3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-5546
Software Genérico Web
4.3
MEDIUM
EPSS
1.8%
2023 CWE-79 1 PoC

ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.

CVE-2023-7196
Ultimate Noindex Nofollow Tool Web Windows
4.3
MEDIUM
EPSS
0.3%
2023 1 PoC

The Ultimate Noindex Nofollow Tool WordPress plugin through 1.1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2023-1197
uvdesk/community-skeleton Web
4.3
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository uvdesk/community-skeleton prior to 1.1.0.

CVE-2023-7173
Hospital Management System Web
4.3
MEDIUM
EPSS
11.4%
2023 CWE-79 2 PoCs

A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file registration.php. The manipulation of the argument First Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249357 was assigned to this vulnerability.

CVE-2023-30682
Samsung Mobile Devices Web
4.3
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call silenceRinger API without permission.

CVE-2023-21834
Self-Service Human Resources Web Database
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Workflow, Approval, Work Force Management). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Self-Service Human Resources. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Self-Service Human Resources accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/

CVE-2023-4113
Service Booking Script Web ⚡ nuclei
4.3
MEDIUM
EPSS
15.1%
2023 CWE-79 1 PoC

A vulnerability was found in PHP Jabbers Service Booking Script 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is VDB-235960. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-7139
Client Details System Web Database
4.3
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability has been found in code-projects Client Details System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/regester.php of the component HTTP POST Request Handler. The manipulation of the argument fname/lname/email/contact leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-249142 is the identifier assigned to this vulnerability.

CVE-2023-7198
WP Dashboard Notes Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses a significant security risk as it violates the principle of least privilege and compromises the integrity and privacy of user data.

CVE-2023-7055
Online Notes Sharing System Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

A vulnerability classified as problematic has been found in PHPGurukul Online Notes Sharing System 1.0. Affected is an unknown function of the file /user/profile.php of the component Contact Information Handler. The manipulation of the argument mobilenumber leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-248742 is the identifier assigned to this vulnerability.

CVE-2023-26839
Software Genérico Web
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to edit information for existing people on the site.

CVE-2023-2287
Orbit Fox by ThemeIsle Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Orbit Fox by ThemeIsle WordPress plugin before 2.10.24 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.

CVE-2023-22027
Business Intelligence Enterprise Edition Web Database
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L

CVE-2023-1088
WP Plugin Manager Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Plugin Manager WordPress plugin before 1.1.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-4878
instantsoft/icms2 Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

CVE-2023-3234
CRMEB Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-502 1 PoC

A vulnerability was found in Zhong Bang CRMEB up to 4.6.0. It has been declared as problematic. Affected by this vulnerability is the function put_image of the file api/controller/v1/PublicController.php. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-231505 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-0498
WP Education Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Education WordPress plugin before 1.2.7 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-5525
Limit Login Attempts Reloaded Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` AJAX action, allowing any user with a valid nonce to toggle the auto-update status of the plugin.

CVE-2023-2903
Rapid Development Platform Web
4.3
MEDIUM
EPSS
0.3%
2023 CWE-284 1 PoC

A vulnerability classified as problematic has been found in NFine Rapid Development Platform 20230511. This affects an unknown part of the file /SystemManage/Role/GetGridJson?keyword=&page=1&rows=20. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-229977 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-5711
System Dashboard Web Windows
4.3
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_php_info() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve sensitive information provided by PHP info.