5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-2784
Mattermost App Framework General
4.2
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests to the Apps allowing a regular user send install requests to the Apps.

CVE-2023-25758
Software Genérico General
4.2
MEDIUM
EPSS
0.1%
2023 1 PoC

Onekey Touch devices through 4.0.0 and Onekey Mini devices through 2.10.0 allow man-in-the-middle attackers to obtain the seed phase. The man-in-the-middle access can only be obtained after disassembling a device (i.e., here, "man-in-the-middle" does not refer to the attacker's position on an IP network). NOTE: the vendor states that "our hardware team has updated the security patch without anyone being affected."

CVE-2023-1774
Mattermost General
4.2
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.

CVE-2023-21432
Smart Things General
4.2
MEDIUM
EPSS
0.0%
2023 CWE-285 1 PoC

Improper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without authorization of the owner.

CVE-2023-34121
Zoom for Windows Windows
4.1
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via network access.

CVE-2023-38058
OTRS General
4.1
MEDIUM
EPSS
0.2%
2023 CWE-269 1 PoC

An improper privilege check in the OTRS ticket move action in the agent interface allows any as agent authenticated attacker to to perform a move of an ticket without the needed permission. This issue affects OTRS: from 8.0.X before 8.0.35.

CVE-2023-31417
Elasticsearch Web Database
4.1
MEDIUM
EPSS
0.1%
2023 CWE-532 1 PoC

Elasticsearch generally filters out sensitive information and credentials before logging to the audit log. It was found that this filtering was not applied when requests to Elasticsearch use certain deprecated URIs for APIs. The impact of this flaw is that sensitive information such as passwords and tokens might be printed in cleartext in Elasticsearch audit logs. Note that audit logging is disabled by default and needs to be explicitly enabled and even when audit logging is enabled, request bodies that could contain sensitive information are not printed to the audit log unless explicitly conf

CVE-2023-0005
PAN-OS Web Networking
4.1
MEDIUM
EPSS
0.3%
2023 CWE-497 1 PoC

A vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to expose the plaintext values of secrets stored in the device configuration and encrypted API keys.

CVE-2023-5838
linkstackorg/linkstack General
4.1
MEDIUM
EPSS
0.0%
2023 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9.

CVE-2023-38057
OTRS Web
4.1
MEDIUM
EPSS
0.5%
2023 CWE-20 1 PoC

An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript code in free text answers. This allows a cross site scripting attack while reading the replies as authenticated agent. This issue affects OTRS Survey module from 7.0.X before 7.0.32, from 8.0.X before 8.0.13 and ((OTRS)) Community Edition Survey module from 6.0.X through 6.0.22.

CVE-2023-30959
com.palantir.apollo:autopilot Web
4.1
MEDIUM
EPSS
0.2%
2023 CWE-84 1 PoC

In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user interaction.

CVE-2023-4126
answerdev/answer General
4.1
MEDIUM
EPSS
0.1%
2023 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository answerdev/answer prior to v1.1.0.

CVE-2023-3021
mkucej/i-librarian-free Web
4.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository mkucej/i-librarian-free prior to 5.10.4.

CVE-2023-21457
Samsung Mobile Devices General
4.1
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Bluetooth without related permission.

CVE-2023-53158
gix-transport Networking
4.1
MEDIUM
EPSS
0.0%
2023 CWE-78 1 PoC

The gix-transport crate before 0.36.1 for Rust allows command execution via the "gix clone 'ssh://-oProxyCommand=open$IFS" substring. NOTE: this was discovered before CVE-2024-32884, a similar vulnerability (involving a username field) that is more difficult to exploit.

CVE-2023-2342
pimcore/pimcore Web
4.0
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-30734
Samsung Health General
4.0
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive information via implicit intent.

CVE-2023-42553
Samsung Email General
4.0
MEDIUM
EPSS
0.3%
2023 1 PoC

Improper authorization verification vulnerability in Samsung Email prior to version 6.1.90.4 allows attackers to read sandbox data of email.

CVE-2023-30716
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper access control vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows attackers to trigger certain commands.

CVE-2023-0435
pyload/pyload General
4.0
MEDIUM
EPSS
0.4%
2023 CWE-1125 1 PoC

Excessive Attack Surface in GitHub repository pyload/pyload prior to 0.5.0b3.dev41.