Lee Le @ Userback Userback plugin <= 1.0.13 versions.

CVE-2023-4865
Take-Note App Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 2 PoCs

A vulnerability has been found in SourceCodester Take-Note App 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-239350 is the identifier assigned to this vulnerability.

CVE-2023-22013
Business Intelligence Enterprise Edition Web Database
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 6.4.0.0.0 and 7.0.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/A

CVE-2023-1911
Blocksy Companion Web Windows
4.3
MEDIUM
EPSS
0.3%
2023 1 PoC

The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example

CVE-2023-4036
Simple Blog Card Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Simple Blog Card WordPress plugin before 1.32 does not ensure that posts to be displayed via a shortcode are public, allowing any authenticated users, such as subscriber, to retrieve arbitrary post title and their content such as draft, private and password protected ones

CVE-2023-5352
Awesome Support Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Awesome Support WordPress plugin before 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing users to edit posts for which they do not have permission.

CVE-2023-30683
Samsung Mobile Devices Web
4.3
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call endCall API without permission.

CVE-2023-0505
Ever Compare Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Ever Compare WordPress plugin through 1.2.3 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-4318
Herd Effects Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items, which could allow attackers to make logged in admins delete arbitrary effects via a CSRF attack

CVE-2023-6633
Site Notes Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Site Notes WordPress plugin through 2.0.0 does not have CSRF checks in some of its functionalities, which could allow attackers to make logged in users perform unwanted actions, such as deleting administration notes, via CSRF attacks

CVE-2023-21959
iReceivables Web Database
4.3
MEDIUM
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (component: Attachments). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iReceivables. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle iReceivables accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVE-2023-1680
CMS Web
4.3
MEDIUM
EPSS
0.3%
2023 CWE-200 1 PoC

A vulnerability, which was classified as problematic, has been found in Xunrui CMS 4.61. This issue affects some unknown processing of the file /dayrui/My/View/main.html. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-224237 was assigned to this vulnerability.

CVE-2023-6292
Ecwid Ecommerce Shopping Cart Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Ecwid Ecommerce Shopping Cart WordPress plugin before 6.12.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVE-2023-23856
SAP BusinessObjects Business Intelligence (Web Intelligence UI) Web
4.3
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

In SAP BusinessObjects Business Intelligence (Web Intelligence user interface) - version 430, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls directly the jsp of Web Intelligence DHTML may be vulnerable to XSS attacks. On successful exploitation an attacker can cause a low impact on integrity of the application.

CVE-2023-5546
Software Genérico Web
4.3
MEDIUM
EPSS
1.8%
2023 CWE-79 1 PoC

ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.