5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-4532
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2023 CWE-863 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. Users were capable of linking CI/CD jobs of private projects which they are not a member of.

CVE-2023-48369
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to different endpoints to potentially overflow the log.

CVE-2023-0999
Sales Tracker Management System Web
4.3
MEDIUM
EPSS
0.3%
2023 CWE-352 1 PoC

A vulnerability classified as problematic was found in SourceCodester Sales Tracker Management System 1.0. This vulnerability affects unknown code of the file admin/?page=user/list. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-221734 is the identifier assigned to this vulnerability.

CVE-2023-21997
User Management Web Database
4.3
MEDIUM
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Proxy User Delegation). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle User Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle User Management accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVE-2023-1767
Snyk Advisor Web
4.3
MEDIUM
EPSS
1.8%
2023 CWE-79 3 PoCs

The Snyk Advisor website (https://snyk.io/advisor/) was vulnerable to a stored XSS prior to 28th March 2023. A feature of Snyk Advisor is to display the contents of a scanned package's Readme on its package health page. An attacker could create a package in NPM with an associated markdown README file containing XSS-able HTML tags. Upon Snyk Advisor importing the package, the XSS would run each time an end user browsed to the package's page on Snyk Advisor.

CVE-2023-49969
Software Genérico Web Database
4.3
MEDIUM
EPSS
0.2%
2023 2 PoCs

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer.

CVE-2023-0762
Clock In Portal- Staff & Attendance Management Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting designations, which could allow attackers to make logged in admins delete arbitrary designations via a CSRF attack

CVE-2023-3920
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2023 CWE-863 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation.

CVE-2023-6296
osCommerce General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

A vulnerability was found in osCommerce 4. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /catalog/compare of the component Instant Message Handler. The manipulation of the argument compare with the input 40dz4iq"><script>alert(1)</script>zohkx leads to cross site scripting. The attack may be launched remotely. VDB-246122 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-1911
Blocksy Companion Web Windows
4.3
MEDIUM
EPSS
0.3%
2023 1 PoC

The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example

CVE-2023-6633
Site Notes Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Site Notes WordPress plugin through 2.0.0 does not have CSRF checks in some of its functionalities, which could allow attackers to make logged in users perform unwanted actions, such as deleting administration notes, via CSRF attacks

CVE-2023-6292
Ecwid Ecommerce Shopping Cart Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Ecwid Ecommerce Shopping Cart WordPress plugin before 6.12.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVE-2023-24499
Butterfly Button plugin General
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Butterfly Button plugin may leave traces of its use on user's device. Since it is used for reporting domestic problems, this may lead to spouse knowing about its use.

CVE-2023-3585
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-400 1 PoC

Mattermost Boards fail to properly validate a board link, allowing an attacker to crash a channel by posting a specially crafted boards link.

CVE-2023-25750
Firefox General
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private browsing mode. This vulnerability affects Firefox < 111.

CVE-2023-45874
Software Genérico General
4.3
MEDIUM
EPSS
0.3%
2023 2 PoCs

An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads).

CVE-2023-28159
Firefox General
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The fullscreen notification could have been hidden on Firefox for Android by using download popups, resulting in potential user confusion or spoofing attacks. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 111.

CVE-2023-5711
System Dashboard Web Windows
4.3
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_php_info() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve sensitive information provided by PHP info.

CVE-2023-39204
Zoom Clients General
4.3
MEDIUM
EPSS
0.3%
2023 CWE-120 1 PoC

Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.

CVE-2023-3900
GitLab DevOps
4.3
MEDIUM
EPSS
0.2%
2023 CWE-1287 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.