5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-2474
Rebuild Web
4.3
MEDIUM
EPSS
0.2%
2023 CWE-352 2 PoCs

A vulnerability has been found in Rebuild 3.2 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to change the configuration settings. VDB-227866 is the identifier assigned to this vulnerability.

CVE-2023-3520
it-novum/openitcockpit Web
4.3
MEDIUM
EPSS
0.0%
2023 CWE-614 1 PoC

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit prior to 4.6.6.

CVE-2023-26438
OX App Suite General
4.3
MEDIUM
EPSS
0.0%
2023 CWE-918 1 PoC

External service lookups for a number of protocols were vulnerable to a time-of-check/time-of-use (TOCTOU) weakness, involving the JDK DNS cache. Attackers that were timing DNS cache expiry correctly were able to inject configuration that would bypass existing network deny-lists. Attackers could exploit this weakness to discover the existence of restricted network infrastructure and service availability. Improvements were made to include deny-lists not only during the check of the provided connection data, but also during use. No publicly available exploits are known.

CVE-2023-5329
DataCube4 Web
4.3
MEDIUM
EPSS
0.2%
2023 CWE-287 1 PoC

A vulnerability classified as problematic was found in Field Logic DataCube4 up to 20231001. This vulnerability affects unknown code of the file /api/ of the component Web API. The manipulation leads to improper authentication. The exploit has been disclosed to the public and may be used. VDB-241030 is the identifier assigned to this vulnerability.

CVE-2023-40362
Software Genérico General
4.3
MEDIUM
EPSS
6.1%
2023 1 PoC

An issue was discovered in CentralSquare Click2Gov Building Permit before October 2023. Lack of access control protections allows remote attackers to arbitrarily delete the contractors from any user's account when the user ID and contractor information is known.

CVE-2023-0761
Clock In Portal- Staff & Attendance Management Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Staff members, which could allow attackers to make logged in admins delete arbitrary Staff via a CSRF attack

CVE-2023-30640
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper access control vulnerability in PersonaManagerService prior to SMR Jul-2023 Release 1 allows local attackers to change confiugration.

CVE-2023-6625
Product Enquiry for WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to make a logged in admin delete them via a CSRF attack

CVE-2023-1089
Coupon Zen Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Coupon Zen WordPress plugin before 1.0.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-1858
Earnings and Expense Tracker App Web
4.3
MEDIUM
EPSS
0.2%
2023 CWE-200 1 PoC

A vulnerability was found in SourceCodester Earnings and Expense Tracker App 1.0. It has been classified as problematic. This affects an unknown part of the file index.php. The manipulation of the argument page leads to information disclosure. It is possible to initiate the attack remotely. The identifier VDB-224997 was assigned to this vulnerability.

CVE-2023-28810
DS-K1T804AXX General
4.3
MEDIUM
EPSS
0.5%
2023 CWE-284 1 PoC

Some access control/intercom products have unauthorized modification of device network configuration vulnerabilities. Attackers can modify device network configuration by sending specific data packets to the vulnerable interface within the same local network.

CVE-2023-7173
Hospital Management System Web
4.3
MEDIUM
EPSS
11.4%
2023 CWE-79 2 PoCs

A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file registration.php. The manipulation of the argument First Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249357 was assigned to this vulnerability.

CVE-2023-7139
Client Details System Web Database
4.3
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability has been found in code-projects Client Details System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/regester.php of the component HTTP POST Request Handler. The manipulation of the argument fname/lname/email/contact leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-249142 is the identifier assigned to this vulnerability.

CVE-2023-4150
User Activity Tracking and Log Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The User Activity Tracking and Log WordPress plugin before 4.0.9 does not have proper CSRF checks when managing its license, which could allow attackers to make logged in admins update and deactivate the plugin's license via CSRF attacks

CVE-2023-1680
CMS Web
4.3
MEDIUM
EPSS
0.3%
2023 CWE-200 1 PoC

A vulnerability, which was classified as problematic, has been found in Xunrui CMS 4.61. This issue affects some unknown processing of the file /dayrui/My/View/main.html. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-224237 was assigned to this vulnerability.

CVE-2023-25749
Firefox General
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

Android applications with unpatched vulnerabilities can be launched from a browser using Intents, exposing users to these vulnerabilities. Firefox will now confirm with users that they want to launch an external application before doing so. <br>*This bug only affects Firefox for Android. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 111.

CVE-2023-26434
OX App Suite General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue POP3 service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit accepted POP3 server response to reasonable length/size. No publicly available exploits are known.

CVE-2023-0301
alfio-event/alf.io Web
4.3
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository alfio-event/alf.io prior to Alf.io 2.0-M4-2301.

CVE-2023-21927
JD Edwards EnterpriseOne Tools Web Database
4.3
MEDIUM
EPSS
0.3%
2023 1 PoC

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Interoperability SEC). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVE-2023-0497
HT Portfolio Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The HT Portfolio WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack