5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-1414
WP VR Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP VR WordPress plugin before 8.3.0 does not have authorisation and CSRF checks in various AJAX actions, one in particular could allow any authenticated users, such as subscriber to update arbitrary tours

CVE-2023-21902
Financial Services Behavior Detection Platform Web Database
4.3
MEDIUM
EPSS
0.4%
2023 1 PoC

Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Application). The supported version that is affected is 8.0.8.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Financial Services Behavior Detection Platform accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (

CVE-2023-4229
ioLogik 4000 Series General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-1021 1 PoC

A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, potentially exposing users to security risks. This vulnerability may allow attackers to trick users into interacting with malicious content, leading to unintended actions or unauthorized data disclosures.

CVE-2023-6299
iText General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-401 1 PoC

A vulnerability, which was classified as problematic, has been found in Apryse iText 8.0.1. This issue affects some unknown processing of the file PdfDocument.java of the component Reference Table Handler. The manipulation leads to memory leak. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 8.0.2 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-246125 was assigned to this vulnerability. NOTE: The vendor was contacted early about this vulnerability. The fix was introdu

CVE-2023-0763
Clock In Portal- Staff & Attendance Management Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Holidays, which could allow attackers to make logged in admins delete arbitrary holidays via a CSRF attack

CVE-2023-0495
HT Slider For Elementor Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The HT Slider For Elementor WordPress plugin before 1.4.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-6066
WP Custom Widget area Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Custom Widget area WordPress plugin through 1.2.5 does not properly apply capability and nonce checks on any of its AJAX action callback functions, which could allow attackers with subscriber+ privilege to create, delete or modify menus on the site.

CVE-2023-2791
Mattermost Web
4.3
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

When creating a playbook run via the /dialog API, Mattermost fails to validate all parameters, allowing an authenticated attacker to edit an arbitrary channel post.

CVE-2023-1087
WC Sales Notification Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WC Sales Notification WordPress plugin before 1.2.3 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-2785
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-400 1 PoC

Mattermost fails to properly truncate the postgres error log message of a search query failure allowing an attacker to cause the creation of large log files which can result in Denial of Service

CVE-2023-6653
Teacher Subject Allocation Management System Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

A vulnerability was found in PHPGurukul Teacher Subject Allocation Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/subject.php of the component Create a new Subject. The manipulation of the argument cid leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-247346 is the identifier assigned to this vulnerability.

CVE-2023-3614
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

Mattermost fails to properly validate a gif image file, allowing an attacker to consume a significant amount of server resources, making the server unresponsive for an extended period of time by linking to specially crafted image file.

CVE-2023-30684
Samsung Mobile Devices Web
4.3
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper access control in Samsung Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call acceptRingingCall API without permission.

CVE-2023-27263
Mattermost Web
4.3
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team they are not a member of.

CVE-2023-2022
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2023 CWE-262 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on protected branches even if they don't have access to merge

CVE-2023-6773
POS and Inventory Management System General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

A vulnerability has been found in CodeAstro POS and Inventory Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /accounts_con/register_account of the component User Creation Handler. The manipulation of the argument account_type with the input Admin leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247909 was assigned to this vulnerability.

CVE-2023-29505
Software Genérico Web
4.3
MEDIUM
EPSS
0.5%
2023 2 PoCs

An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.

CVE-2023-24525
CRM (WebClient UI) Web
4.3
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

SAP CRM WebClient UI - versions WEBCUIF 748, 800, 801, S4FND 102, 103, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On successful exploitation an authenticated attacker can cause limited impact on confidentiality of the application.

CVE-2023-49809
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

Mattermost fails to handle a null request body in the /add endpoint, allowing a simple member to send a request with null request body to that endpoint and make it crash. After a few repetitions, the plugin is disabled. 

CVE-2023-48732
Mattermost General
4.3
MEDIUM
EPSS
0.6%
2023 CWE-200 1 PoC

Mattermost fails to scope the WebSocket response around notified users to a each user separately resulting in the WebSocket broadcasting the information about who was notified about a post to everyone else in the channel.