7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-28904
Volkswagen MIB3 infotainment system MIB3 OI MQB General
5.2
MEDIUM
EPSS
0.0%
2023 CWE-120 2 PoCs

A logic flaw leading to a RAM buffer overflow in the bootloader component of the MIB3 infotainment unit allows an attacker with physical access to the MIB3 ECU to bypass firmware signature verification and run arbitrary code in the infotainment system at boot process.

CVE-2023-2343
pimcore/pimcore Web
5.2
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-1789
firefly-iii/firefly-iii General
5.2
MEDIUM
EPSS
0.2%
2023 CWE-20 1 PoC

Improper Input Validation in GitHub repository firefly-iii/firefly-iii prior to 6.0.0.

CVE-2023-28600
Zoom for macOS Client General
5.2
MEDIUM
EPSS
0.1%
2023 CWE-378 1 PoC

Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to delete/replace Zoom Client files potentially causing a loss of integrity and availability to the Zoom Client.

CVE-2023-5564
froxlor/froxlor Web
5.2
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.1.0-dev1.

CVE-2023-1515
pimcore/pimcore Web
5.2
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.19.

CVE-2023-1067
pimcore/pimcore Web
5.2
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.

CVE-2023-24515
Pandora FMS Web
5.2
MEDIUM
EPSS
0.2%
2023 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) vulnerability in API checker of Pandora FMS. Application does not have a check on the URL scheme used while retrieving API URL. Rather than validating the http/https scheme, the application allows other scheme such as file, which could allow a malicious user to fetch internal file content. This issue affects Pandora FMS v767 version and prior versions on all platforms.

CVE-2023-3469
thorsten/phpmyfaq Web
5.2
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.2.0-beta.2.

CVE-2023-1312
pimcore/pimcore Web
5.2
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.19.

CVE-2023-3291
gpac/gpac General
5.1
MEDIUM
EPSS
0.1%
2023 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.2.

CVE-2023-53936
Cameleon CMS Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts into post titles. Attackers can create posts with embedded SVG scripts that execute when other users mouse over the post title, potentially stealing session cookies and executing arbitrary JavaScript.

CVE-2023-28044
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-30667
Samsung Mobile Devices General
5.1
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper access control in Audio system service prior to SMR Jul-2023 Release 1 allows attacker to send broadcast with system privilege.

CVE-2023-53737
Xperience Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

A stored cross-site scripting vulnerability in Kentico Xperience allows global administrators to inject malicious payloads via the Localization application. Attackers can execute scripts that could affect multiple parts of the administration interface.

CVE-2023-53890
Perch Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Perch CMS 3.2 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG files with script tags that execute when the file is viewed, potentially stealing user session information or performing client-side attacks.

CVE-2023-53897
Rukovoditel Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert XSS payloads in project task comments to execute arbitrary JavaScript in victim browsers.

CVE-2023-54364
Joomla HikaShop Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product filter endpoint. Attackers can craft malicious URLs containing XSS payloads in the from_option, from_ctrl, from_task, or from_itemid parameters to steal session tokens or login credentials when victims visit the link.

CVE-2023-54343
QWE DL Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

QWE DL 2.0.1 mobile web application contains a persistent input validation vulnerability allowing remote attackers to inject malicious script code through path parameter manipulation. Attackers can exploit the vulnerability to execute persistent cross-site scripting attacks, potentially leading to session hijacking and application module manipulation.

CVE-2023-28028
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.