7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-53882
JLex GuestBook Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

JLex GuestBook 1.6.4 contains a reflected cross-site scripting vulnerability in the 'q' URL parameter that allows attackers to inject malicious scripts. Attackers can craft malicious links with XSS payloads to steal session tokens or execute arbitrary JavaScript in victims' browsers.

CVE-2023-54361
Joomla iProperty Real Estate Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the filter_keyword parameter. Attackers can craft URLs containing JavaScript payloads in the filter_keyword GET parameter of the all-properties-with-map endpoint to execute arbitrary code in victim browsers and steal session tokens or credentials.

CVE-2023-5321
hamza417/inure General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-862 1 PoC

Missing Authorization in GitHub repository hamza417/inure prior to build94.

CVE-2023-28028
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-53906
projectSend Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

projectSend r1605 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript through the custom assets configuration page. Attackers can craft a JavaScript payload in the custom assets section that will execute when other users load the affected page, enabling persistent script injection.

CVE-2023-54328
AimOne Video Converter General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-120 1 PoC

AimOne Video Converter 2.04 Build 103 contains a buffer overflow vulnerability in its registration form that causes application crashes. Attackers can generate a 7000-byte payload to trigger the denial of service and potentially exploit the software's registration mechanism.

CVE-2023-53910
WBCE CMS Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by inserting script tags into page content through the WYSIWYG editor. Attackers can submit POST requests to /wbce/modules/wysiwyg/save.php with malicious script content in the content parameter to execute JavaScript when users view the affected page.

CVE-2023-53899
Software Genérico Web
5.1
MEDIUM
EPSS
0.2%
2023 CWE-918 1 PoC

PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Attackers can manipulate the 'shortdesc' parameter to trigger external HTTP requests to arbitrary endpoints during podcast episode creation.

CVE-2023-4681
gpac/gpac General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-21423
Samsung Mobile Devices General
5.1
MEDIUM
EPSS
0.1%
2023 CWE-285 1 PoC

Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without permission using unprotected action.

CVE-2023-30725
Gallery General
5.1
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper authentication in LocalProvier of Gallery prior to version 14.5.01.2 allows attacker to access the data in content provider.

CVE-2023-53961
Impact/Pulse/First Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-352 2 PoCs

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages that submit HTTP requests to the radio processing interface, triggering unintended administrative operations when a logged-in user visits the page.

CVE-2023-53985
Zstore Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Zstore, now referred to as Zippy CRM, 6.5.4 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts through unvalidated input parameters. Attackers can submit crafted payloads in manual insertion points to execute arbitrary JavaScript code in victim's browser context.

CVE-2023-53876
Academy LMS Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-434 1 PoC

Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code.

CVE-2023-53870
Jorani Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Jorani 1.0.3 contains a reflected cross-site scripting vulnerability in the language parameter that allows attackers to inject malicious scripts. Attackers can craft XSS payloads in the language parameter to execute arbitrary JavaScript and potentially steal user session information.

CVE-2023-28059
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-28052
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-28027
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-31001
Security Verify Access Appliance DevOps
5.1
MEDIUM
EPSS
0.0%
2023 CWE-257 1 PoC

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254653.

CVE-2023-53939
TinyWebGallery Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

TinyWebGallery v2.5 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the folder name parameter. Attackers can edit album folder names with script tags to execute arbitrary JavaScript when other users view the affected gallery pages.