7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-41966
Analog FM transmitter Web
6.5
MEDIUM
EPSS
0.1%
2023 CWE-267 2 PoCs

The application suffers from a privilege escalation vulnerability. A user with read permissions can elevate privileges by sending a HTTP POST to set a parameter.

CVE-2023-4640
Anywhere General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

The controller responsible for setting the logging level does not include any authorization checks to ensure the user is authenticated. This can be seen by noting that it extends Controller rather than AuthenticatedController and includes no further checks. This issue affects YugabyteDB Anywhere: from 2.0.0 through 2.17.3

CVE-2023-0889
Themeflection Numbers Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Themeflection Numbers WordPress plugin before 2.0.1 does not have authorisation and CSRF check in an AJAX action, and does not ensure that the options to be updated belong to the plugin. As a result, it could allow any authenticated users, such as subscriber, to update arbitrary blog options, such as enabling registration and set the default role to administrator

CVE-2023-1330
Redirection Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The Redirection WordPress plugin before 1.1.4 does not add nonce verification in place when adding the redirect, which could allow attackers to add redirects via a CSRF attack.

CVE-2023-24121
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet.

CVE-2023-1777
Mattermost Web
6.5
MEDIUM
EPSS
0.3%
2023 CWE-200 1 PoC

Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.

CVE-2023-2983
pimcore/pimcore General
6.5
MEDIUM
EPSS
0.0%
2023 CWE-267 1 PoC

Privilege Defined With Unsafe Actions in GitHub repository pimcore/pimcore prior to 10.5.23.

CVE-2023-4930
Front End PM Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The Front End PM WordPress plugin before 11.4.3 does not block listing the contents of the directories where it stores attachments to private messages, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled.

CVE-2023-40285
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

CVE-2023-21910
Business Intelligence Enterprise Edition Web Database
6.5
MEDIUM
EPSS
0.5%
2023 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General). Supported versions that are affected are 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS

CVE-2023-27896
BusinessObjects Business Intelligence Platform (Web Services) Web
6.5
MEDIUM
EPSS
0.3%
2023 CWE-918 1 PoC

In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own CMS, leading to a high impact on availability.

CVE-2023-0335
WP Shamsi Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Shamsi WordPress plugin through 4.3.3 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber delete attachment.

CVE-2023-1460
Online Pizza Ordering System Web
6.5
MEDIUM
EPSS
0.3%
2023 CWE-287 1 PoC

A vulnerability was found in SourceCodester Online Pizza Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file admin/ajax.php?action=save_user of the component Password Change Handler. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The identifier VDB-223305 was assigned to this vulnerability.

CVE-2023-0661
Devolutions Server General
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data.

CVE-2023-26987
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2023 2 PoCs

An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST request.

CVE-2023-6821
Error Log Viewer by BestWebSoft Web Windows
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

The Error Log Viewer by BestWebSoft WordPress plugin before 1.1.3 is affected by a Directory Listing issue, allowing users to read and download PHP logs without authorization

CVE-2023-1163
Vigor 2960 General
6.5
MEDIUM
EPSS
0.9%
2023 CWE-22 1 PoC

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5 and classified as critical. Affected by this vulnerability is the function getSyslogFile of the file mainfunction.cgi of the component Web Management Interface. The manipulation of the argument option leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-222259. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-0019
SAP GRC (Process Control) General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

In SAP GRC (Process Control) - versions GRCFND_A V1200, GRCFND_A V8100, GRCPINW V1100_700, GRCPINW V1100_731, GRCPINW V1200_750, remote-enabled function module in the proprietary SAP solution enables an authenticated attacker with minimal privileges to access all the confidential data stored in the database. Successful exploitation of this vulnerability can expose user credentials from client-specific tables of the database, leading to high impact on confidentiality.

CVE-2023-41336
ux-autocomplete Web
6.5
MEDIUM
EPSS
1.1%
2023 CWE-20 1 PoC

ux-autocomplete is a JavaScript Autocomplete functionality for Symfony. Under certain circumstances, an attacker could successfully submit an entity id for an `EntityType` that is *not* part of the valid choices. The problem has been fixed in `symfony/ux-autocomplete` version 2.11.2.

CVE-2023-31419
Elasticsearch Web Database
6.5
MEDIUM
EPSS
37.0%
2023 CWE-121 3 PoCs

A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.