5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-3126
B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

The B2BKing plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'b2bkingdownloadpricelist' function in versions up to, and including, 4.6.00. This makes it possible for Authenticated attackers with subscriber or customer-level permissions to retrieve the full pricing list of all products on the site.

CVE-2023-30641
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper access control vulnerability in Settings prior to SMR Jul-2023 Release 1 allows physical attacker to use restricted user profile to access device owner's google account data.

CVE-2023-5522
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post with hundreds of emojis to a channel and freeze the mobile app of users when viewing that particular channel. 

CVE-2023-4297
Mmm Simple File List Web Windows
4.3
MEDIUM
EPSS
0.3%
2023 1 PoC

The Mmm Simple File List WordPress plugin through 2.3 does not validate the generated path to list files from, allowing any authenticated users, such as subscribers, to list the content of arbitrary directories.

CVE-2023-4307
Lock User Account Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Lock User Account WordPress plugin through 1.0.3 does not have CSRF check when bulk locking and unlocking accounts, which could allow attackers to make logged in admins lock and unlock arbitrary users via a CSRF attack

CVE-2023-2901
Rapid Development Platform Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

A vulnerability was found in NFine Rapid Development Platform 20230511. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /SystemManage/User/GetGridJson?_search=false&nd=1680855479750&rows=50&page=1&sidx=F_CreatorTime+desc&sord=asc. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-229975. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-7125
Community by PeepSo Web Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The Community by PeepSo WordPress plugin before 6.3.1.2 does not have CSRF check when creating a user post (visible on their wall in their profile page), which could allow attackers to make logged in users perform such action via a CSRF attack

CVE-2023-2765
OA Web
4.3
MEDIUM
EPSS
0.3%
2023 CWE-36 1 PoC

A vulnerability has been found in Weaver OA up to 9.5 and classified as problematic. This vulnerability affects unknown code of the file /E-mobile/App/System/File/downfile.php. The manipulation of the argument url leads to absolute path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-229270 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-2945
openemr/openemr General
4.3
MEDIUM
EPSS
0.3%
2023 CWE-862 1 PoC

Missing Authorization in GitHub repository openemr/openemr prior to 7.0.1.

CVE-2023-7133
RuoYi Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

A vulnerability was found in y_project RuoYi 4.7.8. It has been declared as problematic. This vulnerability affects unknown code of the file /login of the component HTTP POST Request Handler. The manipulation of the argument rememberMe with the input falsen3f0m<script>alert(1)</script>p86o0 leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249136.

CVE-2023-39203
Zoom Rooms Client for Windows and Zoom VDI Client Windows
4.3
MEDIUM
EPSS
0.2%
2023 CWE-789 1 PoC

Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disclosure of information via network access.

CVE-2023-6070
Trellix Enterprise Security Manager (ESM) Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-918 1 PoC

A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where the API accepts uploaded content and doesn't parse for invalid data

CVE-2023-4868
Contact Manager App Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

A vulnerability was found in SourceCodester Contact Manager App 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file add.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239353 was assigned to this vulnerability.

CVE-2023-3244
Comments Like Dislike Web Windows
4.3
MEDIUM
EPSS
3.3%
2023 CWE-862 1 PoC

The Comments Like Dislike plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the restore_settings function called via an AJAX action in versions up to, and including, 1.2.0. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to reset the plugin's settings. NOTE: this issue is was only partially patched in version 1.2.0, as the nonce is still present to subscriber-level users.

CVE-2023-1337
RapidLoad AI – Optimize Web Vitals Automatically Web Windows
4.3
MEDIUM
EPSS
3.7%
2023 CWE-862 1 PoC

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the clear_uucss_logs function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to delete plugin log files.

CVE-2023-46089
Userback Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in Lee Le @ Userback Userback plugin <= 1.0.13 versions.

CVE-2023-5889
pkp/pkp-lib General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

CVE-2023-43754
Mattermost General
4.3
MEDIUM
EPSS
0.4%
2023 CWE-200 1 PoC

Mattermost fails to check whether the  “Allow users to view archived channels”  setting is enabled during permalink previews display, allowing members to view permalink previews of archived channels even if the “Allow users to view archived channels” setting is disabled. 

CVE-2023-4318
Herd Effects Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items, which could allow attackers to make logged in admins delete arbitrary effects via a CSRF attack

CVE-2023-21959
iReceivables Web Database
4.3
MEDIUM
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (component: Attachments). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iReceivables. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle iReceivables accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).