7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-39983
MXsecurity Series Database
5.3
MEDIUM
EPSS
0.4%
2023 CWE-915 1 PoC

A vulnerability that poses a potential risk of polluting the MXsecurity sqlite database and the nsm-web UI has been identified in MXsecurity versions prior to v1.0.1. This vulnerability might allow an unauthenticated remote attacker to register or add devices via the nsm-web application.

CVE-2023-26460
NetWeaver AS for Java General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-284 1 PoC

Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authentication checks for functionalities that require user identity

CVE-2023-1258
Flow-X General
5.3
MEDIUM
EPSS
13.2%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.

CVE-2023-2152
Student Study Center Desk Management System Web
5.3
MEDIUM
EPSS
0.5%
2023 CWE-73 1 PoC

A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument page leads to file inclusion. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-226273 was assigned to this vulnerability.

CVE-2023-5617
Pentaho Data Integration & Analytics Web
5.3
MEDIUM
EPSS
0.4%
2023 CWE-550 1 PoC

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x and 8.3.x, display the version of Tomcat when a server error is encountered.

CVE-2023-2840
gpac/gpac General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2.

CVE-2023-2109
chatwoot/chatwoot Web
5.3
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.14.0.

CVE-2023-6444
Seriously Simple Podcasting Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
61.4%
2023 2 PoCs

The Seriously Simple Podcasting WordPress plugin before 3.0.0 discloses the Podcast owner's email address (which by default is the admin email address) via an unauthenticated crafted request.

CVE-2023-36539
Zoom clients General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-200 1 PoC

Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.

CVE-2023-3398
jgraph/drawio General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3.

CVE-2023-5514
eSOMS General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-209 1 PoC

The response messages received from the eSOMS report generation using certain parameter queries with full file path can be abused for enumerating the local file system structure.

CVE-2023-3042
dotCMS core Web Networking
5.3
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

In dotCMS, versions mentioned, a flaw in the NormalizationFilter does not strip double slashes (//) from URLs, potentially enabling bypasses for XSS and access controls. An example affected URL is https://demo.dotcms.com//html/portlet/ext/files/edit_text_inc.jsp , which should return a 404 response but didn't. The oversight in the default invalid URL character list can be viewed at the provided GitHub link https://github.com/dotCMS/core/blob/master/dotCMS/src/main/java/com/dotcms/filters/NormalizationFilter.java#L37 .  To mitigate, users can block URLs with double slashes at firewalls or

CVE-2023-5515
eSOMS General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-200 1 PoC

The responses for web queries with certain parameters disclose internal path of resources. This information can be used to learn internal structure of the application and to further plot attacks against web servers and deployed web applications.

CVE-2023-30666
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper input validation vulnerability in DoOemImeiSetPreconfig in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds write.

CVE-2023-6376
court document management software General
5.3
MEDIUM
EPSS
1.0%
2023 CWE-330 1 PoC

Henschen & Associates court document management software does not sufficiently randomize file names of cached documents, allowing a remote, unauthenticated attacker to access restricted documents.

CVE-2023-1540
answerdev/answer General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-204 1 PoC

Observable Response Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2023-21925
Health Sciences InForm Web Database
5.3
MEDIUM
EPSS
0.5%
2023 1 PoC

Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Health Sciences InForm. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/

CVE-2023-21904
Banking Virtual Account Management Web Database
5.3
MEDIUM
EPSS
0.6%
2023 1 PoC

Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Banking Virtual Acco

CVE-2023-46666
Elastic Sharepoint Online Python Connector Database Windows
5.3
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that user would have read permissions to all content on the Sharepoint site through Elasticsearch.

CVE-2023-3553
nilsteampassnet/teampass General
5.3
MEDIUM
EPSS
0.6%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository nilsteampassnet/teampass prior to 3.0.10.