7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-6341
CMS360 Web Cloud
5.3
MEDIUM
EPSS
0.9%
2023 CWE-639 1 PoC

Catalis (previously Icon Software) CMS360 allows a remote, unauthenticated attacker to view sensitive court documents by modifying document and other identifiers in URLs. The impact varies based on the intention and configuration of a specific CMS360 installation.

CVE-2023-2241
PoDoFo General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-122 1 PoC

A vulnerability, which was classified as critical, was found in PoDoFo 0.10.0. Affected is the function readXRefStreamEntry of the file PdfXRefStreamParserObject.cpp. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as 535a786f124b739e3c857529cecc29e4eeb79778. It is recommended to apply a patch to fix this issue. VDB-227226 is the identifier assigned to this vulnerability.

CVE-2023-6459
Mattermost General
5.3
MEDIUM
EPSS
0.5%
2023 CWE-200 1 PoC

Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint is revealing channelIDs.

CVE-2023-21825
iSupplier Portal Web Database
5.3
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Supplier Management). Supported versions that are affected are 12.2.6-12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupplier Portal. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle iSupplier Portal accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2023-26144
graphql General
5.3
MEDIUM
EPSS
2.1%
2023 CWE-400 1 PoC

Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries. This vulnerability allows an attacker to degrade system performance. **Note:** It was not proven that this vulnerability can crash the process.

CVE-2023-1999
libwebp General
5.3
MEDIUM
EPSS
0.4%
2023 CWE-416 1 PoC

There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.

CVE-2023-47668
Membership Plugin – Restrict Content General
5.3
MEDIUM
EPSS
5.5%
2023 CWE-200 2 PoCs

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StellarWP Membership Plugin – Restrict Content plugin <= 3.2.7 versions.

CVE-2023-21916
PeopleSoft Enterprise PT PeopleTools Web Database
5.3
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Web Server). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2023-31286
Software Genérico General
5.3
MEDIUM
EPSS
0.4%
2023 3 PoCs

An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When a password reset request occurs, the server response leaks the existence of users. If one tries to reset a password of a non-existent user, an error message indicates that this user does not exist.

CVE-2023-21831
PeopleSoft Enterprise CS Academic Advisement Web Database
5.3
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the PeopleSoft Enterprise CS Academic Advisement product of Oracle PeopleSoft (component: Advising Notes). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Academic Advisement. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise CS Academic Advisement accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2023-2617
wechat_qrcode Module General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

A vulnerability classified as problematic was found in OpenCV wechat_qrcode Module up to 4.7.0. Affected by this vulnerability is the function DecodedBitStreamParser::decodeByteSegment of the file qrcode/decoder/decoded_bit_stream_parser.cpp. The manipulation leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-228547.

CVE-2023-0311
thorsten/phpmyfaq Web
5.3
MEDIUM
EPSS
1.4%
2023 CWE-287 1 PoC

Improper Authentication in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

CVE-2023-43491
Smart Reader Web
5.3
MEDIUM
EPSS
0.8%
2023 CWE-284 2 PoCs

An information disclosure vulnerability exists in the web interface /cgi-bin/debug_dump.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

CVE-2023-6447
EventPrime Web Windows
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id/event name.

CVE-2023-6354
Magistrate Court Case Management Plus General
5.3
MEDIUM
EPSS
1.0%
2023 CWE-287 1 PoC

Tyler Technologies Magistrate Court Case Management Plus allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the PDFViewer.aspx 'filename' parameter.

CVE-2023-2322
pimcore/pimcore Web
5.2
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-3565
nilsteampassnet/teampass Web
5.2
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

CVE-2023-43074
Unity General
5.2
MEDIUM
EPSS
0.0%
2023 CWE-73 1 PoC

Dell Unity 5.3 contain(s) an Arbitrary File Creation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by crafting arbitrary files through a request to the server.

CVE-2023-28904
Volkswagen MIB3 infotainment system MIB3 OI MQB General
5.2
MEDIUM
EPSS
0.0%
2023 CWE-120 2 PoCs

A logic flaw leading to a RAM buffer overflow in the bootloader component of the MIB3 infotainment unit allows an attacker with physical access to the MIB3 ECU to bypass firmware signature verification and run arbitrary code in the infotainment system at boot process.

CVE-2023-1789
firefly-iii/firefly-iii General
5.2
MEDIUM
EPSS
0.2%
2023 CWE-20 1 PoC

Improper Input Validation in GitHub repository firefly-iii/firefly-iii prior to 6.0.0.