5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-4112
Shuttle Booking Software Web ⚡ nuclei
4.3
MEDIUM
EPSS
15.1%
2023 CWE-79 1 PoC

A vulnerability was found in PHP Jabbers Shuttle Booking Software 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-235959. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-3707
ActivityPub Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The ActivityPub WordPress plugin before 1.0.0 does not ensure that post contents to be displayed are public and belong to the plugin, allowing any authenticated user, such as subscriber to retrieve the content of arbitrary post (such as draft and private) via an IDOR vector. Password protected posts are not affected by this issue.

CVE-2023-5333
Mattermost Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sending a specially crafted request to /api/v4/users/ids with multiple identical IDs.

CVE-2023-30534
cacti Web ⚡ nuclei
4.3
MEDIUM
EPSS
54.9%
2023 CWE-502 0 PoCs

Cacti is an open source operational monitoring and fault management framework. There are two instances of insecure deserialization in Cacti version 1.2.24. While a viable gadget chain exists in Cacti’s vendor directory (phpseclib), the necessary gadgets are not included, making them inaccessible and the insecure deserializations not exploitable. Each instance of insecure deserialization is due to using the unserialize function without sanitizing the user input. Cacti has a “safe” deserialization that attempts to sanitize the content and check for specific values before calling unserialize, but

CVE-2023-5546
Software Genérico Web
4.3
MEDIUM
EPSS
1.8%
2023 CWE-79 1 PoC

ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.

CVE-2023-26839
Software Genérico Web
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to edit information for existing people on the site.

CVE-2023-3601
Simple Author Box Web Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The Simple Author Box WordPress plugin before 2.52 does not verify a user ID before outputting information about that user, leading to arbitrary user information disclosure to users with a role as low as Contributor.

CVE-2023-4836
WordPress File Sharing Plugin Web Windows
4.3
MEDIUM
EPSS
0.3%
2023 2 PoCs

The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and folders, allowing users to gain access to those filed by manipulating IDs which can easily be brute forced

CVE-2023-1158
Pentaho Business Analytics Server General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-863 1 PoC

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x expose dashboard prompts to users who are not part of the authorization list. 

CVE-2023-6741
WP Customer Area Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Customer Area WordPress plugin before 8.2.1 does not properly validate users capabilities in some of its AJAX actions, allowing malicious users to edit other users' account address.

CVE-2023-46442
Software Genérico General
4.3
MEDIUM
EPSS
2.9%
2023 2 PoCs

An infinite loop in the retrieveActiveBody function of Soot before v4.4.1 under Java 8 allows attackers to cause a Denial of Service (DoS).

CVE-2023-39205
Zoom Clients General
4.3
MEDIUM
EPSS
0.3%
2023 CWE-754 1 PoC

Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-5331
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

Mattermost fails to properly check the creator of an attached file when adding the file to a draft post, potentially exposing unauthorized file information.

CVE-2023-2808
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-20 1 PoC

Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlink, allowing an attacker to trigger link preview on a disallowed domain using a specially crafted link.

CVE-2023-2287
Orbit Fox by ThemeIsle Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Orbit Fox by ThemeIsle WordPress plugin before 2.10.24 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.

CVE-2023-1088
WP Plugin Manager Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Plugin Manager WordPress plugin before 1.1.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-3917
GitLab DevOps
4.3
MEDIUM
EPSS
0.2%
2023 CWE-1287 1 PoC

Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail.

CVE-2023-22021
Business Intelligence Enterprise Edition Web Database
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 6.4.0.0.0 and 7.0.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:

CVE-2023-4117
Rental Property Booking Web
4.3
MEDIUM
EPSS
0.7%
2023 CWE-79 2 PoCs

A vulnerability, which was classified as problematic, has been found in PHP Jabbers Rental Property Booking 2.0. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-235964. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-6501
Splashscreen Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Splashscreen WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack