3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-3726
OCSInventory Web
6.9
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

OCSInventory allow stored email template with special characters that lead to a Stored cross-site Scripting.

CVE-2023-7328
Screen SFT DAB 600/C Web
6.9
MEDIUM
EPSS
0.1%
2023 CWE-306 2 PoCs

Screen SFT DAB 600/C firmware versions up to and including 1.9.3 contain an improper access control on the user management API allows unauthenticated requests to retrieve structured user data, including account names and connection metadata such as client IP and timeout values.

CVE-2023-53871
Soosyze Web
6.9
MEDIUM
EPSS
0.3%
2023 CWE-434 1 PoC

Soosyze 2.0.0 contains a file upload vulnerability that allows attackers to upload arbitrary HTML files with embedded PHP code to the application. Attackers can exploit the broken file upload mechanism to potentially view sensitive file paths and execute malicious PHP scripts on the server.

CVE-2023-30962
com.palantir.acme.cerberus:cerberus Web
6.8
MEDIUM
EPSS
0.6%
2023 CWE-434 1 PoC

The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Gotham to launch attacks against other users. This vulnerability is resolved in Cerberus 100.230704.0-27-g031dd58 .

CVE-2023-0541
GS Books Showcase Web Windows
6.8
MEDIUM
EPSS
0.5%
2023 1 PoC

The GS Books Showcase WordPress plugin before 1.3.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0378
Greenshift Web Windows
6.8
MEDIUM
EPSS
0.5%
2023 1 PoC

The Greenshift WordPress plugin before 5.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-2323
pimcore/pimcore Web
6.8
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-49983
Software Genérico Web
6.8
MEDIUM
EPSS
0.4%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.

CVE-2023-0075
Amazon JS Web Windows
6.8
MEDIUM
EPSS
0.5%
2023 1 PoC

The Amazon JS WordPress plugin through 0.10 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-21922
Health Sciences InForm Web Database
6.8
MEDIUM
EPSS
0.7%
2023 1 PoC

Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Health Sciences InForm accessible

CVE-2023-0642
squidex/squidex Web
6.8
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository squidex/squidex prior to 7.4.0.

CVE-2023-0375
Easy Affiliate Links Web Windows
6.8
MEDIUM
EPSS
0.7%
2023 1 PoC

The Easy Affiliate Links WordPress plugin before 3.7.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0061
Judge.me Product Reviews for WooCommerce Web Windows
6.8
MEDIUM
EPSS
0.5%
2023 1 PoC

The Judge.me Product Reviews for WooCommerce WordPress plugin before 1.3.21 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-3589
Teamwork Cloud - Business Edition Web Cloud
6.8
MEDIUM
EPSS
0.2%
2023 CWE-352 1 PoC

A Cross-Site Request Forgery (CSRF) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x could allow with some very specific conditions an attacker to send a specifically crafted query to the server.

CVE-2023-2614
pimcore/pimcore Web
6.8
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-4652
instantsoft/icms2 Web
6.8
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

CVE-2023-20116
Cisco Unified Communications Manager Web Networking
6.8
MEDIUM
EPSS
0.5%
2023 CWE-835 1 PoC

A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the web UI of the Self Care Portal. An attacker could exploit this vulnerability by sending crafted HTTP input to an affected device. A successful exploit could allow the attacker to cause a DoS conditi

CVE-2023-2616
pimcore/pimcore Web
6.8
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-49923
Enterprise Search Web
6.8
MEDIUM
EPSS
0.4%
2023 CWE-532 1 PoC

An issue was discovered by Elastic whereby the Documents API of App Search logged the raw contents of indexed documents at INFO log level. Depending on the contents of such documents, this could lead to the insertion of sensitive or private information in the App Search logs. Elastic has released 8.11.2 and 7.17.16 that resolves this issue by changing the log level at which these are logged to DEBUG, which is disabled by default.

CVE-2023-2615
pimcore/pimcore Web
6.8
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.