5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-4468
Trio 8500 Cloud
4.3
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

A vulnerability was found in Poly Trio 8500, Trio 8800 and Trio C60. It has been classified as problematic. This affects an unknown part of the component Poly Lens Management Cloud Registration. The manipulation leads to missing authorization. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The identifier VDB-249261 was assigned to this vulnerability.

CVE-2023-21419
Samsung Mobile Devices DevOps
4.3
MEDIUM
EPSS
0.1%
2023 CWE-287 1 PoC

An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container remain unlocked under certain condition.

CVE-2023-4059
Profile Builder Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the blog

CVE-2023-3760
SGS General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability has been found in Intergard SGS 8.7.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Change Password Handler. The manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-234445 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-6761
IceCMS Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

A vulnerability, which was classified as problematic, has been found in Thecosy IceCMS up to 2.0.1. This issue affects some unknown processing of the component User Data Handler. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247889 was assigned to this vulnerability.

CVE-2023-34115
Zoom Meeting SDK General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-120 1 PoC

Buffer copy without checking size of input in Zoom Meeting SDK before 5.13.0 may allow an authenticated user to potentially enable a denial of service via local access. This issue may result in the Zoom Meeting SDK to crash and need to be restarted.

CVE-2023-6385
WordPress Ping Optimizer Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WordPress Ping Optimizer WordPress plugin through 2.35.1.3.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as clearing logs.

CVE-2023-6843
easy.jobs- Best Recruitment Plugin for Job Board Listing, Manager, Career Page for Elementor & Gutenberg Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The easy.jobs- Best Recruitment Plugin for Job Board Listing, Manager, Career Page for Elementor & Gutenberg WordPress plugin before 2.4.7 does not properly secure some of its AJAX actions, allowing any logged-in users to modify its settings.

CVE-2023-21426
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-798 1 PoC

Hardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardemulation PIN.

CVE-2023-28599
Zoom for Android General
4.3
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victim to a malicious website during meeting creation.

CVE-2023-4869
Contact Manager App Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

A vulnerability was found in SourceCodester Contact Manager App 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file update.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-239354 is the identifier assigned to this vulnerability.

CVE-2023-7195
WP-Reply Notify Web Windows
4.3
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP-Reply Notify WordPress plugin through 1.1 does not have a CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.

CVE-2023-2395
SRX5308 General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

A vulnerability classified as problematic has been found in Netgear SRX5308 up to 4.3.5-3. This affects an unknown part of the component Web Management Interface. The manipulation of the argument Login.userAgent leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227673 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-1903
HCM Fiori App My Forms (Fiori 2.0) General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

SAP HCM Fiori App My Forms (Fiori 2.0) - version 605, does not perform necessary authorization checks for an authenticated user exposing the restricted header data.

CVE-2023-0467
WP Dark Mode Web Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The WP Dark Mode WordPress plugin before 4.0.8 does not properly sanitize the style parameter in shortcodes before using it to load a PHP template. This leads to Local File Inclusion on servers where non-existent directories may be traversed, or when chained with another vulnerability allowing arbitrary directory creation.

CVE-2023-24058
Software Genérico Web
4.3
MEDIUM
EPSS
0.5%
2023 2 PoCs

Booked Scheduler 2.5.5 allows authenticated users to create and schedule events for any other user via a modified userId value to reservation_save.php. NOTE: 2.5.5 is a version from 2014; the latest version of Booked Scheduler is not affected. However, LabArchives Scheduler (Sep 6, 2022 Feature Release) is affected.

CVE-2023-3178
POST SMTP Mailer Web Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The POST SMTP Mailer WordPress plugin before 2.5.7 does not have proper CSRF checks in some AJAX actions, which could allow attackers to make logged in users with the manage_postman_smtp capability delete arbitrary logs via a CSRF attack.

CVE-2023-2822
Ethos Identity General ⚡ nuclei
4.3
MEDIUM
EPSS
83.7%
2023 CWE-79 3 PoCs

A vulnerability was found in Ellucian Ethos Identity up to 5.10.5. It has been classified as problematic. Affected is an unknown function of the file /cas/logout. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 5.10.6 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-229596.

CVE-2023-5713
System Dashboard Web Windows
4.3
MEDIUM
EPSS
0.3%
2023 CWE-862 1 PoC

The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve potentially sensitive option values, and deserialize the content of those values.

CVE-2023-45038
Music Station General ⚡ nuclei
4.3
MEDIUM
EPSS
6.9%
2023 CWE-287 0 PoCs

An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following version: Music Station 5.4.0 and later