5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-24118
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the security parameter at /goform/WifiBasicSet.

CVE-2023-22941
Splunk Enterprise General
6.5
MEDIUM
EPSS
1.1%
2023 CWE-248 1 PoC

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, an improperly-formatted ‘INGEST_EVAL’ parameter in a Field Transformation crashes the Splunk daemon (splunkd).

CVE-2023-47171
AVideo Web
6.5
MEDIUM
EPSS
0.3%
2023 CWE-73 2 PoCs

An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.

CVE-2023-34317
OAS Platform General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-20 1 PoC

An improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to unexpected data in the configuration. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-47504
Elementor Website Builder General
6.5
MEDIUM
EPSS
7.1%
2023 CWE-287 1 PoC

Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Builder: from n/a through 3.16.4.

CVE-2023-0501
WP Insurance Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Insurance WordPress plugin before 2.1.4 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-51071
Software Genérico Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily disable the SMB service on a victim's Qstar instance by executing a specific command in a link.

CVE-2023-41474
Software Genérico General
6.5
MEDIUM
EPSS
74.9%
2023 1 PoC

Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.faces.resource component.

CVE-2023-23396
Microsoft Office Online Server General
6.5
MEDIUM
EPSS
8.2%
2023 CWE-400 1 PoC

Microsoft Excel Denial of Service Vulnerability

CVE-2023-46701
Mattermost Web
6.5
MEDIUM
EPSS
0.2%
2023 CWE-200 1 PoC

Mattermost fails to perform authorization checks in the /plugins/playbooks/api/v0/runs/add-to-timeline-dialog endpoint of the Playbooks plugin allowing an attacker to get limited information about a post if they know the post ID

CVE-2023-4127
answerdev/answer General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-366 1 PoC

Race Condition within a Thread in GitHub repository answerdev/answer prior to v1.1.1.

CVE-2023-6568
mlflow/mlflow Web ⚡ nuclei
6.5
MEDIUM
EPSS
33.4%
2023 CWE-79 1 PoC

A reflected Cross-Site Scripting (XSS) vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the Content-Type header in POST requests. An attacker can inject malicious JavaScript code into the Content-Type header, which is then improperly reflected back to the user without adequate sanitization or escaping, leading to arbitrary JavaScript execution in the context of the victim's browser. The vulnerability is present in the mlflow/server/auth/__init__.py file, where the user-supplied Content-Type header is directly injected into a Python formatted string and

CVE-2023-3508
WooCommerce Pre-Orders Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when processing its tab actions, which could allow attackers to make logged in admins email pre-orders customer, change the released date, mark all pre-orders of a specific product as complete or cancel via CSRF attacks

CVE-2023-6129
OpenSSL General
6.5
MEDIUM
EPSS
3.3%
2023 CWE-440 1 PoC

Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications running on PowerPC CPU based platforms if the CPU provides vector instructions. Impact summary: If an attacker can influence whether the POLY1305 MAC algorithm is used, the application state might be corrupted with various application dependent consequences. The POLY1305 MAC (message authentication code) implementation in OpenSSL for PowerPC CPUs restores the contents of vector registers in a different order than they are saved. Thus the contents o

CVE-2023-42508
Artifactory General
6.5
MEDIUM
EPSS
0.4%
2023 CWE-20 1 PoC

JFrog Artifactory prior to version 7.66.0 is vulnerable to specific endpoint abuse with a specially crafted payload, which can lead to unauthenticated users being able to send emails with manipulated email body.

CVE-2023-28746
Intel(R) Atom(R) Processors General
6.5
MEDIUM
EPSS
0.0%
2023 1 PoC

Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2023-3711
PM23/43 General
6.4
MEDIUM
EPSS
0.1%
2023 CWE-384 2 PoCs

Session Fixation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Session Credential Falsification through Prediction.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).

CVE-2023-5774
Animated Counters Web Windows
6.4
MEDIUM
EPSS
0.1%
2023 CWE-79 3 PoCs

The Animated Counters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2023-33984
SAP NetWeaver (Design Time Repository) Web
6.4
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

SAP NetWeaver (Design Time Repository) - version 7.50, returns an unfavorable content type for some versioned files, which could allow an authorized attacker to create a file with a malicious content and send a link to a victim in an email or instant message. Under certain circumstances, this could lead to Cross-Site Scripting vulnerability.

CVE-2023-2404
CRM and Lead Management by vcita Web Windows
6.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 2.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with the edit_posts capability, such as contributors and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.