5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-6311
Loan Management System Web Database
4.7
MEDIUM
EPSS
0.0%
2023 CWE-89 1 PoC

A vulnerability was found in SourceCodester Loan Management System 1.0 and classified as critical. This issue affects the function delete_ltype of the file delete_ltype.php of the component Loan Type Page. The manipulation of the argument ltype_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-246137 was assigned to this vulnerability.

CVE-2023-1756
thorsten/phpmyfaq Web
4.7
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2023-34020
Uncanny Toolkit for LearnDash General ⚡ nuclei
4.7
MEDIUM
EPSS
4.7%
2023 CWE-601 0 PoCs

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash.This issue affects Uncanny Toolkit for LearnDash: from n/a through 3.6.4.3.

CVE-2023-49971
Software Genérico Web
4.7
MEDIUM
EPSS
0.3%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter at /customer_support/index.php?page=customer_list.

CVE-2023-7176
Online College Library System Web Database
4.7
MEDIUM
EPSS
0.1%
2023 CWE-89 2 PoCs

A vulnerability classified as critical has been found in Campcodes Online College Library System 1.0. This affects an unknown part of the file /admin/return_add.php of the component HTTP POST Request Handler. The manipulation of the argument student leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249363.

CVE-2023-4650
instantsoft/icms2 Web
4.7
MEDIUM
EPSS
0.0%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

CVE-2023-0943
Best POS Management System Web
4.7
MEDIUM
EPSS
5.8%
2023 CWE-434 1 PoC

A vulnerability, which was classified as problematic, has been found in SourceCodester Best POS Management System 1.0. This issue affects the function save_settings of the file index.php?page=site_settings of the component Image Handler. The manipulation of the argument img with the input ../../shell.php leads to unrestricted upload. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-221591.

CVE-2023-34970
Valhall GPU Kernel Driver General
4.7
MEDIUM
EPSS
0.1%
2023 CWE-416 1 PoC

A local non-privileged user can make improper GPU processing operations to access a limited amount outside of buffer bounds or to exploit a software race condition. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory

CVE-2023-1442
QYKCMS Web
4.7
MEDIUM
EPSS
0.5%
2023 CWE-434 1 PoC

A vulnerability was found in Meizhou Qingyunke QYKCMS 4.3.0. It has been classified as problematic. This affects an unknown part of the file /admin_system/api.php of the component Update Handler. The manipulation of the argument downurl leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223287.

CVE-2023-3439
Linux Kernel (mctp) General
4.7
MEDIUM
EPSS
0.0%
2023 CWE-416 1 PoC

A flaw was found in the MCTP protocol in the Linux kernel. The function mctp_unregister() reclaims the device's relevant resource when a netcard detaches. However, a running routine may be unaware of this and cause the use-after-free of the mdev->addrs object, potentially leading to a denial of service.

CVE-2023-30720
Samsung Mobile Devices General
4.7
MEDIUM
EPSS
0.1%
2023 1 PoC

PendingIntent hijacking in LmsAssemblyTrackerCTC prior to SMR Sep-2023 Release 1 allows local attacker to gain arbitrary file access.

CVE-2023-1759
thorsten/phpmyfaq Web
4.7
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2023-42482
Software Genérico General
4.7
MEDIUM
EPSS
0.1%
2023 1 PoC

Samsung Mobile Processor Exynos 2200 allows a GPU Use After Free.

CVE-2023-33200
Bifrost GPU Kernel Driver General
4.7
MEDIUM
EPSS
0.1%
2023 CWE-416 1 PoC

A local non-privileged user can make improper GPU processing operations to exploit a software race condition. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory.

CVE-2023-25585
binutils General
4.7
MEDIUM
EPSS
0.0%
2023 CWE-457 1 PoC

A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.

CVE-2023-0913
Auto Dealer Management System Database
4.7
MEDIUM
EPSS
0.5%
2023 CWE-89 1 PoC

A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0. This vulnerability affects unknown code of the file /adms/admin/?page=vehicles/sell_vehicle. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-221482 is the identifier assigned to this vulnerability.

CVE-2023-29204
xwiki-platform Web ⚡ nuclei
4.7
MEDIUM
EPSS
1.0%
2023 CWE-601 0 PoCs

XWiki Commons are technical libraries common to several other top level XWiki projects. It is possible to bypass the existing security measures put in place to avoid open redirect by using a redirect such as `//mydomain.com` (i.e. omitting the `http:`). It was also possible to bypass it when using URL such as `http:/mydomain.com`. The problem has been patched on XWiki 13.10.10, 14.4.4 and 14.8RC1.

CVE-2023-2979
Pydio Cells General
4.7
MEDIUM
EPSS
0.0%
2023 CWE-284 1 PoC

A vulnerability classified as critical has been found in Abstrium Pydio Cells 4.2.0. This affects an unknown part of the component User Creation Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-230211.

CVE-2023-5339
Mattermost General
4.7
MEDIUM
EPSS
0.1%
2023 CWE-200 1 PoC

Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged. 

CVE-2023-7177
Online College Library System Web Database
4.7
MEDIUM
EPSS
0.0%
2023 CWE-89 1 PoC

A vulnerability classified as critical was found in Campcodes Online College Library System 1.0. This vulnerability affects unknown code of the file /admin/book_add.php of the component HTTP POST Request Handler. The manipulation of the argument category leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249364.