7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-43066
Unity General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-78 1 PoC

Dell Unity prior to 5.3 contains a Restricted Shell Bypass vulnerability. This could allow an authenticated, local attacker to exploit this vulnerability by authenticating to the device CLI and issuing certain commands.

CVE-2023-28036
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-28041
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-25937
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-21484
Samsung Mobile Devices General
5.1
MEDIUM
EPSS
0.1%
2023 CWE-287 1 PoC

Improper access control vulnerability in AppLock prior to SMR May-2023 Release 1 allows local attackers without proper permission to execute a privileged operation.

CVE-2023-53927
Simple CMS Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

PHPJabbers Simple CMS 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through section name parameters. Attackers can create sections with embedded JavaScript payloads that will execute when administrators view the sections, potentially enabling client-side code execution.

CVE-2023-54362
Cart Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the keyword parameter. Attackers can craft malicious URLs containing script payloads in the keyword parameter of the product-variants endpoint to execute arbitrary JavaScript in victim browsers and steal session tokens or credentials.

CVE-2023-53903
WebsiteBaker Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files with script tags that execute when the file is viewed, enabling persistent cross-site scripting attacks.

CVE-2023-1270
btcpayserver/btcpayserver Web
5.1
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting in GitHub repository btcpayserver/btcpayserver prior to 1.8.3.

CVE-2023-54332
Jetpack Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious scripts through the post_id parameter. Attackers can craft malicious URLs with script payloads to execute arbitrary JavaScript in victims' browsers when they interact with the contact form page.

CVE-2023-53932
Serendipity Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Serendipity 2.4.0 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through blog entry creation. Attackers can craft entries with JavaScript payloads that will execute when other users view the compromised blog post.

CVE-2023-54363
Joomla Solidres Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating multiple GET parameters including show, reviews, type_id, distance, facilities, categories, prices, location, and Itemid. Attackers can craft malicious URLs containing JavaScript payloads in these parameters to steal session tokens, login credentials, or manipulate site content when victims visit the crafted links.

CVE-2023-54337
Sysax Multi Server General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-1284 2 PoCs

Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the application. Attackers can overwrite the password field with 800 bytes of repeated characters to trigger an application crash and disrupt server functionality.

CVE-2023-53887
Zomplog Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Zomplog 3.9 contains a cross-site scripting vulnerability that allows authenticated users to inject malicious scripts when creating new pages. Attackers can craft malicious image source and onerror attributes to execute arbitrary JavaScript code in victim's browser.

CVE-2023-28061
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-42574
GameHomeCN General
5.1
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper access control vulnerablility in GameHomeCN prior to version 4.2.60.2 allows local attackers to launch arbitrary activity in GameHomeCN.

CVE-2023-28034
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-1704
pimcore/pimcore Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.20.

CVE-2023-53891
Blackcat CMS Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Blackcat CMS 1.4 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into page content. Attackers can insert JavaScript payloads in the page modification interface that execute when other users view the compromised page.

CVE-2023-21487
Samsung Mobile Devices General
5.1
MEDIUM
EPSS
0.1%
2023 CWE-287 1 PoC

Improper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows local attackers to change a call setting.