5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-4119
LMS General
4.3
MEDIUM
EPSS
2.6%
2023 CWE-79 1 PoC

A vulnerability has been found in Academy LMS 6.0 and classified as problematic. This vulnerability affects unknown code of the file /academy/home/courses. The manipulation of the argument query/sort_by leads to cross site scripting. The attack can be initiated remotely. VDB-235966 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-4878
instantsoft/icms2 Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

CVE-2023-3593
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

Mattermost fails to properly validate markdown, allowing an attacker to crash the server via a specially crafted markdown input.

CVE-2023-3234
CRMEB Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-502 1 PoC

A vulnerability was found in Zhong Bang CRMEB up to 4.6.0. It has been declared as problematic. Affected by this vulnerability is the function put_image of the file api/controller/v1/PublicController.php. The manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-231505 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-5525
Limit Login Attempts Reloaded Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` AJAX action, allowing any user with a valid nonce to toggle the auto-update status of the plugin.

CVE-2023-5330
Mattermost Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a specially crafted request to the /api/v4/opengraph filling the cache and turning the server unavailable.

CVE-2023-0504
HT Politic Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The HT Politic WordPress plugin before 2.3.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-6905
NxFilter Windows
4.3
MEDIUM
EPSS
0.1%
2023 CWE-90 1 PoC

A vulnerability, which was classified as problematic, has been found in Jahastech NxFilter 4.3.2.5. This issue affects some unknown processing of the file user,adap.jsp?actionFlag=test&id=1 of the component Bind Request Handler. The manipulation leads to ldap injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-248267. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-3904
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2023 CWE-1287 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards.

CVE-2023-49874
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Mattermost fails to check whether a user is a guest when updating the tasks of a private playbook run allowing a guest to update the tasks of a private playbook run if they know the run ID.

CVE-2023-4829
froxlor/froxlor Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.0.22.

CVE-2023-5772
Debug Log Manager – Conveniently Monitor and Inspect Errors Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 2 PoCs

The Debug Log Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the clear_log() function. This makes it possible for unauthenticated attackers to clear the debug log via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2023-2358
Pentaho Business Analytics Server General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-257 1 PoC

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.5.0.0 and 9.3.0.4, including 8.3.x.x, saves passwords of the Hadoop Copy Files step in plaintext. 

CVE-2023-4454
wallabag/wallabag Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3.

CVE-2023-4649
instantsoft/icms2 Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-384 1 PoC

Session Fixation in GitHub repository instantsoft/icms2 prior to 2.16.1.

CVE-2023-0674
XXL-JOB Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

A vulnerability, which was classified as problematic, has been found in XXL-JOB 2.3.1. Affected by this issue is some unknown functionality of the file /user/updatePwd of the component New Password Handler. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220196.

CVE-2023-6298
iText General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-129 1 PoC

A vulnerability classified as problematic was found in Apryse iText 8.0.2. This vulnerability affects the function main of the file PdfDocument.java. The manipulation leads to improper validation of array index. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The identifier of this vulnerability is VDB-246124. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. A statement published afterwards explains that the exception is not a vu

CVE-2023-2118
Devolutions Server General
4.3
MEDIUM
EPSS
0.4%
2023 1 PoC

Insufficient access control in support ticket feature in Devolutions Server 2023.1.5.0 and below allows an authenticated attacker to send support tickets and download diagnostic files via specific endpoints.

CVE-2023-6767
Wedding Guest e-Book Web
4.3
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

A vulnerability, which was classified as problematic, was found in SourceCodester Wedding Guest e-Book 1.0. This affects an unknown part of the file /endpoint/add-guest.php. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-247899.

CVE-2023-4714
PlayTube General ⚡ nuclei
4.3
MEDIUM
EPSS
90.0%
2023 CWE-200 1 PoC

A vulnerability was found in PlayTube 3.0.1 and classified as problematic. This issue affects some unknown processing of the component Redirect Handler. The manipulation leads to information disclosure. The attack may be initiated remotely. The identifier VDB-238577 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.