7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-0999
Sales Tracker Management System Web
4.3
MEDIUM
EPSS
0.3%
2023 CWE-352 1 PoC

A vulnerability classified as problematic was found in SourceCodester Sales Tracker Management System 1.0. This vulnerability affects unknown code of the file admin/?page=user/list. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-221734 is the identifier assigned to this vulnerability.

CVE-2023-21426
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-798 1 PoC

Hardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardemulation PIN.

CVE-2023-21927
JD Edwards EnterpriseOne Tools Web Database
4.3
MEDIUM
EPSS
0.3%
2023 1 PoC

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Interoperability SEC). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVE-2023-5375
mosparo/mosparo General ⚡ nuclei
4.3
MEDIUM
EPSS
43.3%
2023 CWE-601 1 PoC

Open Redirect in GitHub repository mosparo/mosparo prior to 1.0.2.

CVE-2023-5198
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2023 CWE-863 1 PoC

An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a removed project member to write to protected branches using deploy keys.

CVE-2023-1158
Pentaho Business Analytics Server General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-863 1 PoC

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x expose dashboard prompts to users who are not part of the authorization list. 

CVE-2023-28599
Zoom for Android General
4.3
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victim to a malicious website during meeting creation.

CVE-2023-4869
Contact Manager App Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

A vulnerability was found in SourceCodester Contact Manager App 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file update.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-239354 is the identifier assigned to this vulnerability.

CVE-2023-7195
WP-Reply Notify Web Windows
4.3
MEDIUM
EPSS
0.3%
2023 1 PoC

The WP-Reply Notify WordPress plugin through 1.1 does not have a CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.

CVE-2023-0484
Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-5329
DataCube4 Web
4.3
MEDIUM
EPSS
0.2%
2023 CWE-287 1 PoC

A vulnerability classified as problematic was found in Field Logic DataCube4 up to 20231001. This vulnerability affects unknown code of the file /api/ of the component Web API. The manipulation leads to improper authentication. The exploit has been disclosed to the public and may be used. VDB-241030 is the identifier assigned to this vulnerability.

CVE-2023-1417
GitLab DevOps
4.3
MEDIUM
EPSS
0.6%
2023 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible for an unauthorised user to add child epics linked to victim's epic in an unrelated group.

CVE-2023-4114
Night Club Booking Software Web ⚡ nuclei
4.3
MEDIUM
EPSS
6.8%
2023 CWE-79 2 PoCs

A vulnerability was found in PHP Jabbers Night Club Booking Software 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-235961 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-21941
BI Publisher (formerly XML Publisher) Web Database
4.3
MEDIUM
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVE-2023-2395
SRX5308 General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

A vulnerability classified as problematic has been found in Netgear SRX5308 up to 4.3.5-3. This affects an unknown part of the component Web Management Interface. The manipulation of the argument Login.userAgent leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227673 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-22009
Self-Service Human Resources Web Database
4.3
MEDIUM
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Workforce Management). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Self-Service Human Resources. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Self-Service Human Resources accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVE-2023-5333
Mattermost Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sending a specially crafted request to /api/v4/users/ids with multiple identical IDs.

CVE-2023-1903
HCM Fiori App My Forms (Fiori 2.0) General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

SAP HCM Fiori App My Forms (Fiori 2.0) - version 605, does not perform necessary authorization checks for an authenticated user exposing the restricted header data.

CVE-2023-0467
WP Dark Mode Web Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The WP Dark Mode WordPress plugin before 4.0.8 does not properly sanitize the style parameter in shortcodes before using it to load a PHP template. This leads to Local File Inclusion on servers where non-existent directories may be traversed, or when chained with another vulnerability allowing arbitrary directory creation.

CVE-2023-24058
Software Genérico Web
4.3
MEDIUM
EPSS
0.5%
2023 2 PoCs

Booked Scheduler 2.5.5 allows authenticated users to create and schedule events for any other user via a modified userId value to reservation_save.php. NOTE: 2.5.5 is a version from 2014; the latest version of Booked Scheduler is not affected. However, LabArchives Scheduler (Sep 6, 2022 Feature Release) is affected.