7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-46297
Software Genérico Web Networking
5.1
MEDIUM
EPSS
0.1%
2023 1 PoC

An issue was discovered on Mercusys MW325R EU V3 MW325R(EU)_V3_1.11.0 221019 devices. A WAN attacker can make the admin interface unreachable/invisible via an unauthenticated HTTP request. Verification of the data sent by the user does not occur. The web server does not crash, but the admin interface becomes invisible, because the files necessary to display the content are no longer available. A reboot of the router is typically required to restore the correct behavior.

CVE-2023-4434
hamza417/inure General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-862 1 PoC

Missing Authorization in GitHub repository hamza417/inure prior to build88.

CVE-2023-5862
hamza417/inure General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-862 1 PoC

Missing Authorization in GitHub repository hamza417/inure prior to Build95.

CVE-2023-28054
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-28033
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-25938
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-53920
PodcastGenerator Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the podcast title field accessible through the podcast details interface (podcast_details.php). Malicious JavaScript payloads injected into the podcast title execute when users visit the application's home page.

CVE-2023-53916
Zenphoto Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Zenphoto 1.6 contains a stored cross-site scripting vulnerability in the user postal code field accessible through the admin-users.php interface. When administrators view user information imported as HTML, malicious JavaScript payloads injected into the postal code field execute in their browser context.

CVE-2023-22041
Java SE JDK and JRE Database
5.1
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u371-perf, 11.0.19, 17.0.7, 20.0.1; Oracle GraalVM Enterprise Edition: 20.3.10, 21.3.6, 22.3.2; Oracle GraalVM for JDK: 17.0.7 and 20.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK executes to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition, Orac

CVE-2023-53978
myBB forums Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum announcement system that allows authenticated administrators to inject malicious scripts when creating announcements. Attackers can exploit this vulnerability by inserting script payloads in the announcement title field when adding announcements through the 'Forums and Posts' > 'Forum Announcements' interface, causing arbitrary JavaScript to execute when the announcement is displayed on the forum.

CVE-2023-53904
Xenforo Web
5.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Xenforo 2.2.13 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the smilie category title parameter. Attackers can create a smilie category with a malicious script that will execute when the admin panel is loaded, potentially enabling further client-side attacks.

CVE-2023-54361
Joomla iProperty Real Estate Web
5.1
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the filter_keyword parameter. Attackers can craft URLs containing JavaScript payloads in the filter_keyword GET parameter of the all-properties-with-map endpoint to execute arbitrary code in victim browsers and steal session tokens or credentials.

CVE-2023-28056
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVE-2023-53741
Screen SFT DAB Series - Compact Radio DAB Transmitter Web
5.1
MEDIUM
EPSS
0.3%
2023 CWE-384 2 PoCs

Screen SFT DAB 1.9.3 contains a weak session management vulnerability that allows attackers to bypass authentication controls by reusing IP address-bound session identifiers. Attackers can exploit the vulnerable API by intercepting and reusing established sessions to remove user accounts without proper authorization.

CVE-2023-28029
CPG BIOS General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable

CVE-2023-6363
Valhall GPU Kernel Driver General
5.1
MEDIUM
EPSS
0.0%
2023 CWE-416 1 PoC

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory. This issue affects Valhall GPU Kernel Driver: from r41p0 through r47p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r47p0.

CVE-2023-2629
pimcore/customer-data-framework General
5.0
MEDIUM
EPSS
0.0%
2023 CWE-1236 1 PoC

Improper Neutralization of Formula Elements in a CSV File in GitHub repository pimcore/customer-data-framework prior to 3.3.9.

CVE-2023-5536
Ubuntu Server General
5.0
MEDIUM
EPSS
0.0%
2023 1 PoC

A feature in LXD (LP#1829071), affects the default configuration of Ubuntu Server which allows privileged users in the lxd group to escalate their privilege to root without requiring a sudo password.

CVE-2023-26431
OX App Suite General
5.0
MEDIUM
EPSS
0.2%
2023 CWE-918 1 PoC

IPv4-mapped IPv6 addresses did not get recognized as "local" by the code and a connection attempt is made. Attackers with access to user accounts could use this to bypass existing deny-list functionality and trigger requests to restricted network infrastructure to gain insight about topology and running services. We now respect possible IPV4-mapped IPv6 addresses when checking if contained in a deny-list. No publicly available exploits are known.

CVE-2023-26435
OX App Suite General
5.0
MEDIUM
EPSS
0.2%
2023 CWE-918 1 PoC

It was possible to call filesystem and network references using the local LibreOffice instance using manipulated ODT documents. Attackers could discover restricted network topology and services as well as including local files with read permissions of the open-xchange system user. This was limited to specific file-types, like images. We have improved existing content filters and validators to avoid including any local resources. No publicly available exploits are known.