5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-7114
Mattermost Web
7.1
HIGH
EPSS
0.3%
2023 CWE-74 1 PoC

Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.

CVE-2023-39980
MXsecurity Series Database
7.1
HIGH
EPSS
0.4%
2023 CWE-89 1 PoC

A vulnerability that allows the unauthorized disclosure of authenticated information has been identified in MXsecurity versions prior to v1.0.1. This vulnerability arises when special elements are not neutralized correctly, allowing remote attackers to alter SQL commands.

CVE-2023-5555
frappe/lms Web
7.1
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository frappe/lms prior to 5614a6203fb7d438be8e2b1e3030e4528d170ec4.

CVE-2023-41111
Software Genérico General
7.1
HIGH
EPSS
0.3%
2023 1 PoC

An issue was discovered in Samsung Mobile Processor, Wearable Processor, Automotive Processor, and Modem (Exynos 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, W920, Modem 5123, Modem 5300, and Auto T5123). Improper handling of a length parameter inconsistency can cause abnormal termination of a mobile phone. This occurs in the RLC task and RLC module.

CVE-2023-29745
Software Genérico General
7.1
HIGH
EPSS
0.1%
2023 1 PoC

An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database.

CVE-2023-22710
Return and Warranty Management System for WooCommerce Web
7.1
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in chilidevs Return and Warranty Management System for WooCommerce plugin <= 1.2.3 versions.

CVE-2023-2239
microweber/microweber General
7.1
HIGH
EPSS
0.3%
2023 CWE-359 1 PoC

Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository microweber/microweber prior to 1.3.4.

CVE-2023-35918
Bulk Stock Management Web
7.1
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Bulk Stock Management plugin <= 2.2.33 versions.

CVE-2023-30489
Email Subscription Popup Web
7.1
HIGH
EPSS
0.5%
2023 CWE-79 1 PoC

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Email Subscription Popup plugin <= 1.2.16 versions.

CVE-2023-53775
Screen SFT DAB Series - Compact Radio DAB Transmitter Web
7.1
HIGH
EPSS
0.2%
2023 CWE-384 2 PoCs

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change user passwords by exploiting weak session management controls. Attackers can reuse IP-bound session identifiers to issue unauthorized requests to the userManager API and modify user credentials without proper authentication.

CVE-2023-47115
label-studio Web ⚡ nuclei
7.1
HIGH
EPSS
3.2%
2023 CWE-79 0 PoCs

Label Studio is an a popular open source data labeling tool. Versions prior to 1.9.2 have a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. Executing arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. The file `users/fu

CVE-2023-27647
Software Genérico General
7.1
HIGH
EPSS
0.1%
2023 1 PoC

An issue found in DUALSPACE Lock Master v.2.2.4 allows a local attacker to cause a denial of service or gain sensitive information via the com.ludashi.superlock.util.pref.SharedPrefProviderEntryMethod: insert of the android.net.Uri.insert method.

CVE-2023-27264
Mattermost Web
7.1
HIGH
EPSS
0.1%
2023 CWE-862 1 PoC

A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks/[playbookID] API.

CVE-2023-53901
WBCE CMS Web
7.1
HIGH
EPSS
0.1%
2023 CWE-601 1 PoC

WBCE CMS 1.6.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML and CSS to capture user keystrokes. Attackers can upload a crafted HTML file with CSS-based keylogging techniques to intercept password characters through background image requests.

CVE-2023-32327
Security Verify Access Appliance DevOps
7.1
HIGH
EPSS
0.0%
2023 CWE-611 1 PoC

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 254783.

CVE-2023-5689
modoboa/modoboa Web
7.1
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository modoboa/modoboa prior to 2.2.2.

CVE-2023-20587
3rd Gen AMD EPYC™ Processors General
7.1
HIGH
EPSS
0.0%
2023 1 PoC

Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code execution.

CVE-2023-28344
Software Genérico Web Windows
7.1
HIGH
EPSS
0.1%
2023 2 PoCs

An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers to view constantly updated screenshots of student desktops and to submit falsified screenshots on behalf of students. Attackers are able to view screenshots of student desktops without their consent. These screenshots may potentially contain sensitive/personal data. Attackers can also rapidly submit falsified images, hiding the actual contents of student desktops from the Teacher Console.

CVE-2023-6279
Woostify Sites Library Web Windows
7.1
HIGH
EPSS
0.1%
2023 1 PoC

The Woostify Sites Library WordPress plugin before 1.4.8 does not have authorisation in an AJAX action, allowing any authenticated users, such as subscriber to update arbitrary blog options and set them to 'activated' which could lead to DoS when using a specific option name

CVE-2023-21489
Samsung Mobile Devices General
7.1
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

Heap out-of-bounds write vulnerability in bootloader prior to SMR May-2023 Release 1 allows a physical attacker to execute arbitrary code.