7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-5967
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-754 1 PoC

Mattermost fails to properly validate requests to the Calls plugin, allowing an attacker sending a request without a User Agent header to cause a panic and crash the Calls plugin

CVE-2023-30949
com.palantir.slate:slate General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-1173 1 PoC

A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the page's content, which could lead to phishing attacks.

CVE-2023-5498
chiefonboarding/chiefonboarding Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository chiefonboarding/chiefonboarding prior to v2.0.47.

CVE-2023-0762
Clock In Portal- Staff & Attendance Management Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting designations, which could allow attackers to make logged in admins delete arbitrary designations via a CSRF attack

CVE-2023-6257
Inline Related Posts Web Windows
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The Inline Related Posts WordPress plugin before 3.6.0 is missing authorization in an AJAX action to ensure that users are allowed to see the content of the posts displayed, allowing any authenticated user, such as subscriber to retrieve the content of password protected posts

CVE-2023-6577
PatrolFlow 2530Pro Web
4.3
MEDIUM
EPSS
0.0%
2023 CWE-22 1 PoC

A vulnerability was found in Byzoro PatrolFlow 2530Pro up to 20231126. It has been rated as problematic. This issue affects some unknown processing of the file /log/mailsendview.php. The manipulation of the argument file with the input /boot/phpConfig/tb_admin.txt leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247157 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-3920
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2023 CWE-863 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation.

CVE-2023-2902
Rapid Development Platform Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

A vulnerability was found in NFine Rapid Development Platform 20230511. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /SystemManage/Organize/GetTreeGridJson?_search=false&nd=1681813520783&rows=10000&page=1&sidx=&sord=asc. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-229976. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-4865
Take-Note App Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 2 PoCs

A vulnerability has been found in SourceCodester Take-Note App 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-239350 is the identifier assigned to this vulnerability.

CVE-2023-3582
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-863 1 PoC

Mattermost fails to verify channel membership when linking a board to a channel allowing a low-privileged authenticated user to link a Board to a private channel they don't have access to, 

CVE-2023-45357
Software Genérico General
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitive information via a popup warning message. 6.14 (6.14.0) is also a fixed release.

CVE-2023-7026
IPTV Gateway Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-434 1 PoC

A vulnerability was found in Lightxun IPTV Gateway up to 20231208. It has been rated as problematic. This issue affects some unknown processing of the file /ZHGXTV/index.php/admin/index/web_upload_template.html. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248579.

CVE-2023-4251
EventPrime Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks.

CVE-2023-3366
MultiParcels Shipping For WooCommerce Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.2 does not have CRSF check when deleting a shipment, allowing attackers to make any logged in user, delete arbitrary shipment via a CSRF attack

CVE-2023-4172
Flash Flood Disaster Monitoring and Warning System General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-36 1 PoC

A vulnerability, which was classified as problematic, has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This issue affects some unknown processing of the file \Service\FileHandler.ashx. The manipulation of the argument FileDirectory leads to absolute path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-236207.

CVE-2023-1034
salesagility/suitecrm General
4.3
MEDIUM
EPSS
2.0%
2023 CWE-29 1 PoC

Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9.

CVE-2023-1680
CMS Web
4.3
MEDIUM
EPSS
0.3%
2023 CWE-200 1 PoC

A vulnerability, which was classified as problematic, has been found in Xunrui CMS 4.61. This issue affects some unknown processing of the file /dayrui/My/View/main.html. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-224237 was assigned to this vulnerability.

CVE-2023-4150
User Activity Tracking and Log Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The User Activity Tracking and Log WordPress plugin before 4.0.9 does not have proper CSRF checks when managing its license, which could allow attackers to make logged in admins update and deactivate the plugin's license via CSRF attacks

CVE-2023-1337
RapidLoad AI – Optimize Web Vitals Automatically Web Windows
4.3
MEDIUM
EPSS
3.7%
2023 CWE-862 1 PoC

The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the clear_uucss_logs function in versions up to, and including, 1.7.1. This makes it possible for authenticated attackers with subscriber-level access to delete plugin log files.

CVE-2023-47865
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a post even if the Hardened Mode setting was enabled