7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-2302
Contact Form and Calls To Action by vcita Web Windows
6.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with the edit_posts capability, such as contributors and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2023-0978
Trellix Intelligent Sandbox General
6.4
MEDIUM
EPSS
0.4%
2023 CWE-77 1 PoC

A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using specially crafted strings. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI command. The vulnerability allows the attack

CVE-2023-30772
Software Genérico General
6.4
MEDIUM
EPSS
0.1%
2023 2 PoCs

The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/power/supply/da9150-charger.c if a physically proximate attacker unplugs a device.

CVE-2023-5350
salesagility/suitecrm Database
6.4
MEDIUM
EPSS
15.3%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.

CVE-2023-21483
Galaxy Store General
6.4
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper Access Control vulnerability in Galaxy Store prior to version 4.5.53.6 allows local attacker to access protected data using exported service.

CVE-2023-4651
instantsoft/icms2 Web
6.4
MEDIUM
EPSS
0.0%
2023 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1.

CVE-2023-4453
pimcore/pimcore Web
6.4
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.8.

CVE-2023-24517
Pandora FMS General
6.4
MEDIUM
EPSS
0.2%
2023 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in the Pandora FMS File Manager component, allows an attacker to make make use of this issue ( unrestricted file upload ) to execute arbitrary system commands. This issue affects Pandora FMS v767 version and prior versions on all platforms.

CVE-2023-0012
Host Agent (Windows) Windows
6.4
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be able to replace executables with a malicious file that will be started under a privileged account. Note that by default all user members of SAP_LocaAdmin are denied the ability to logon locally by security policy so that this can only occur if the system has already been compromised.

CVE-2023-2807
Pandora FMS General
6.4
MEDIUM
EPSS
0.1%
2023 CWE-290 1 PoC

Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication. This issue affects PandoraFMS v771 and prior versions on all platforms.

CVE-2023-6335
Workforce Access Windows
6.4
MEDIUM
EPSS
0.1%
2023 CWE-59 1 PoC

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled Filename.This issue affects Workforce Access: before 8.7.

CVE-2023-2069
GitLab DevOps
6.4
MEDIUM
EPSS
0.5%
2023 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. A user with the role of developer could use the import project feature to leak CI/CD variables.

CVE-2023-2300
Contact Form Builder by vcita Web Windows
6.4
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

The Contact Form Builder by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 4.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with the edit_posts capability, such as contributors and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2023-4265
Zephyr Web
6.4
MEDIUM
EPSS
0.3%
2023 CWE-120 1 PoC

Potential buffer overflow vulnerabilities in the following locations: https://github.com/zephyrproject-rtos/zephyr/blob/main/drivers/usb/device/usb_dc_native_posix.c#L359 https://github.com/zephyrproject-rtos/zephyr/blob/main/drivers/usb/device/usb_dc_native_posix.c#L359 https://github.com/zephyrproject-rtos/zephyr/blob/main/subsys/usb/device/class/netusb/function_rndis... https://github.com/zephyrproject-rtos/zephyr/blob/main/subsys/usb/device/class/netusb/function_rndis.c#L841

CVE-2023-2406
Event Registration Calendar By vcita Web Windows
6.4
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

The Event Registration Calendar By vcita plugin, versions up to and including 3.9.1, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with the edit_posts capability, such as contributors and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2023-33203
Software Genérico General
6.4
MEDIUM
EPSS
0.0%
2023 2 PoCs

The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/net/ethernet/qualcomm/emac/emac.c if a physically proximate attacker unplugs an emac based device.

CVE-2023-28153
Software Genérico General
6.4
MEDIUM
EPSS
0.1%
2023 1 PoC

An issue was discovered in the Kiddoware Kids Place Parental Control application before 3.8.50 for Android. The child can remove all restrictions temporarily without the parents noticing by rebooting into Android Safe Mode and disabling the "Display over other apps" permission.

CVE-2023-5618
Modern Footnotes Web Windows
6.4
MEDIUM
EPSS
0.1%
2023 CWE-79 2 PoCs

The Modern Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up to, and including, 1.4.16 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2023-5774
Animated Counters Web Windows
6.4
MEDIUM
EPSS
0.1%
2023 CWE-79 3 PoCs

The Animated Counters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2023-3711
PM23/43 General
6.4
MEDIUM
EPSS
0.1%
2023 CWE-384 2 PoCs

Session Fixation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Session Credential Falsification through Prediction.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).