3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-49965
Software Genérico Web Networking
6.8
MEDIUM
EPSS
0.4%
2023 1 PoC

SpaceX Starlink Wi-Fi router Gen 2 before 2023.48.0 allows XSS via the ssid and password parameters on the Setup Page.

CVE-2023-1033
froxlor/froxlor Web
6.8
MEDIUM
EPSS
0.2%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.11.

CVE-2023-4422
cockpit-hq/cockpit Web
6.8
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

CVE-2023-2614
pimcore/pimcore Web
6.8
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-2102
alextselegidis/easyappointments Web
6.8
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

CVE-2023-35719
ADSelfService Plus Web
6.8
MEDIUM
EPSS
0.1%
2023 CWE-345 1 PoC

ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of ManageEngine ADSelfService Plus. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Password Reset Portal used by the GINA client. The issue results from the lack of proper authentication of data received via HTTP. An attacker can leverage this vulnerability to bypass authentication and execute code in the contex

CVE-2023-2228
modoboa/modoboa Web
6.8
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.1.0.

CVE-2023-24518
Pandora FMS Web
6.7
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

A Cross-site Request Forgery (CSRF) vulnerability in Pandora FMS allows an attacker to force authenticated users to send a request to a web application they are currently authenticated against. This issue affects Pandora FMS version 767 and earlier versions on all platforms.

CVE-2023-0828
Pandora FMS Web
6.7
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) vulnerability in Syslog Section of Pandora FMS allows attacker to cause that users cookie value will be transferred to the attackers users server. This issue affects Pandora FMS v767 version and prior versions on all platforms.

CVE-2023-31493
Software Genérico Web
6.6
MEDIUM
EPSS
2.5%
2023 2 PoCs

RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing execution of any commands on the remote system.

CVE-2023-2429
thorsten/phpmyfaq Web
6.6
MEDIUM
EPSS
0.3%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.13.

CVE-2023-37941
Apache Superset Web
6.6
MEDIUM
EPSS
84.2%
2023 CWE-502 2 PoCs

If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. The Superset metadata db is an 'internal' component that is typically only accessible directly by the system administrator and the superset process itself. Gaining access to that database should be difficult and require significant privileges. This vulnerability impacts Apache Superset versions 1.5.0 up to and including 2.1.0. Users are recommended to upgrade to version 2.1.1 or later.

CVE-2023-3507
WooCommerce Pre-Orders Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when canceling pre-orders, which could allow attackers to make logged in admins cancel arbitrary pre-orders via a CSRF attack

CVE-2023-0336
OoohBoi Steroids for Elementor Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber to delete attachment.

CVE-2023-49112
SAST Web
6.5
MEDIUM
EPSS
0.1%
2023 3 PoCs

Kiuwan provides an API endpoint /saas/rest/v1/info/application to get information about any application, providing only its name via the "application" parameter. This endpoint lacks proper access control mechanisms, allowing other authenticated users to read information about applications, even though they have not been granted the necessary rights to do so. This issue affects Kiuwan SAST: <master.1808.p685.q13371

CVE-2023-4930
Front End PM Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The Front End PM WordPress plugin before 11.4.3 does not block listing the contents of the directories where it stores attachments to private messages, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled.

CVE-2023-7268
ArtPlacer Widget Web Windows
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated users, such as subscriber, to delete arbitrary widgets

CVE-2023-6139
Essential Real Estate Web Windows
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Denial of Service attacks.

CVE-2023-0911
WordPress Shortcodes Plugin — Shortcodes Ultimate Web Windows
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to be retrieved via the user shortcode, allowing any authenticated users such as subscriber to retrieve arbitrary user meta (except the user_pass), such as the user email and activation key by default.

CVE-2023-5070
Social Media Share Buttons & Social Sharing Icons Web Windows
6.5
MEDIUM
EPSS
14.9%
2023 CWE-200 1 PoC

The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.8.5 via the sfsi_save_export function. This can allow subscribers to export plugin settings that include social media authentication tokens and secrets as well as app passwords.