3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-5519
EventPrime Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks.

CVE-2023-4183
Inventory Management System Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

A vulnerability has been found in SourceCodester Inventory Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file edit_update.php of the component Password Handler. The manipulation of the argument user_id leads to improper access controls. The attack can be initiated remotely. VDB-236218 is the identifier assigned to this vulnerability.

CVE-2023-23897
Simple Mobile URL Redirect Web ⚡ nuclei
4.3
MEDIUM
EPSS
51.0%
2023 CWE-352 0 PoCs

Cross-Site Request Forgery (CSRF) vulnerability in Ozette Plugins Simple Mobile URL Redirect plugin <= 1.7.2 versions.

CVE-2023-6297
Nipah Virus Testing Management System Web
4.3
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

A vulnerability classified as problematic has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of the file patient-search-report.php of the component Search Report Page. The manipulation of the argument Search By Patient Name with the input <script>alert(document.cookie)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-246123.

CVE-2023-6767
Wedding Guest e-Book Web
4.3
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

A vulnerability, which was classified as problematic, was found in SourceCodester Wedding Guest e-Book 1.0. This affects an unknown part of the file /endpoint/add-guest.php. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-247899.

CVE-2023-6289
Swift Performance Lite Web Cloud Windows
4.3
MEDIUM
EPSS
2.9%
2023 2 PoCs

The Swift Performance Lite WordPress plugin before 2.3.6.15 does not prevent users from exporting the plugin's settings, which may include sensitive information such as Cloudflare API tokens.

CVE-2023-1414
WP VR Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP VR WordPress plugin before 8.3.0 does not have authorisation and CSRF checks in various AJAX actions, one in particular could allow any authenticated users, such as subscriber to update arbitrary tours

CVE-2023-4836
WordPress File Sharing Plugin Web Windows
4.3
MEDIUM
EPSS
0.3%
2023 2 PoCs

The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and folders, allowing users to gain access to those filed by manipulating IDs which can easily be brute forced

CVE-2023-21902
Financial Services Behavior Detection Platform Web Database
4.3
MEDIUM
EPSS
0.4%
2023 1 PoC

Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Application). The supported version that is affected is 8.0.8.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Financial Services Behavior Detection Platform accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (

CVE-2023-7052
Online Notes Sharing System Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been classified as problematic. This affects an unknown part of the file /user/profile.php. The manipulation of the argument name leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248739.

CVE-2023-0763
Clock In Portal- Staff & Attendance Management Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Holidays, which could allow attackers to make logged in admins delete arbitrary holidays via a CSRF attack

CVE-2023-0495
HT Slider For Elementor Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The HT Slider For Elementor WordPress plugin before 1.4.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-6066
WP Custom Widget area Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Custom Widget area WordPress plugin through 1.2.5 does not properly apply capability and nonce checks on any of its AJAX action callback functions, which could allow attackers with subscriber+ privilege to create, delete or modify menus on the site.

CVE-2023-2791
Mattermost Web
4.3
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

When creating a playbook run via the /dialog API, Mattermost fails to validate all parameters, allowing an authenticated attacker to edit an arbitrary channel post.

CVE-2023-6501
Splashscreen Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Splashscreen WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2023-6202
Mattermost Web
4.3
MEDIUM
EPSS
0.2%
2023 CWE-284 1 PoC

Mattermost fails to perform proper authorization in the /plugins/focalboard/api/v2/users endpoint allowing an attacker who is a guest user and knows the ID of another user to get their information (e.g. name, surname, nickname) via Mattermost Boards.

CVE-2023-1087
WC Sales Notification Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WC Sales Notification WordPress plugin before 1.2.3 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-3707
ActivityPub Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The ActivityPub WordPress plugin before 1.0.0 does not ensure that post contents to be displayed are public and belong to the plugin, allowing any authenticated user, such as subscriber to retrieve the content of arbitrary post (such as draft and private) via an IDOR vector. Password protected posts are not affected by this issue.

CVE-2023-6653
Teacher Subject Allocation Management System Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

A vulnerability was found in PHPGurukul Teacher Subject Allocation Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/subject.php of the component Create a new Subject. The manipulation of the argument cid leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-247346 is the identifier assigned to this vulnerability.

CVE-2023-4111
Bus Reservation System Web ⚡ nuclei
4.3
MEDIUM
EPSS
16.8%
2023 CWE-79 2 PoCs

A vulnerability was found in PHP Jabbers Bus Reservation System 1.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument index/pickup_id leads to cross site scripting. The attack may be launched remotely. VDB-235958 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.