5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-1312
pimcore/pimcore Web
5.2
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.19.

CVE-2023-43074
Unity General
5.2
MEDIUM
EPSS
0.0%
2023 CWE-73 1 PoC

Dell Unity 5.3 contain(s) an Arbitrary File Creation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by crafting arbitrary files through a request to the server.

CVE-2023-24515
Pandora FMS Web
5.2
MEDIUM
EPSS
0.2%
2023 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) vulnerability in API checker of Pandora FMS. Application does not have a check on the URL scheme used while retrieving API URL. Rather than validating the http/https scheme, the application allows other scheme such as file, which could allow a malicious user to fetch internal file content. This issue affects Pandora FMS v767 version and prior versions on all platforms.

CVE-2023-1515
pimcore/pimcore Web
5.2
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.19.

CVE-2023-4157
omeka/omeka-s General
5.2
MEDIUM
EPSS
0.1%
2023 CWE-74 1 PoC

CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in GitHub repository omeka/omeka-s prior to version 4.0.3.

CVE-2023-2328
pimcore/pimcore Web
5.2
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-2343
pimcore/pimcore Web
5.2
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-28904
Volkswagen MIB3 infotainment system MIB3 OI MQB General
5.2
MEDIUM
EPSS
0.0%
2023 CWE-120 2 PoCs

A logic flaw leading to a RAM buffer overflow in the bootloader component of the MIB3 infotainment unit allows an attacker with physical access to the MIB3 ECU to bypass firmware signature verification and run arbitrary code in the infotainment system at boot process.

CVE-2023-3565
nilsteampassnet/teampass Web
5.2
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

CVE-2023-2322
pimcore/pimcore Web
5.2
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-54360
Joomla JLex Review Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the review_id URL parameter. Attackers can craft malicious links containing JavaScript payloads that execute in victims' browsers when clicked, enabling session hijacking or credential theft.

CVE-2023-1270
btcpayserver/btcpayserver Web
5.1
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting in GitHub repository btcpayserver/btcpayserver prior to 1.8.3.

CVE-2023-28042
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-53738
Xperience Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via page preview URLs. Attackers can exploit this vulnerability to execute arbitrary scripts in users' browsers during page preview interactions.

CVE-2023-53985
Zstore Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Zstore, now referred to as Zippy CRM, 6.5.4 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts through unvalidated input parameters. Attackers can submit crafted payloads in manual insertion points to execute arbitrary JavaScript code in victim's browser context.

CVE-2023-5686
radareorg/radare2 General
5.1
MEDIUM
EPSS
0.1%
2023 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.

CVE-2023-53906
projectSend Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

projectSend r1605 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript through the custom assets configuration page. Attackers can craft a JavaScript payload in the custom assets section that will execute when other users load the affected page, enabling persistent script injection.

CVE-2023-53910
WBCE CMS Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by inserting script tags into page content through the WYSIWYG editor. Attackers can submit POST requests to /wbce/modules/wysiwyg/save.php with malicious script content in the content parameter to execute JavaScript when users view the affected page.

CVE-2023-53939
TinyWebGallery Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

TinyWebGallery v2.5 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the folder name parameter. Attackers can edit album folder names with script tags to execute arbitrary JavaScript when other users view the affected gallery pages.

CVE-2023-28058
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.