5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-0749
Ocean Extra Web Windows
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually a template, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, such as draft, private or even password protected ones.

CVE-2023-45826
leantime Web Database ⚡ nuclei
6.5
MEDIUM
EPSS
34.4%
2023 CWE-89 0 PoCs

Leantime is an open source project management system. A 'userId' variable in `app/domain/files/repositories/class.files.php` is not parameterized. An authenticated attacker can send a carefully crafted POST request to `/api/jsonrpc` to exploit an SQL injection vulnerability. Confidentiality is impacted as it allows for dumping information from the database. This issue has been addressed in version 2.4-beta-4. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2023-23855
Solution Manager General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-601 1 PoC

SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insufficient URL validation. A successful attack could lead an attacker to read or modify the information or expose the user to a phishing attack. As a result, it has a low impact to confidentiality, integrity and availability.

CVE-2023-4198
Dolibarr ERP CRM General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database table containing customer data

CVE-2023-6277
Red Hat Enterprise Linux 6 Web
6.5
MEDIUM
EPSS
3.8%
2023 CWE-400 5 PoCs

An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.

CVE-2023-0107
usememos/memos Web
6.5
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

CVE-2023-36761
🔥 KEV Microsoft Office 2019 General
6.5
MEDIUM
EPSS
5.5%
2023 CWE-20 1 PoC

Microsoft Word Information Disclosure Vulnerability

CVE-2023-24524
S/4 HANA (Map Treasury Correspondence Format Data) General
6.5
MEDIUM
EPSS
0.3%
2023 CWE-862 1 PoC

SAP S/4 HANA Map Treasury Correspondence Format Data does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to delete the data with a high impact to availability.

CVE-2023-5571
vriteio/vrite General
6.5
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Improper Input Validation in GitHub repository vriteio/vrite prior to 0.3.0.

CVE-2023-3338
kernel General
6.5
MEDIUM
EPSS
7.7%
2023 CWE-476 2 PoCs

A null pointer dereference flaw was found in the Linux kernel's DECnet networking protocol. This issue could allow a remote user to crash the system.

CVE-2023-4640
Anywhere General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

The controller responsible for setting the logging level does not include any authorization checks to ensure the user is authenticated. This can be seen by noting that it extends Controller rather than AuthenticatedController and includes no further checks. This issue affects YugabyteDB Anywhere: from 2.0.0 through 2.17.3

CVE-2023-7201
Everest Backup Web Windows
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

The Everest Backup WordPress plugin before 2.2.5 does not properly validate backup files to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

CVE-2023-25741
Firefox General
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused web compatibility problems as well as this security concern, so the behavior was disabled until further review. This vulnerability affects Firefox < 110.

CVE-2023-27636
Software Genérico Web
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.

CVE-2023-6139
Essential Real Estate Web Windows
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Denial of Service attacks.

CVE-2023-0025
Solution Manager (BSP Application) General
6.5
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information or craft a payload which may restrict access to the desired resources.

CVE-2023-42578
Samsung Data Store General
6.5
MEDIUM
EPSS
0.3%
2023 1 PoC

Improper handling of insufficient permissions or privileges vulnerability in Samsung Data Store prior to version 5.2.00.7 allows remote attackers to access location information without permission.

CVE-2023-7268
ArtPlacer Widget Web Windows
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated users, such as subscriber, to delete arbitrary widgets

CVE-2023-45229
edk2 General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-125 1 PoC

EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.

CVE-2023-2650
OpenSSL Web
6.5
MEDIUM
EPSS
92.1%
2023 1 PoC

Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Impact summary: Applications that use OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit may experience notable to very long delays when processing those messages, which may lead to a Denial of Service. An OBJECT IDENTIFIER is composed of a series of numbers - sub-identifiers - most of which have no size limit. OBJ_obj2txt() may be used to translate an ASN.1 OBJECT IDENTIFIER given in DER encoding form