5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-3914
GitLab DevOps
5.4
MEDIUM
EPSS
0.0%
2023 CWE-286 1 PoC

A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.

CVE-2023-29983
Software Genérico General
5.4
MEDIUM
EPSS
40.8%
2023 3 PoCs

Cross Site Scripting vulnerability found in Maximilian Vogt cmaps v.8.0 allows a remote attacker to execute arbitrary code via the auditlog tab in the admin panel.

CVE-2023-24724
Software Genérico Web
5.4
MEDIUM
EPSS
0.8%
2023 1 PoC

A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insufficient validation and sanitization of data input into the user creation and editing form fields. The product name is SAS Web Administration interface (SASAdmin). For the product release, the reported version is 9.4_M2 and the fixed version is 9.4_M3. For the SAS release, the reported version is 9.4 TS1M2 and the fixed version is 9.4 TS1M3.

CVE-2023-7085
Scalable Vector Graphics (SVG) Web Windows
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

The Scalable Vector Graphics (SVG) WordPress plugin through 3.4 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

CVE-2023-0405
GPT AI Power: Content Writer & ChatGPT & Image Generator & WooCommerce Product Writer & AI Training Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The GPT AI Power: Content Writer & ChatGPT & Image Generator & WooCommerce Product Writer & AI Training WordPress plugin before 1.4.38 does not perform any kind of nonce or privilege checks before letting logged-in users modify arbitrary posts.

CVE-2023-1265
GitLab DevOps
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance.

CVE-2023-25347
Software Genérico Web
5.4
MEDIUM
EPSS
0.4%
2023 1 PoC

A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web script or HTML via input fields. These input fields are located in the "Title" Input Field in EventEditor.php.

CVE-2023-3115
GitLab DevOps
5.4
MEDIUM
EPSS
0.0%
2023 CWE-286 1 PoC

An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On restrictions were not correctly enforced for indirect project members accessing public members-only project repositories.

CVE-2023-0823
Cookie Notice & Compliance for GDPR / CCPA Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The Cookie Notice & Compliance for GDPR / CCPA WordPress plugin before 2.4.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2023-0062
EAN for WooCommerce Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The EAN for WooCommerce WordPress plugin before 4.4.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0589
WP Image Carousel Web Windows
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

The WP Image Carousel WordPress plugin through 1.0.2 does not sanitise and escape some parameters, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.

CVE-2023-24505
NCR/Camera General
5.3
MEDIUM
EPSS
0.3%
2023 CWE-200 1 PoC

Milesight NCR/camera version 71.8.0.6-r5 discloses sensitive information through an unspecified request.

CVE-2023-21943
Hyperion Essbase Web Database
5.3
MEDIUM
EPSS
0.5%
2023 1 PoC

Vulnerability in Oracle Essbase (component: Security and Provisioning). The supported version that is affected is 21.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Essbase. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Essbase accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).

CVE-2023-1629
Antivirus General
5.3
MEDIUM
EPSS
0.3%
2023 CWE-119 2 PoCs

A vulnerability classified as critical was found in JiangMin Antivirus 16.2.2022.418. Affected by this vulnerability is the function 0x222010 in the library kvcore.sys of the component IOCTL Handler. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224011.

CVE-2023-1539
answerdev/answer General
5.3
MEDIUM
EPSS
0.4%
2023 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2023-21479
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper authorization in Smart suggestions prior to SMR Apr-2023 Release 1 in Android 13 and 4.1.01.0 in Android 12 allows remote attackers to register a schedule.

CVE-2023-31194
Diagon Web
5.3
MEDIUM
EPSS
0.1%
2023 CWE-119 2 PoCs

An improper array index validation vulnerability exists in the GraphPlanar::Write functionality of Diagon v1.0.139. A specially crafted markdown file can lead to memory corruption. A victim would need to open a malicious file to trigger this vulnerability.

CVE-2023-53879
NVClient General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-121 2 PoCs

NVClient 5.0 contains a stack buffer overflow vulnerability in the user configuration contact field that allows attackers to crash the application. Attackers can overwrite 846 bytes of memory by pasting a crafted payload into the contact box, causing a denial of service condition.

CVE-2023-1176
mlflow/mlflow General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-36 1 PoC

Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.2.2.

CVE-2023-7216
Red Hat Enterprise Linux 6 General
5.3
MEDIUM
EPSS
0.3%
2023 CWE-59 1 PoC

A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory, which allows files to be written in arbitrary directories through symlinks.