5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-30678
Calendar General
5.1
MEDIUM
EPSS
0.1%
2023 1 PoC

Potential zip path traversal vulnerability in Calendar application prior to version 12.4.07.15 in Android 13 allows attackers to write arbitrary file.

CVE-2023-21424
Samsung Mobile Devices General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-285 1 PoC

Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Release 1 allows attacker to modify network related values, network code, carrier id and operator brand.

CVE-2023-54358
WordPress adivaha Travel Plugin Web Windows
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the isMobile parameter. Attackers can craft malicious URLs containing JavaScript payloads in the isMobile GET parameter at the /mobile-app/v3/ endpoint to execute arbitrary code in victims' browsers and steal session tokens or credentials.

CVE-2023-5595
gpac/gpac General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-400 1 PoC

Denial of Service in GitHub repository gpac/gpac prior to 2.3.0-DEV.

CVE-2023-53976
myBB forums Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the template management system that allows authenticated administrators to inject malicious scripts when creating new templates. Attackers can exploit this vulnerability by inserting script payloads in the template title field when adding new templates through the 'Templates and Style' > 'Templates' > 'Manage Templates' > 'Global Templates' interface, causing arbitrary JavaScript to execute when the template is viewed.

CVE-2023-49031
Software Genérico General
5.1
MEDIUM
EPSS
0.1%
2023 1 PoC

Directory Traversal (Local File Inclusion) vulnerability in Tikit (now Advanced) eMarketing platform 6.8.3.0 allows a remote attacker to read arbitrary files and obtain sensitive information via a crafted payload to the filename parameter to the OpenLogFile endpoint.

CVE-2023-28026
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-53899
Software Genérico Web
5.1
MEDIUM
EPSS
0.2%
2023 CWE-918 1 PoC

PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Attackers can manipulate the 'shortdesc' parameter to trigger external HTTP requests to arbitrary endpoints during podcast episode creation.

CVE-2023-53909
WBCE CMS Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by uploading crafted SVG files through the media manager. Attackers can upload SVG files containing script tags to the /wbce/modules/elfinder/ef/php/connector.wbce.php endpoint and execute JavaScript when victims access the uploaded file.

CVE-2023-53898
Rukovoditel Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert iframe and script payloads in application copyright text to execute arbitrary JavaScript in victim browsers.

CVE-2023-5321
hamza417/inure General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-862 1 PoC

Missing Authorization in GitHub repository hamza417/inure prior to build94.

CVE-2023-54361
Joomla iProperty Real Estate Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the filter_keyword parameter. Attackers can craft URLs containing JavaScript payloads in the filter_keyword GET parameter of the all-properties-with-map endpoint to execute arbitrary code in victim browsers and steal session tokens or credentials.

CVE-2023-53882
JLex GuestBook Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

JLex GuestBook 1.6.4 contains a reflected cross-site scripting vulnerability in the 'q' URL parameter that allows attackers to inject malicious scripts. Attackers can craft malicious links with XSS payloads to steal session tokens or execute arbitrary JavaScript in victims' browsers.

CVE-2023-28032
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-53953
WebsiteBaker Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts when creating web pages. Attackers can craft malicious payloads in page titles that execute arbitrary JavaScript when the page is viewed by other users.

CVE-2023-4678
gpac/gpac General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-369 1 PoC

Divide By Zero in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-0679
Canteen Management System Web Database
5.0
MEDIUM
EPSS
0.3%
2023 CWE-89 1 PoC

A vulnerability was found in SourceCodester Canteen Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file removeUser.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220220.

CVE-2023-1183
libreoffice General
5.0
MEDIUM
EPSS
7.3%
2023 CWE-20 3 PoCs

A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.

CVE-2023-5244
microweber/microweber Web ⚡ nuclei
5.0
MEDIUM
EPSS
28.9%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 2.0.

CVE-2023-30952
com.palantir.foundry:foundry-frontend General
5.0
MEDIUM
EPSS
0.3%
2023 CWE-20 1 PoC

A security defect was discovered in Foundry Issues that enabled users to create convincing phishing links by editing the request sent when creating an Issue. This defect was resolved in Frontend release 6.228.0 .