5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-1034
salesagility/suitecrm General
4.3
MEDIUM
EPSS
2.0%
2023 CWE-29 1 PoC

Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9.

CVE-2023-4172
Flash Flood Disaster Monitoring and Warning System General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-36 1 PoC

A vulnerability, which was classified as problematic, has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This issue affects some unknown processing of the file \Service\FileHandler.ashx. The manipulation of the argument FileDirectory leads to absolute path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-236207.

CVE-2023-3366
MultiParcels Shipping For WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.2 does not have CRSF check when deleting a shipment, allowing attackers to make any logged in user, delete arbitrary shipment via a CSRF attack

CVE-2023-2783
Mattermost App Framework General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

Mattermost Apps Framework fails to verify that a secret provided in the incoming webhook request allowing an attacker to modify the contents of the post sent by the Apps.

CVE-2023-4251
EventPrime Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks.

CVE-2023-7026
IPTV Gateway Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-434 1 PoC

A vulnerability was found in Lightxun IPTV Gateway up to 20231208. It has been rated as problematic. This issue affects some unknown processing of the file /ZHGXTV/index.php/admin/index/web_upload_template.html. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248579.

CVE-2023-4023
All Users Messenger Web Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The All Users Messenger WordPress plugin through 1.24 does not prevent non-administrator users from deleting messages from the all-users messenger.

CVE-2023-2103
alextselegidis/easyappointments Web
4.3
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

CVE-2023-26432
OX App Suite General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue SMTP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit accepted SMTP server response to reasonable length/size. No publicly available exploits are known.

CVE-2023-0499
QuickSwish Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The QuickSwish WordPress plugin before 1.1.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-30960
com.palantir.foundry.jobtracker:job-tracker General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-639 1 PoC

A security defect was discovered in Foundry job-tracker that enabled users to query metadata related to builds on resources they did not have access to. This defect was resolved with the release of job-tracker 4.645.0. The service was rolled out to all affected Foundry instances. No further intervention is required.

CVE-2023-47233
Software Genérico General
4.3
MEDIUM
EPSS
0.0%
2023 1 PoC

The brcm80211 component in the Linux kernel through 6.5.10 has a brcmf_cfg80211_detach use-after-free in the device unplugging (disconnect the USB by hotplug) code. For physically proximate attackers with local access, this "could be exploited in a real world scenario." This is related to brcmf_cfg80211_escan_timeout_worker in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c.

CVE-2023-6121
Red Hat Enterprise Linux 8 General
4.3
MEDIUM
EPSS
0.7%
2023 CWE-125 2 PoCs

An out-of-bounds read vulnerability was found in the NVMe-oF/TCP subsystem in the Linux kernel. This issue may allow a remote attacker to send a crafted TCP packet, triggering a heap-based buffer overflow that results in kmalloc data being printed and potentially leaked to the kernel ring buffer (dmesg).

CVE-2023-4138
ikus060/rdiffweb General
4.2
MEDIUM
EPSS
0.1%
2023 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.0.

CVE-2023-21462
Quick Share Agent General
4.2
MEDIUM
EPSS
0.1%
2023 CWE-215 1 PoC

The sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 allows to local attacker to access MAC address without related permission.

CVE-2023-22016
VM VirtualBox Database
4.2
MEDIUM
EPSS
0.0%
2023 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.46 and Prior to 7.0.10. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1

CVE-2023-23546
UR32L Networking
4.2
MEDIUM
EPSS
0.1%
2023 CWE-295 1 PoC

A misconfiguration vulnerability exists in the urvpn_client functionality of Milesight UR32L v32.3.0.5. A specially-crafted man-in-the-middle attack can lead to increased privileges. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

CVE-2023-3586
Mattermost General
4.2
MEDIUM
EPSS
0.2%
2023 CWE-863 1 PoC

Mattermost fails to disable public Boards after the "Enable Publicly-Shared Boards" configuration option is disabled, resulting in previously-shared public Boards to remain accessible.

CVE-2023-32115
Master Data Synchronization (MDS COMPARE TOOL) General
4.2
MEDIUM
EPSS
0.2%
2023 CWE-89 1 PoC

An attacker can exploit MDS COMPARE TOOL and use specially crafted inputs to read and modify database commands, resulting in the retrieval of additional information persisted by the system.

CVE-2023-3192
froxlor/froxlor General
4.2
MEDIUM
EPSS
0.2%
2023 CWE-384 1 PoC

Session Fixation in GitHub repository froxlor/froxlor prior to 2.1.0.