3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-6985
10Web AI Assistant – AI content writing assistant Web Windows
6.5
MEDIUM
EPSS
7.8%
2023 CWE-862 1 PoC

The 10Web AI Assistant – AI content writing assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the install_plugin AJAX action in all versions up to, and including, 1.0.18. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins that can be used to gain further access to a compromised site.

CVE-2023-1371
W4 Post List Web Windows
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

The W4 Post List WordPress plugin before 2.4.6 does not ensure that password protected posts can be accessed before displaying their content, which could allow any authenticated users to access them

CVE-2023-1460
Online Pizza Ordering System Web
6.5
MEDIUM
EPSS
0.3%
2023 CWE-287 1 PoC

A vulnerability was found in SourceCodester Online Pizza Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file admin/ajax.php?action=save_user of the component Password Change Handler. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The identifier VDB-223305 was assigned to this vulnerability.

CVE-2023-3125
B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

The B2BKing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'b2bking_save_price_import' function in versions up to, and including, 4.6.00. This makes it possible for Authenticated attackers with subscriber or customer-level permissions to modify the pricing of any product on the site.

CVE-2023-7268
ArtPlacer Widget Web Windows
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated users, such as subscriber, to delete arbitrary widgets

CVE-2023-0336
OoohBoi Steroids for Elementor Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber to delete attachment.

CVE-2023-4930
Front End PM Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The Front End PM WordPress plugin before 11.4.3 does not block listing the contents of the directories where it stores attachments to private messages, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled.

CVE-2023-32750
Software Genérico Web
6.5
MEDIUM
EPSS
2.8%
2023 2 PoCs

Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The job "remote-download" can be used to cause the backend to send a HTTP GET request to a specified URL and save the response to a new file. The response file is then available in a user-specified folder in Pydio Cells.

CVE-2023-49112
SAST Web
6.5
MEDIUM
EPSS
0.1%
2023 3 PoCs

Kiuwan provides an API endpoint /saas/rest/v1/info/application to get information about any application, providing only its name via the "application" parameter. This endpoint lacks proper access control mechanisms, allowing other authenticated users to read information about applications, even though they have not been granted the necessary rights to do so. This issue affects Kiuwan SAST: <master.1808.p685.q13371

CVE-2023-6139
Essential Real Estate Web Windows
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Denial of Service attacks.

CVE-2023-0335
WP Shamsi Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber delete attachment.

CVE-2023-2787
Mattermost Web
6.5
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary posts by using the message threads API.

CVE-2023-4455
wallabag/wallabag Web
6.5
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3.

CVE-2023-21984
Solaris Operating System Web Database
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Libraries). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVE-2023-46673
Elasticsearch Web Database
6.5
MEDIUM
EPSS
0.5%
2023 CWE-755 1 PoC

It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.

CVE-2023-22022
Life Sciences Data Management Workbench Web Database
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Vulnerability in the Oracle Health Sciences Sciences Data Management Workbench product of Oracle Health Sciences Applications (component: Blinding Functionality). Supported versions that are affected are 3.1.0.2, 3.1.1.3 and 3.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Health Sciences Sciences Data Management Workbench. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Health Sciences Sciences Data Management Workbench accessible data. CVS

CVE-2023-27636
Software Genérico Web
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.

CVE-2023-22037
Web Applications Desktop Integrator Web Database
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: MS Excel Specific). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Web Applications Desktop Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vu

CVE-2023-40285
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

CVE-2023-0522
Enable/Disable Auto Login when Register Web Windows
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

The Enable/Disable Auto Login when Register WordPress plugin through 1.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack