5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-40285
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

CVE-2023-4800
DoLogin Security Web Windows
6.5
MEDIUM
EPSS
8.9%
2023 2 PoCs

The DoLogin Security WordPress plugin before 3.7.1 does not restrict the access of a widget that shows the IPs of failed logins to low privileged users.

CVE-2023-47993
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

A Buffer out-of-bound read vulnerability in Exif.cpp::ReadInt32 in FreeImage 3.18.0 allows attackers to cause a denial-of-service.

CVE-2023-3172
froxlor/froxlor General
6.5
MEDIUM
EPSS
0.3%
2023 CWE-22 1 PoC

Path Traversal in GitHub repository froxlor/froxlor prior to 2.0.20.

CVE-2023-31187
IX Workforce Engagement General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-522 1 PoC

Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials

CVE-2023-24045
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2023 1 PoC

In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request.

CVE-2023-5214
Bolt General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-269 1 PoC

In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.

CVE-2023-27167
Software Genérico Database
6.5
MEDIUM
EPSS
0.6%
2023 2 PoCs

Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/absence?search_month=1.

CVE-2023-3423
cloudexplorer-dev/cloudexplorer-lite Cloud
6.5
MEDIUM
EPSS
0.1%
2023 CWE-521 1 PoC

Weak Password Requirements in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v 1.2.0.

CVE-2023-1147
flatpressblog/flatpress Web
6.5
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2023-47459
Software Genérico General
6.5
MEDIUM
EPSS
0.8%
2023 1 PoC

An issue in Knovos Discovery v.22.67.0 allows a remote attacker to obtain sensitive information via the /DiscoveryReview/Service/CaseManagement.svc/GetProductSiteName component.

CVE-2023-27035
Software Genérico General
6.5
MEDIUM
EPSS
26.3%
2023 3 PoCs

An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page.

CVE-2023-24528
Fiori apps 1.0 for travel management in SAP ERP (My Travel Requests) General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests) - version 600, allows an authenticated attacker to exploit a certain misconfigured application endpoint to view sensitive data. This endpoint is normally exposed over the network and successful exploitation can lead to exposure of data like travel documents.

CVE-2023-1092
OAuth Single Sign On Free Web Windows
6.5
MEDIUM
EPSS
0.2%
2023 4 PoCs

The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium WordPress plugin before 38.4.9 and OAuth Single Sign On Enterprise WordPress plugin before 48.4.9 do not have CSRF checks when deleting Identity Providers (IdP), which could allow attackers to make logged in admins delete arbitrary IdP via a CSRF attack

CVE-2023-51775
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

CVE-2023-6824
WP Customer Area Web Windows
6.5
MEDIUM
EPSS
0.5%
2023 1 PoC

The WP Customer Area WordPress plugin before 8.2.1 does not properly validates user capabilities in some of its AJAX actions, allowing any users to retrieve other user's account address.

CVE-2023-5195
Mattermost General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-863 1 PoC

Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of

CVE-2023-49339
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2023 1 PoC

Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/ssb/studentCard/retrieveData endpoint.

CVE-2023-20525
2nd Gen EPYC General
6.5
MEDIUM
EPSS
0.3%
2023 1 PoC

Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the bounds of a mapped register potentially leading to a denial of service.

CVE-2023-41705
OX App Suite General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-400 1 PoC

Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of DAV user-agents now gets monitored, and the related request is terminated if a resource threshold is reached. No publicly available exploits are known.