3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-27163
Software Genérico Web ⚡ nuclei
6.5
MEDIUM
EPSS
93.3%
2023 23 PoCs

request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.

CVE-2023-5006
WP Discord Invite Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Discord Invite WordPress plugin before 2.5.1 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to perform actions on their behalf by tricking a logged in administrator to submit a crafted request.

CVE-2023-29020
fastify-passport Web
6.5
MEDIUM
EPSS
0.1%
2023 CWE-384 2 PoCs

@fastify/passport is a port of passport authentication library for the Fastify ecosystem. The CSRF (Cross-Site Request Forger) protection enforced by the `@fastify/csrf-protection` library, when combined with `@fastify/passport` in affected versions, can be bypassed by network and same-site attackers. `fastify/csrf-protection` implements the synchronizer token pattern (using plugins `@fastify/session` and `@fastify/secure-session`) by storing a random value used for CSRF token generation in the `_csrf` attribute of a user's session. The `@fastify/passport` library does not clear the session ob

CVE-2023-28761
NetWeaver Enterprise Portal Web
6.5
MEDIUM
EPSS
0.4%
2023 CWE-306 1 PoC

In SAP NetWeaver Enterprise Portal - version 7.50, an unauthenticated attacker can attach to an open interface and make use of an open API to access a service which will enable them to access or modify server settings and data, leading to limited impact on confidentiality and integrity.

CVE-2023-3720
Upload Media By URL Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The Upload Media By URL WordPress plugin before 1.0.8 does not have CSRF check when uploading files, which could allow attackers to make logged in admins upload files (including HTML containing JS code for users with the unfiltered_html capability) on their behalf.

CVE-2023-21909
Siebel UI Framework Web Database
6.5
MEDIUM
EPSS
0.5%
2023 1 PoC

Vulnerability in the Siebel CRM product of Oracle Siebel CRM (component: UI Framework). Supported versions that are affected are 23.3 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVE-2023-1331
Redirection Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The Redirection WordPress plugin before 1.1.5 does not have CSRF checks in the uninstall action, which could allow attackers to make logged in admins delete all the redirections through a CSRF attack.

CVE-2023-27073
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

A Cross-Site Request Forgery (CSRF) in Online Food Ordering System v1.0 allows attackers to change user details and credentials via a crafted POST request.

CVE-2023-1107
flatpressblog/flatpress Web
6.5
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2023-32750
Software Genérico Web
6.5
MEDIUM
EPSS
2.8%
2023 2 PoCs

Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The job "remote-download" can be used to cause the backend to send a HTTP GET request to a specified URL and save the response to a new file. The response file is then available in a user-specified folder in Pydio Cells.

CVE-2023-45826
leantime Web Database ⚡ nuclei
6.5
MEDIUM
EPSS
34.4%
2023 CWE-89 0 PoCs

Leantime is an open source project management system. A 'userId' variable in `app/domain/files/repositories/class.files.php` is not parameterized. An authenticated attacker can send a carefully crafted POST request to `/api/jsonrpc` to exploit an SQL injection vulnerability. Confidentiality is impacted as it allows for dumping information from the database. This issue has been addressed in version 2.4-beta-4. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2023-48780
WP Catalogue Web
6.5
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnigmaWeb WP Catalogue allows Stored XSS.This issue affects WP Catalogue: from n/a through 1.7.6.

CVE-2023-1524
Download Manager Web Windows
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user to download any file with the knowledge of any one file's password.

CVE-2023-23999
MonsterInsights Web
6.5
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in MonsterInsights plugin <= 8.14.0 versions.

CVE-2023-3508
WooCommerce Pre-Orders Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when processing its tab actions, which could allow attackers to make logged in admins email pre-orders customer, change the released date, mark all pre-orders of a specific product as complete or cancel via CSRF attacks

CVE-2023-6821
Error Log Viewer by BestWebSoft Web Windows
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

The Error Log Viewer by BestWebSoft WordPress plugin before 1.1.3 is affected by a Directory Listing issue, allowing users to read and download PHP logs without authorization

CVE-2023-2446
UserPro - Community and User Profile WordPress Plugin Web Windows
6.5
MEDIUM
EPSS
0.3%
2023 CWE-200 2 PoCs

The UserPro plugin for WordPress is vulnerable to sensitive information disclosure via the 'userpro' shortcode in versions up to, and including 5.1.1. This is due to insufficient restriction on sensitive user meta values that can be called via that shortcode. This makes it possible for authenticated attackers, with subscriber-level permissions, and above to retrieve sensitive user meta that can be used to gain access to a high privileged user account.

CVE-2023-21993
Clinical Remote Data Capture Option Web Database
6.5
MEDIUM
EPSS
0.5%
2023 1 PoC

Vulnerability in the Oracle Clinical Remote Data Capture product of Oracle Health Sciences Applications (component: Forms). The supported version that is affected is 5.4.0.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Clinical Remote Data Capture. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Clinical Remote Data Capture accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N

CVE-2023-4145
pimcore/customer-data-framework Web
6.5
MEDIUM
EPSS
0.0%
2023 CWE-79 4 PoCs

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/customer-data-framework prior to 3.4.2.

CVE-2023-0107
usememos/memos Web
6.5
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.