7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-45223
Mattermost General
4.3
MEDIUM
EPSS
0.4%
2023 CWE-200 1 PoC

Mattermost fails to properly validate the "Show Full Name" option in a few endpoints in Mattermost Boards, allowing a member to get the full name of another user even if the Show Full Name option was disabled. 

CVE-2023-6384
WP User Profile Avatar Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar

CVE-2023-3760
SGS General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability has been found in Intergard SGS 8.7.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Change Password Handler. The manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-234445 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-6761
IceCMS Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

A vulnerability, which was classified as problematic, has been found in Thecosy IceCMS up to 2.0.1. This issue affects some unknown processing of the component User Data Handler. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247889 was assigned to this vulnerability.

CVE-2023-7092
UW-302VP Web
4.3
MEDIUM
EPSS
0.2%
2023 CWE-352 2 PoCs

A vulnerability was found in Uniway UW-302VP 2.0. It has been rated as problematic. This issue affects some unknown processing of the file /boaform/wlan_basic_set.cgi of the component Admin Web Interface. The manipulation of the argument wlanssid/password leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248939. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-34115
Zoom Meeting SDK General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-120 1 PoC

Buffer copy without checking size of input in Zoom Meeting SDK before 5.13.0 may allow an authenticated user to potentially enable a denial of service via local access. This issue may result in the Zoom Meeting SDK to crash and need to be restarted.

CVE-2023-6385
WordPress Ping Optimizer Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WordPress Ping Optimizer WordPress plugin through 2.35.1.3.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as clearing logs.

CVE-2023-1939
Remote Desktop Manager Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

No access control for the OTP key   on OTP entries in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prior versions and Remote Desktop Manager Linux 2022.3.2.0 and prior versions allows non admin users to see OTP keys via the user interface.

CVE-2023-6843
easy.jobs- Best Recruitment Plugin for Job Board Listing, Manager, Career Page for Elementor & Gutenberg Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The easy.jobs- Best Recruitment Plugin for Job Board Listing, Manager, Career Page for Elementor & Gutenberg WordPress plugin before 2.4.7 does not properly secure some of its AJAX actions, allowing any logged-in users to modify its settings.

CVE-2023-0497
HT Portfolio Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The HT Portfolio WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-48369
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to different endpoints to potentially overflow the log.

CVE-2023-3706
ActivityPub Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The ActivityPub WordPress plugin before 1.0.0 does not ensure that post titles to be displayed are public and belong to the plugin, allowing any authenticated user, such as subscriber to retrieve the title of arbitrary post (such as draft and private) via an IDOR vector

CVE-2023-7125
Community by PeepSo Web Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The Community by PeepSo WordPress plugin before 6.3.1.2 does not have CSRF check when creating a user post (visible on their wall in their profile page), which could allow attackers to make logged in users perform such action via a CSRF attack

CVE-2023-2765
OA Web
4.3
MEDIUM
EPSS
0.3%
2023 CWE-36 1 PoC

A vulnerability has been found in Weaver OA up to 9.5 and classified as problematic. This vulnerability affects unknown code of the file /E-mobile/App/System/File/downfile.php. The manipulation of the argument url leads to absolute path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-229270 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-7040
Stupid Simple CMS Web
4.3
MEDIUM
EPSS
0.3%
2023 CWE-24 1 PoC

A vulnerability classified as problematic was found in codelyfe Stupid Simple CMS up to 1.2.4. Affected by this vulnerability is an unknown functionality of the file /file-manager/rename.php. The manipulation of the argument oldName leads to path traversal: '../filedir'. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-248689 was assigned to this vulnerability.

CVE-2023-26433
OX App Suite General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

When adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue IMAP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit accepted IMAP server response to reasonable length/size. No publicly available exploits are known.

CVE-2023-2945
openemr/openemr General
4.3
MEDIUM
EPSS
0.3%
2023 CWE-862 1 PoC

Missing Authorization in GitHub repository openemr/openemr prior to 7.0.1.

CVE-2023-0999
Sales Tracker Management System Web
4.3
MEDIUM
EPSS
0.3%
2023 CWE-352 1 PoC

A vulnerability classified as problematic was found in SourceCodester Sales Tracker Management System 1.0. This vulnerability affects unknown code of the file admin/?page=user/list. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-221734 is the identifier assigned to this vulnerability.

CVE-2023-21426
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-798 1 PoC

Hardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardemulation PIN.

CVE-2023-5375
mosparo/mosparo General ⚡ nuclei
4.3
MEDIUM
EPSS
43.3%
2023 CWE-601 1 PoC

Open Redirect in GitHub repository mosparo/mosparo prior to 1.0.2.