5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-0496
HT Event Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The HT Event WordPress plugin before 1.4.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-4478
Mattermost General
4.3
MEDIUM
EPSS
0.3%
2023 CWE-74 1 PoC

Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thus blocking them from later accessing Mattermost without the system admin activating their accounts.

CVE-2023-47168
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-601 1 PoC

Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked "Back to Mattermost" after providing a invalid custom url scheme in /oauth/{service}/mobile_login?redirect_to=

CVE-2023-21425
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.0%
2023 CWE-287 1 PoC

Improper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to get sensitive information.

CVE-2023-3056
YFCMF Web
4.3
MEDIUM
EPSS
0.2%
2023 CWE-24 1 PoC

A vulnerability was found in YFCMF up to 3.0.4. It has been declared as problematic. This vulnerability affects unknown code of the file index.php. The manipulation leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-230542 is the identifier assigned to this vulnerability.

CVE-2023-0914
pixelfed/pixelfed General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-285 1 PoC

Improper Authorization in GitHub repository pixelfed/pixelfed prior to 0.11.4.

CVE-2023-0503
Free WooCommerce Theme 99fy Extension Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Free WooCommerce Theme 99fy Extension WordPress plugin before 1.2.8 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-30949
com.palantir.slate:slate General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-1173 1 PoC

A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the page's content, which could lead to phishing attacks.

CVE-2023-6577
PatrolFlow 2530Pro Web
4.3
MEDIUM
EPSS
0.0%
2023 CWE-22 1 PoC

A vulnerability was found in Byzoro PatrolFlow 2530Pro up to 20231126. It has been rated as problematic. This issue affects some unknown processing of the file /log/mailsendview.php. The manipulation of the argument file with the input /boot/phpConfig/tb_admin.txt leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247157 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-2902
Rapid Development Platform Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

A vulnerability was found in NFine Rapid Development Platform 20230511. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /SystemManage/Organize/GetTreeGridJson?_search=false&nd=1681813520783&rows=10000&page=1&sidx=&sord=asc. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-229976. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-3582
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-863 1 PoC

Mattermost fails to verify channel membership when linking a board to a channel allowing a low-privileged authenticated user to link a Board to a private channel they don't have access to, 

CVE-2023-45357
Software Genérico General
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitive information via a popup warning message. 6.14 (6.14.0) is also a fixed release.

CVE-2023-1384
Fire TV Stick 3rd gen Web
4.3
MEDIUM
EPSS
0.9%
2023 CWE-80 1 PoC

The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary javascript code to be run This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS versions prior to 7.6.3.3.

CVE-2023-4655
instantsoft/icms2 Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1.

CVE-2023-1775
Mattermost General
4.3
MEDIUM
EPSS
0.3%
2023 CWE-200 1 PoC

When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Websocket clients.

CVE-2023-2831
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-400 1 PoC

Mattermost fails to unescape Markdown strings in a memory-efficient way, allowing an attacker to cause a Denial of Service by sending a message containing a large number of escaped characters.

CVE-2023-0453
WP Private Message Web Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensure that private messages to be accessed belong to the user making the requests. This allowing any authenticated users to access private messages belonging to other users by tampering the ID.

CVE-2023-48268
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards allowing an attacker to consume excessive resources, possibly leading to Denial of Service, by importing a board using a specially crafted zip (zip bomb).

CVE-2023-4544
Smart S85F Management Platform Web
4.3
MEDIUM
EPSS
0.0%
2023 CWE-425 1 PoC

A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230809. It has been rated as problematic. This issue affects some unknown processing of the file /config/php.ini. The manipulation leads to direct request. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-238049 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-5531
Thumbnail Slider With Lightbox Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the delete functionality. This makes it possible for unauthenticated attackers to delete image lightboxes via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.