3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-1623
Custom Post Type UI Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The Custom Post Type UI WordPress plugin before 1.13.5 does not properly check for CSRF when sending the debug information to a user supplied email, which could allow attackers to make a logged in admin send such information to an arbitrary email address via a CSRF attack.

CVE-2023-3073
tsolucio/corebos Web
6.5
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8 via evvtgendoc.

CVE-2023-35840
Software Genérico Web
6.5
MEDIUM
EPSS
6.3%
2023 1 PoC

_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.

CVE-2023-50811
Software Genérico Web
6.5
MEDIUM
EPSS
0.0%
2023 1 PoC

An issue discovered in SELESTA Visual Access Manager 4.38.6 allows attackers to modify the “computer” POST parameter related to the ID of a specific reception by POST HTTP request interception. Iterating that parameter, it has been possible to access to the application and take control of many other receptions in addition the assigned one.

CVE-2023-41336
ux-autocomplete Web
6.5
MEDIUM
EPSS
1.1%
2023 CWE-20 1 PoC

ux-autocomplete is a JavaScript Autocomplete functionality for Symfony. Under certain circumstances, an attacker could successfully submit an entity id for an `EntityType` that is *not* part of the valid choices. The problem has been fixed in `symfony/ux-autocomplete` version 2.11.2.

CVE-2023-25927
Security Verify Access Web
6.5
MEDIUM
EPSS
0.3%
2023 CWE-20 1 PoC

IBM Security Verify Access 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, and 10.0.5 could allow an attacker to crash the webseald process using specially crafted HTTP requests resulting in loss of access to the system. IBM X-Force ID: 247635.

CVE-2023-1496
imgproxy/imgproxy Web ⚡ nuclei
6.5
MEDIUM
EPSS
39.8%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository imgproxy/imgproxy prior to 3.14.0.

CVE-2023-1092
OAuth Single Sign On Free Web Windows
6.5
MEDIUM
EPSS
0.2%
2023 4 PoCs

The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium WordPress plugin before 38.4.9 and OAuth Single Sign On Enterprise WordPress plugin before 48.4.9 do not have CSRF checks when deleting Identity Providers (IdP), which could allow attackers to make logged in admins delete arbitrary IdP via a CSRF attack

CVE-2023-21978
Application Object Library Web Database
6.5
MEDIUM
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: GUI). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized u

CVE-2023-0502
WP News Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP News WordPress plugin through 1.1.9 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-7201
Everest Backup Web Windows
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

The Everest Backup WordPress plugin before 2.2.5 does not properly validate backup files to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

CVE-2023-27163
Software Genérico Web ⚡ nuclei
6.5
MEDIUM
EPSS
93.3%
2023 23 PoCs

request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.

CVE-2023-27073
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

A Cross-Site Request Forgery (CSRF) in Online Food Ordering System v1.0 allows attackers to change user details and credentials via a crafted POST request.

CVE-2023-6824
WP Customer Area Web Windows
6.5
MEDIUM
EPSS
0.5%
2023 1 PoC

The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX actions, allowing any users to retrieve other user's account address.

CVE-2023-5227
thorsten/phpmyfaq Web
6.5
MEDIUM
EPSS
0.4%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

CVE-2023-0314
thorsten/phpmyfaq Web
6.5
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

CVE-2023-20118
🔥 KEV Cisco Small Business RV Series Router Firmware Web Networking
6.5
MEDIUM
EPSS
3.8%
2023 CWE-77 1 PoC

A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to improper validation of user input within incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface. A successful exploit could allow the attacker to gain root-level privileges and access unauthorized data. To exploit this vulnerability, an attacke

CVE-2023-39422
IRM Next Generation Web
6.5
MEDIUM
EPSS
0.1%
2023 CWE-798 1 PoC

The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering this extra safety mechanism useless.

CVE-2023-26841
Software Genérico Web
6.5
MEDIUM
EPSS
1.1%
2023 1 PoC

A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to change any user's password except for the user that is currently logged in.

CVE-2023-33409
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Minical 1.0.0 is vulnerable to Cross Site Request Forgery (CSRF) via minical/public/application/controllers/settings/company.php.