5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-48226
openreplay General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-20 1 PoC

OpenReplay is a self-hosted session replay suite. In version 1.14.0, due to lack of validation Name field - Account Settings (for registration looks like validation is correct), a bad actor can send emails with HTML injected code to the victims. Bad actors can use this to phishing actions for example. Email is really send from OpenReplay, but bad actors can add there HTML code injected (content spoofing). Please notice that during Registration steps for FullName looks like is validated correct - can not type there, but using this kind of bypass/workaround - bad actors can achieve own goal. As

CVE-2023-5907
File Manager Web Windows
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

The File Manager WordPress plugin before 6.3 does not restrict the file managers root directory, allowing an administrator to set a root outside of the WordPress root directory, giving access to system files and directories even in a multisite setup, where site administrators should not be allowed to modify the sites files.

CVE-2023-2193
Mattermost General
6.5
MEDIUM
EPSS
0.3%
2023 CWE-862 1 PoC

Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker possessing an authorization code to generate an access token.

CVE-2023-37031
Software Genérico Networking
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `eNB Configuration Transfer` packet missing its required `Target eNB ID` field.

CVE-2023-24124
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wrlEn parameter at /goform/WifiBasicSet.

CVE-2023-23999
MonsterInsights Web
6.5
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in MonsterInsights plugin <= 8.14.0 versions.

CVE-2023-4560
omeka/omeka-s General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-612 1 PoC

Improper Authorization of Index Containing Sensitive Information in GitHub repository omeka/omeka-s prior to 4.0.4.

CVE-2023-4145
pimcore/customer-data-framework Web
6.5
MEDIUM
EPSS
0.0%
2023 CWE-79 4 PoCs

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/customer-data-framework prior to 3.4.2.

CVE-2023-3507
WooCommerce Pre-Orders Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when canceling pre-orders, which could allow attackers to make logged in admins cancel arbitrary pre-orders via a CSRF attack

CVE-2023-0911
WordPress Shortcodes Plugin — Shortcodes Ultimate Web Windows
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to be retrieved via the user shortcode, allowing any authenticated users such as subscriber to retrieve arbitrary user meta (except the user_pass), such as the user email and activation key by default.

CVE-2023-6985
10Web AI Assistant – AI content writing assistant Web Windows
6.5
MEDIUM
EPSS
7.8%
2023 CWE-862 1 PoC

The 10Web AI Assistant – AI content writing assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the install_plugin AJAX action in all versions up to, and including, 1.0.18. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins that can be used to gain further access to a compromised site.

CVE-2023-0609
wallabag/wallabag General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-285 1 PoC

Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.

CVE-2023-22897
Software Genérico Networking ⚡ nuclei
6.5
MEDIUM
EPSS
88.9%
2023 3 PoCs

An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows information disclosure of memory contents to be achieved by an authenticated user. Essentially, uninitialized data can be retrieved via an approach in which a sessionid is obtained but not used.

CVE-2023-37030
Software Genérico Networking
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Initial UE Message` packet missing an expected `eNB_UE_S1AP_ID` field.

CVE-2023-2787
Mattermost Web
6.5
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary posts by using the message threads API.

CVE-2023-4455
wallabag/wallabag Web
6.5
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3.

CVE-2023-46673
Elasticsearch Web Database
6.5
MEDIUM
EPSS
0.5%
2023 CWE-755 1 PoC

It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.

CVE-2023-30456
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2023 2 PoCs

An issue was discovered in arch/x86/kvm/vmx/nested.c in the Linux kernel before 6.2.8. nVMX on x86_64 lacks consistency checks for CR0 and CR4.

CVE-2023-45231
edk2 General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-125 1 PoC

EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing  Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.

CVE-2023-2983
pimcore/pimcore General
6.5
MEDIUM
EPSS
0.0%
2023 CWE-267 1 PoC

Privilege Defined With Unsafe Actions in GitHub repository pimcore/pimcore prior to 10.5.23.