7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-3413
GitLab DevOps
6.5
MEDIUM
EPSS
0.2%
2023 CWE-201 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to read the source code of a project through a fork created before changing visibility to only project members.

CVE-2023-4560
omeka/omeka-s General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-612 1 PoC

Improper Authorization of Index Containing Sensitive Information in GitHub repository omeka/omeka-s prior to 4.0.4.

CVE-2023-0772
Popup Builder by OptinMonster Web Windows
6.5
MEDIUM
EPSS
0.3%
2023 1 PoC

The Popup Builder by OptinMonster WordPress plugin before 2.12.2 does not ensure that the campaign to be loaded via some shortcodes is actually a campaign, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, like draft, private or even password protected ones.

CVE-2023-2380
SRX5308 General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability, which was classified as problematic, was found in Netgear SRX5308 up to 4.3.5-3. Affected is an unknown function. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-227658 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-5459
DVP32ES2 PLC General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability has been found in Delta Electronics DVP32ES2 PLC 1.48 and classified as critical. This vulnerability affects unknown code of the component Password Transmission Handler. The manipulation leads to denial of service. The exploit has been disclosed to the public and may be used. VDB-241582 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-4145
pimcore/customer-data-framework Web
6.5
MEDIUM
EPSS
0.0%
2023 CWE-79 4 PoCs

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/customer-data-framework prior to 3.4.2.

CVE-2023-1093
OAuth Single Sign On Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack

CVE-2023-45228
Analog FM transmitter Web
6.5
MEDIUM
EPSS
0.0%
2023 CWE-284 2 PoCs

The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissions by sending a single HTTP POST request with modified parameters.

CVE-2023-3507
WooCommerce Pre-Orders Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when canceling pre-orders, which could allow attackers to make logged in admins cancel arbitrary pre-orders via a CSRF attack

CVE-2023-0661
Devolutions Server General
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data.

CVE-2023-21994
Mobile Security Suite Database
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle Mobile Security Suite product of Oracle Fusion Middleware (component: Android Mobile Authenticator App). Supported versions that are affected are Prior to 11.1.2.3.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Mobile Security Suite executes to compromise Oracle Mobile Security Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Mobile Security Suite accessible data. CVSS 3

CVE-2023-0500
WP Film Studio Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Film Studio WordPress plugin before 1.3.5 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-3338
kernel General
6.5
MEDIUM
EPSS
7.7%
2023 CWE-476 2 PoCs

A null pointer dereference flaw was found in the Linux kernel's DECnet networking protocol. This issue could allow a remote user to crash the system.

CVE-2023-24121
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet.

CVE-2023-0666
Wireshark General
6.5
MEDIUM
EPSS
2.5%
2023 CWE-122 2 PoCs

Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.

CVE-2023-5840
linkstackorg/linkstack General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-640 1 PoC

Weak Password Recovery Mechanism for Forgotten Password in GitHub repository linkstackorg/linkstack prior to v4.2.9.

CVE-2023-5462
XD5E-30R-E General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-404 2 PoCs

A vulnerability was found in XINJE XD5E-30R-E 3.5.3b. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Modbus Handler. The manipulation leads to denial of service. The exploit has been disclosed to the public and may be used. The identifier VDB-241585 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-0024
Solution Manager (BSP Application) Web
6.5
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information or craft a payload which may restrict access to the desired resources, resulting in Cross-Site Scripting vulnerability.

CVE-2023-23296
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2023 1 PoC

Korenix JetWave 4200 Series 1.3.0 and JetWave 3200 Series 1.6.0 are vulnerable to Denial of Service via /goform/formDefault.

CVE-2023-1524
Download Manager Web Windows
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

The Download Manager WordPress plugin before 3.2.71 does not adequately validate passwords for password-protected files. Upon validation, a master key is generated and exposed to the user, which may be used to download any password-protected file on the server, allowing a user to download any file with the knowledge of any one file's password.