5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-26841
Software Genérico Web
6.5
MEDIUM
EPSS
1.1%
2023 1 PoC

A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to change any user's password except for the user that is currently logged in.

CVE-2023-28488
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

client.c in gdhcp in ConnMan through 1.41 could be used by network-adjacent attackers (operating a crafted DHCP server) to cause a stack-based buffer overflow and denial of service, terminating the connman process.

CVE-2023-33409
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Minical 1.0.0 is vulnerable to Cross Site Request Forgery (CSRF) via minical/public/application/controllers/settings/company.php.

CVE-2023-1426
WP Tiles Web Windows
6.5
MEDIUM
EPSS
0.5%
2023 1 PoC

The WP Tiles WordPress plugin through 1.1.2 does not ensure that posts to be displayed are not draft/private, allowing any authenticated users, such as subscriber to retrieve the titles of draft and privates posts for example. AN attacker could also retrieve the title of any other type of post.

CVE-2023-23466
Media Control Panel General
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

Media CP Media Control Panel latest version. Insufficiently protected credential change.

CVE-2023-42755
Red Hat Enterprise Linux 8 General
6.5
MEDIUM
EPSS
0.0%
2023 CWE-125 1 PoC

A flaw was found in the IPv4 Resource Reservation Protocol (RSVP) classifier in the Linux kernel. The xprt pointer may go beyond the linear part of the skb, leading to an out-of-bounds read in the `rsvp_classify` function. This issue may allow a local user to crash the system and cause a denial of service.

CVE-2023-7286
ACF Quick Edit Fields Web Windows
6.5
MEDIUM
EPSS
1.0%
2023 CWE-639 1 PoC

The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.2.2. This makes it possible for attackers without the edit_users capability to access metadata of other users, this includes contributor-level users and above.

CVE-2023-30950
com.palantir.campaigns:campaigns General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-290 1 PoC

The foundry campaigns service was found to be vulnerable to an unauthenticated information disclosure in a rest endpoint

CVE-2023-6199
BookStack General
6.5
MEDIUM
EPSS
13.4%
2023 CWE-918 2 PoCs

Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.

CVE-2023-26142
Crow Web
6.5
MEDIUM
EPSS
0.2%
2023 CWE-113 1 PoC

All versions of the package crow are vulnerable to HTTP Response Splitting when untrusted user input is used to build header values. Header values are not properly sanitized against CRLF Injection in the set_header and add_header functions. An attacker can add the \r\n (carriage return line feeds) characters to end the HTTP response headers and inject malicious content.

CVE-2023-26150
asyncua General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-287 1 PoC

Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space without encryption and authentication. **Note:** This issue is a result of missing checks for services that require an active session.

CVE-2023-26428
OX App Suite General
6.5
MEDIUM
EPSS
0.3%
2023 CWE-639 1 PoC

Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same context. Signatures of other users could be read even though they are not explicitly shared. We improved permission handling when requesting snippets that are not explicitly shared with other users. No publicly available exploits are known.

CVE-2023-6640
PC Controller General
6.5
MEDIUM
EPSS
0.0%
2023 CWE-248 1 PoC

Malformed S2 Nonce Get Command Class packets can be sent to crash PC Controller v5.54.0 and earlier.

CVE-2023-29020
fastify-passport Web
6.5
MEDIUM
EPSS
0.1%
2023 CWE-384 2 PoCs

@fastify/passport is a port of passport authentication library for the Fastify ecosystem. The CSRF (Cross-Site Request Forger) protection enforced by the `@fastify/csrf-protection` library, when combined with `@fastify/passport` in affected versions, can be bypassed by network and same-site attackers. `fastify/csrf-protection` implements the synchronizer token pattern (using plugins `@fastify/session` and `@fastify/secure-session`) by storing a random value used for CSRF token generation in the `_csrf` attribute of a user's session. The `@fastify/passport` library does not clear the session ob

CVE-2023-1331
Redirection Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The Redirection WordPress plugin before 1.1.5 does not have CSRF checks in the uninstall action, which could allow attackers to make logged in admins delete all the redirections through a CSRF attack.

CVE-2023-32615
OAS Platform General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-73 1 PoC

A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary file creation or overwrite. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-1107
flatpressblog/flatpress Web
6.5
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2023-37033
Software Genérico Networking
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Initial UE Message` packet missing an expected `EUTRAN_CGI` field.

CVE-2023-48780
WP Catalogue Web
6.5
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnigmaWeb WP Catalogue allows Stored XSS.This issue affects WP Catalogue: from n/a through 1.7.6.

CVE-2023-6119
GetSusp General
6.5
MEDIUM
EPSS
0.0%
2023 CWE-269 1 PoC

An Improper Privilege Management vulnerability in Trellix GetSusp prior to version 5.0.0.27 allows a local, low privilege attacker to gain access to files that usually require a higher privilege level. This is caused by GetSusp not correctly protecting a directory that it creates during execution, allowing an attacker to take over file handles used by GetSusp. As this runs with high privileges, the attacker gains elevated permissions. The file handles are opened as read-only.