7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-5681
NS-ASG Application Security Gateway Web Database
4.7
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /admin/list_addr_fwresource_ip.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243057 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-45671
frigate Web ⚡ nuclei
4.7
MEDIUM
EPSS
32.1%
2023 CWE-79 0 PoCs

Frigate is an open source network video recorder. Prior to version 0.13.0 Beta 3, there is a reflected cross-site scripting vulnerability in any API endpoints reliant on the `/<camera_name>` base path as values provided for the path are not sanitized. Exploiting this vulnerability requires the attacker to both know very specific information about a user's Frigate server and requires an authenticated user to be tricked into clicking a specially crafted link to their Frigate instance. This vulnerability could exploited by an attacker under the following circumstances: Frigate publicly exposed to

CVE-2023-32068
xwiki-platform Web ⚡ nuclei
4.7
MEDIUM
EPSS
67.1%
2023 CWE-601 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 14.10.4 it's possible to exploit well known parameters in XWiki URLs to perform redirection to untrusted site. This vulnerability was partially fixed in the past for XWiki 12.10.7 and 13.3RC1 but there is still the possibility to force specific URLs to skip some checks, e.g. using URLs like `http:example.com` in the parameter would allow the redirect. The issue has now been patched against all patterns that are known for performing redirects. This issue has been patche

CVE-2023-30726
GameLauncher General
4.7
MEDIUM
EPSS
0.1%
2023 1 PoC

PendingIntent hijacking vulnerability in GameLauncher prior to version 4.2.59.5 allows local attackers to access data.

CVE-2023-0528
Online Tours & Travels Management System Web Database
4.7
MEDIUM
EPSS
0.3%
2023 CWE-89 1 PoC

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. This affects an unknown part of the file admin/abc.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-219597 was assigned to this vulnerability.

CVE-2023-5966
EspoCRM Web
4.7
MEDIUM
EPSS
0.5%
2023 CWE-434 2 PoCs

An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the extension deployment form, which could lead to arbitrary PHP code execution.

CVE-2023-6176
Red Hat Enterprise Linux 8 Web
4.7
MEDIUM
EPSS
0.0%
2023 1 PoC

A null pointer dereference flaw was found in the Linux kernel API for the cryptographic algorithm scatterwalk functionality. This issue occurs when a user constructs a malicious packet with specific socket configuration, which could allow a local user to crash the system or escalate their privileges on the system.

CVE-2023-2307
builderio/qwik Web
4.7
MEDIUM
EPSS
0.2%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository builderio/qwik prior to 0.104.0.

CVE-2023-2515
Mattermost General
4.7
MEDIUM
EPSS
0.1%
2023 CWE-863 1 PoC

Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to system admin

CVE-2023-49986
Software Genérico Web
4.7
MEDIUM
EPSS
0.2%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in the component /admin/parent of School Fees Management System 1.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.

CVE-2023-1391
Online Tours & Travels Management System Web
4.7
MEDIUM
EPSS
0.4%
2023 CWE-434 1 PoC

A vulnerability, which was classified as problematic, was found in SourceCodester Online Tours & Travels Management System 1.0. Affected is an unknown function of the file admin/ab.php. The manipulation of the argument img leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-222978 is the identifier assigned to this vulnerability.

CVE-2023-0532
Online Tours & Travels Management System Web Database
4.7
MEDIUM
EPSS
0.2%
2023 CWE-89 1 PoC

A vulnerability classified as critical was found in SourceCodester Online Tours & Travels Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/disapprove_user.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-219601 was assigned to this vulnerability.

CVE-2023-7179
Online College Library System Web Database
4.7
MEDIUM
EPSS
0.0%
2023 CWE-89 1 PoC

A vulnerability, which was classified as critical, was found in Campcodes Online College Library System 1.0. Affected is an unknown function of the file /admin/category_row.php of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-249366 is the identifier assigned to this vulnerability.

CVE-2023-41911
Software Genérico General
4.7
MEDIUM
EPSS
0.1%
2023 1 PoC

Samsung Mobile Processor Exynos 2200 allows a GPU Double Free (issue 1 of 2).

CVE-2023-0943
Best POS Management System Web
4.7
MEDIUM
EPSS
5.8%
2023 CWE-434 1 PoC

A vulnerability, which was classified as problematic, has been found in SourceCodester Best POS Management System 1.0. This issue affects the function save_settings of the file index.php?page=site_settings of the component Image Handler. The manipulation of the argument img with the input ../../shell.php leads to unrestricted upload. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-221591.

CVE-2023-7212
DeDeCMS Web
4.7
MEDIUM
EPSS
0.0%
2023 CWE-434 1 PoC

A vulnerability classified as critical has been found in DeDeCMS up to 5.7.112. Affected is an unknown function of the file file_class.php of the component Backend. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249768. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-5965
EspoCRM Web
4.7
MEDIUM
EPSS
0.5%
2023 CWE-434 2 PoCs

An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the update form, which could lead to arbitrary PHP code execution.

CVE-2023-25200
Software Genérico General
4.7
MEDIUM
EPSS
0.1%
2023 1 PoC

An HTML injection vulnerability exists in the MT Safeline X-Ray X3310 webserver version NXG 19.05 that enables a remote attacker to render malicious HTML and obtain sensitive information in a victim's browser.

CVE-2023-34970
Valhall GPU Kernel Driver General
4.7
MEDIUM
EPSS
0.1%
2023 CWE-416 1 PoC

A local non-privileged user can make improper GPU processing operations to access a limited amount outside of buffer bounds or to exploit a software race condition. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory

CVE-2023-0160
kernel General
4.7
MEDIUM
EPSS
0.0%
2023 CWE-833 1 PoC

A deadlock flaw was found in the Linux kernel’s BPF subsystem. This flaw allows a local user to potentially crash the system.