5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-2926
SeaCMS Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability was found in SeaCMS 11.6 and classified as problematic. This issue affects some unknown processing of the file member.php of the component Picture Upload Handler. The manipulation of the argument oldpic leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-230081 was assigned to this vulnerability.

CVE-2023-43714
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "SKIP_CART_PAGE_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-0434
pyload/pyload General
5.4
MEDIUM
EPSS
0.5%
2023 CWE-20 1 PoC

Improper Input Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev40.

CVE-2023-0078
Resume Builder Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Resume Builder WordPress plugin through 3.1.1 does not sanitize and escape some parameters related to Resume, which could allow users with a role as low as subscriber to perform Stored XSS attacks against higher privilege users

CVE-2023-6379
Open CMS Web ⚡ nuclei
5.4
MEDIUM
EPSS
18.6%
2023 CWE-79 0 PoCs

Cross-site scripting (XSS) vulnerability in Alkacon Software Open CMS, affecting versions 14 and 15 of the 'Mercury' template. This vulnerability could allow a remote attacker to send a specially crafted JavaScript payload to a victim and partially take control of their browsing session.

CVE-2023-2105
alextselegidis/easyappointments General
5.4
MEDIUM
EPSS
0.8%
2023 CWE-384 1 PoC

Session Fixation in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

CVE-2023-43735
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "formats_titles[7]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-0176
Giveaways and Contests by RafflePress Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Giveaways and Contests by RafflePress WordPress plugin before 1.11.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-4821
Drag and Drop Multiple File Upload for WooCommerce Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dangerous file extensions. Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts.

CVE-2023-21861
Business Intelligence Enterprise Edition Web Database
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Visual Analyzer). Supported versions that are affected are 5.9.0.0.0 and 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Succe

CVE-2023-30789
MonicaHQ General
5.4
MEDIUM
EPSS
0.6%
2023 1 PoC

MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/work` endpoint and job and company parameter.

CVE-2023-0536
Wp-D3 Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The Wp-D3 WordPress plugin through 2.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0395
menu shortcode Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The menu shortcode WordPress plugin through 1.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-43720
Os Commerce Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "BILLING_GENDER_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

CVE-2023-4823
WP Meta and Date Remover Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings. This endpoint has no capability checks and does not sanitize the user input, which is then later output unescaped. Allowing any authenticated users, such as subscriber change them and perform Stored Cross-Site Scripting.

CVE-2023-2000
Mattermost General
5.4
MEDIUM
EPSS
0.1%
2023 CWE-601 1 PoC

Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website

CVE-2023-0177
Social Like Box and Page by WpDevArt Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Social Like Box and Page by WpDevArt WordPress plugin before 0.8.41 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-6082
chartjs Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2023-21427
Samsung Mobile Devices General
5.4
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control vulnerability in NfcTile prior to SMR Jan-2023 Release 1 allows to attacker to use NFC without user recognition.

CVE-2023-0171
jQuery T(-) Countdown Widget Web Windows
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

The jQuery T(-) Countdown Widget WordPress plugin before 2.3.24 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.