5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-7040
Stupid Simple CMS Web
4.3
MEDIUM
EPSS
0.3%
2023 CWE-24 1 PoC

A vulnerability classified as problematic was found in codelyfe Stupid Simple CMS up to 1.2.4. Affected by this vulnerability is an unknown functionality of the file /file-manager/rename.php. The manipulation of the argument oldName leads to path traversal: '../filedir'. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-248689 was assigned to this vulnerability.

CVE-2023-26433
OX App Suite General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

When adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue IMAP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit accepted IMAP server response to reasonable length/size. No publicly available exploits are known.

CVE-2023-5375
mosparo/mosparo General ⚡ nuclei
4.3
MEDIUM
EPSS
43.3%
2023 CWE-601 1 PoC

Open Redirect in GitHub repository mosparo/mosparo prior to 1.0.2.

CVE-2023-5198
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2023 CWE-863 1 PoC

An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a removed project member to write to protected branches using deploy keys.

CVE-2023-0484
Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-1417
GitLab DevOps
4.3
MEDIUM
EPSS
0.6%
2023 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible for an unauthorised user to add child epics linked to victim's epic in an unrelated group.

CVE-2023-21941
BI Publisher (formerly XML Publisher) Web Database
4.3
MEDIUM
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVE-2023-22009
Self-Service Human Resources Web Database
4.3
MEDIUM
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Workforce Management). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Self-Service Human Resources. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Self-Service Human Resources accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVE-2023-1086
Preview Link Generator Web Windows
4.3
MEDIUM
EPSS
0.8%
2023 1 PoC

The Preview Link Generator WordPress plugin before 1.0.4 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-6893
Intercom Broadcasting System Web
4.3
MEDIUM
EPSS
88.4%
2023 CWE-22 1 PoC

A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK) and classified as problematic. Affected by this issue is some unknown functionality of the file /php/exportrecord.php. The manipulation of the argument downname with the input C:\ICPAS\Wnmp\WWW\php\conversion.php leads to path traversal. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.0 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-248252.

CVE-2023-3479
hestiacp/hestiacp Web ⚡ nuclei
4.3
MEDIUM
EPSS
23.5%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8.

CVE-2023-4168
Adlisting General ⚡ nuclei
4.3
MEDIUM
EPSS
74.7%
2023 CWE-200 2 PoCs

A vulnerability was found in Templatecookie Adlisting 2.14.0. It has been classified as problematic. Affected is an unknown function of the file /ad-list of the component Redirect Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-236184. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-47858
Mattermost Web
4.3
MEDIUM
EPSS
0.2%
2023 CWE-284 1 PoC

Mattermost fails to properly verify the permissions needed for viewing archived public channels,  allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams/<team-id>/channels/deleted endpoint.

CVE-2023-4269
User Activity Log Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The User Activity Log WordPress plugin before 1.6.6 lacks proper authorisation when exporting its activity logs, allowing any authenticated users, such as subscriber to perform such action and retrieve PII such as email addresses.

CVE-2023-4209
POEditor Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The POEditor WordPress plugin before 0.9.8 does not have CSRF checks in various places, which could allow attackers to make logged in admins perform unwanted actions, such as reset the plugin's settings and update its API key via CSRF attacks.

CVE-2023-36531
LiquidPoll – Advanced Polls for Creators and Brands General
4.3
MEDIUM
EPSS
4.8%
2023 CWE-862 1 PoC

Missing Authorization vulnerability in LiquidPoll LiquidPoll – Advanced Polls for Creators and Brands allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LiquidPoll – Advanced Polls for Creators and Brands: from n/a through 3.3.68.

CVE-2023-6465
Nipah Virus Testing Management System Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been classified as problematic. This affects an unknown part of the file registered-user-testing.php. The manipulation of the argument regmobilenumber leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-246615.

CVE-2023-4381
instantsoft/icms2 Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-620 1 PoC

Unverified Password Change in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

CVE-2023-5967
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-754 1 PoC

Mattermost fails to properly validate requests to the Calls plugin, allowing an attacker sending a request without a User Agent header to cause a panic and crash the Calls plugin

CVE-2023-5498
chiefonboarding/chiefonboarding Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository chiefonboarding/chiefonboarding prior to v2.0.47.