7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-47865
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Mattermost fails to check if hardened mode is enabled when overriding the username and/or the icon when posting a post. If settings allowed integrations to override the username and profile picture when posting, a member could also override the username and icon when making a post even if the Hardened Mode setting was enabled

CVE-2023-2786
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

Mattermost fails to properly check the permissions when executing commands allowing a member with no permissions to post a message in a channel to actually post it by executing channel commands.

CVE-2023-46089
Userback Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in Lee Le @ Userback Userback plugin <= 1.0.13 versions.

CVE-2023-22013
Business Intelligence Enterprise Edition Web Database
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). Supported versions that are affected are 6.4.0.0.0 and 7.0.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/A

CVE-2023-6296
osCommerce General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

A vulnerability was found in osCommerce 4. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /catalog/compare of the component Instant Message Handler. The manipulation of the argument compare with the input 40dz4iq"><script>alert(1)</script>zohkx leads to cross site scripting. The attack may be launched remotely. VDB-246122 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-4439
Card Holder Management System General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-1284 1 PoC

A vulnerability was found in SourceCodester Card Holder Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Minus Value Handler. The manipulation leads to improper validation of specified quantity in input. The attack may be launched remotely. The identifier of this vulnerability is VDB-237560.

CVE-2023-4036
Simple Blog Card Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Simple Blog Card WordPress plugin before 1.32 does not ensure that posts to be displayed via a shortcode are public, allowing any authenticated users, such as subscriber, to retrieve arbitrary post title and their content such as draft, private and password protected ones

CVE-2023-5352
Awesome Support Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Awesome Support WordPress plugin before 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing users to edit posts for which they do not have permission.

CVE-2023-25749
Firefox General
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

Android applications with unpatched vulnerabilities can be launched from a browser using Intents, exposing users to these vulnerabilities. Firefox will now confirm with users that they want to launch an external application before doing so. <br>*This bug only affects Firefox for Android. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 111.

CVE-2023-1911
Blocksy Companion Web Windows
4.3
MEDIUM
EPSS
0.3%
2023 1 PoC

The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example

CVE-2023-0498
WP Education Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Education WordPress plugin before 1.2.7 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack

CVE-2023-5889
pkp/pkp-lib General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

CVE-2023-6899
DashMachine General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-94 1 PoC

A vulnerability classified as problematic was found in rmountjoy92 DashMachine 0.5-4. Affected by this vulnerability is an unknown functionality of the file /settings/save_config of the component Config Handler. The manipulation of the argument value_template leads to code injection. The exploit has been disclosed to the public and may be used. The identifier VDB-248257 was assigned to this vulnerability.

CVE-2023-43754
Mattermost General
4.3
MEDIUM
EPSS
0.4%
2023 CWE-200 1 PoC

Mattermost fails to check whether the  “Allow users to view archived channels”  setting is enabled during permalink previews display, allowing members to view permalink previews of archived channels even if the “Allow users to view archived channels” setting is disabled. 

CVE-2023-5331
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

Mattermost fails to properly check the creator of an attached file when adding the file to a draft post, potentially exposing unauthorized file information.

CVE-2023-4318
Herd Effects Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items, which could allow attackers to make logged in admins delete arbitrary effects via a CSRF attack

CVE-2023-48906
Software Genérico General
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Stack Overflow vulnerability in Btstack 1.6 and earlier allows attackers to cause a denial of service via crafted input to the char_for_nibble function.

CVE-2023-3964
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2023 CWE-863 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer packages on public projects that have package registry disabled in the project settings.

CVE-2023-1680
CMS Web
4.3
MEDIUM
EPSS
0.3%
2023 CWE-200 1 PoC

A vulnerability, which was classified as problematic, has been found in Xunrui CMS 4.61. This issue affects some unknown processing of the file /dayrui/My/View/main.html. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-224237 was assigned to this vulnerability.

CVE-2023-6633
Site Notes Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Site Notes WordPress plugin through 2.0.0 does not have CSRF checks in some of its functionalities, which could allow attackers to make logged in users perform unwanted actions, such as deleting administration notes, via CSRF attacks