5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-50720
xwiki-platform General ⚡ nuclei
5.3
MEDIUM
EPSS
49.7%
2023 CWE-200 1 PoC

XWiki Platform is a generic wiki platform. Prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the email addresses of users even when obfuscation of email addresses is enabled. To demonstrate the vulnerability, search for `objcontent:email*` using XWiki's regular search interface. This has been fixed in XWiki 14.10.15, 15.5.2 and 15.7RC1 by not indexing email address properties when obfuscation is enabled. There are no known workarounds for this vulnerability.

CVE-2023-1007
Antivirus General
5.3
MEDIUM
EPSS
0.3%
2023 CWE-284 2 PoCs

A vulnerability was found in Twister Antivirus 8.17. It has been declared as critical. This vulnerability affects the function 0x801120E4 in the library filmfd.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-221740.

CVE-2023-1537
answerdev/answer General
5.3
MEDIUM
EPSS
0.3%
2023 CWE-294 1 PoC

Authentication Bypass by Capture-replay in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2023-4511
Wireshark General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-835 1 PoC

BT SDP dissector infinite loop in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture file

CVE-2023-47627
aiohttp Web
5.3
MEDIUM
EPSS
0.2%
2023 CWE-444 1 PoC

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser is only used when AIOHTTP_NO_EXTENSIONS is enabled (or not using a prebuilt wheel). These bugs have been addressed in commit `d5c12ba89` which has been included in release version 3.8.6. Users are advised to upgrade. There are no known workarounds for these issues.

CVE-2023-4227
ioLogik 4000 Series General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-489 1 PoC

A vulnerability has been identified in the ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which can be exploited by malicious actors to potentially gain unauthorized access to the product. This could lead to security breaches, data theft, and unauthorized manipulation of sensitive information. The vulnerability is attributed to the presence of an unauthorized service, which could potentially enable unauthorized access to the. device.

CVE-2023-6344
Court Case Management Plus General
5.3
MEDIUM
EPSS
1.6%
2023 CWE-287 1 PoC

Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate directories using the tiffserver/te003.aspx or te004.aspx 'ifolder' parameter. This behavior is related to the use of a deprecated version of Aquaforest TIFF Server, possibly 2.x. The vulnerable Aquaforest TIFF Server feature was removed on or around 2023-11-01. Insecure configuration issues in Aquaforest TIFF Server are identified separately as CVE-2023-6352. CVE-2023-6343 is related to or partially caused by CVE-2023-6352.

CVE-2023-5177
Vrm 360 3D Model Viewer Web Windows
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Vrm 360 3D Model Viewer WordPress plugin through 1.2.1 exposes the full path of a file when putting in a non-existent file in a parameter of the shortcode.

CVE-2023-1263
CMP – Coming Soon & Maintenance Plugin by NiteoThemes Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
22.9%
2023 CWE-200 0 PoCs

The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmp_get_post_detail function. This can allow unauthenticated individuals to obtain the contents of any non-password-protected, published post or page even when maintenance mode is enabled.

CVE-2023-45648
Apache Tomcat Web ⚡ nuclei
5.3
MEDIUM
EPSS
59.5%
2023 CWE-20 0 PoCs

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the

CVE-2023-47102
Software Genérico General
5.3
MEDIUM
EPSS
0.3%
2023 3 PoCs

UrBackup Server 2.5.31 allows brute-force enumeration of user accounts because a failure message confirms that a username is not valid.

CVE-2023-2299
Online Booking & Scheduling Calendar for WordPress by vcita Web Windows
5.3
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized medication of data via the /wp-json/vcita-wordpress/v1/actions/auth REST-API endpoint in versions up to, and including, 4.4.2 due to a missing capability check on the processAction function. This makes it possible for unauthenticated attackers modify the plugin's settings.

CVE-2023-53893
TITAN Web
5.3
MEDIUM
EPSS
0.1%
2023 CWE-918 2 PoCs

Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL parameter that allows attackers to bypass network restrictions. Attackers can exploit the unvalidated parameter to initiate file, service, and network enumeration by forcing the application to make HTTP, DNS, or file requests to arbitrary destinations.

CVE-2023-36844
🔥 KEV Junos OS Web Networking ⚡ nuclei
5.3
MEDIUM
EPSS
94.3%
2023 CWE-473 6 PoCs

A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on EX Series: * All versions prior to 20.4R3-S9; * 21.1 versions 21.1R1 and later; * 21.2 versions prior to 21.2R3-S7; * 21.3 versions prior to 21.3R3

CVE-2023-47529
Cloud Templates & Patterns collection Cloud
5.3
MEDIUM
EPSS
3.4%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ThemeIsle Cloud Templates & Patterns collection.This issue affects Cloud Templates & Patterns collection: from n/a through 1.2.2.

CVE-2023-37012
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial UE Message` message missing a required `PLMN Identity` field to repeatedly crash the MME, resulting in denial of service.

CVE-2023-31405
SAP NetWeaver AS for Java (Log Viewer) Web
5.3
MEDIUM
EPSS
0.3%
2023 CWE-117 1 PoC

SAP NetWeaver AS for Java - versions ENGINEAPI 7.50, SERVERCORE 7.50, J2EE-APPS 7.50, allows an unauthenticated attacker to craft a request over the network which can result in unwarranted modifications to a system log without user interaction. There is no ability to view any information or any effect on availability.

CVE-2023-39983
MXsecurity Series Database
5.3
MEDIUM
EPSS
0.4%
2023 CWE-915 1 PoC

A vulnerability that poses a potential risk of polluting the MXsecurity sqlite database and the nsm-web UI has been identified in MXsecurity versions prior to v1.0.1. This vulnerability might allow an unauthenticated remote attacker to register or add devices via the nsm-web application.

CVE-2023-1258
Flow-X General
5.3
MEDIUM
EPSS
13.2%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.