7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-6633
Site Notes Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Site Notes WordPress plugin through 2.0.0 does not have CSRF checks in some of its functionalities, which could allow attackers to make logged in users perform unwanted actions, such as deleting administration notes, via CSRF attacks

CVE-2023-2808
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-20 1 PoC

Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlink, allowing an attacker to trigger link preview on a disallowed domain using a specially crafted link.

CVE-2023-6292
Ecwid Ecommerce Shopping Cart Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Ecwid Ecommerce Shopping Cart WordPress plugin before 6.12.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVE-2023-45806
discourse General
4.3
MEDIUM
EPSS
4.0%
2023 CWE-1333 1 PoC

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, if a user has been quoted and uses a `|` in their full name, they might be able to trigger a bug that generates a lot of duplicate content in all the posts they've been quoted by updating their full name again. Version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches contain a patch for this issue. No known workaround exists, although one can stop the "bleeding" by ensuring u

CVE-2023-23856
SAP BusinessObjects Business Intelligence (Web Intelligence UI) Web
4.3
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

In SAP BusinessObjects Business Intelligence (Web Intelligence user interface) - version 430, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls directly the jsp of Web Intelligence DHTML may be vulnerable to XSS attacks. On successful exploitation an attacker can cause a low impact on integrity of the application.

CVE-2023-21959
iReceivables Web Database
4.3
MEDIUM
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (component: Attachments). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iReceivables. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle iReceivables accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVE-2023-24499
Butterfly Button plugin General
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Butterfly Button plugin may leave traces of its use on user's device. Since it is used for reporting domestic problems, this may lead to spouse knowing about its use.

CVE-2023-3585
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-400 1 PoC

Mattermost Boards fail to properly validate a board link, allowing an attacker to crash a channel by posting a specially crafted boards link.

CVE-2023-3786
Komet General
4.3
MEDIUM
EPSS
0.0%
2023 CWE-284 2 PoCs

A vulnerability classified as problematic has been found in Aures Komet up to 20230509. This affects an unknown part of the component Kiosk Mode. The manipulation leads to improper access controls. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The identifier VDB-235053 was assigned to this vulnerability.

CVE-2023-2287
Orbit Fox by ThemeIsle Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Orbit Fox by ThemeIsle WordPress plugin before 2.10.24 does not limit URLs which may be used for the stock photo import feature, allowing the user to specify arbitrary URLs. This leads to a server-side request forgery as the user may force the server to access any URL of their choosing.

CVE-2023-25750
Firefox General
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private browsing mode. This vulnerability affects Firefox < 111.

CVE-2023-1858
Earnings and Expense Tracker App Web
4.3
MEDIUM
EPSS
0.2%
2023 CWE-200 1 PoC

A vulnerability was found in SourceCodester Earnings and Expense Tracker App 1.0. It has been classified as problematic. This affects an unknown part of the file index.php. The manipulation of the argument page leads to information disclosure. It is possible to initiate the attack remotely. The identifier VDB-224997 was assigned to this vulnerability.

CVE-2023-7196
Ultimate Noindex Nofollow Tool Web Windows
4.3
MEDIUM
EPSS
0.3%
2023 1 PoC

The Ultimate Noindex Nofollow Tool WordPress plugin through 1.1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2023-1197
uvdesk/community-skeleton Web
4.3
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository uvdesk/community-skeleton prior to 1.1.0.

CVE-2023-30682
Samsung Mobile Devices Web
4.3
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call silenceRinger API without permission.

CVE-2023-5546
Software Genérico Web
4.3
MEDIUM
EPSS
1.8%
2023 CWE-79 1 PoC

ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.

CVE-2023-6766
Teacher Subject Allocation Management System Web
4.3
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

A vulnerability classified as problematic has been found in PHPGurukul Teacher Subject Allocation Management System 1.0. Affected is an unknown function of the file /admin/course.php of the component Delete Course Handler. The manipulation of the argument delid leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247896.

CVE-2023-21834
Self-Service Human Resources Web Database
4.3
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Workflow, Approval, Work Force Management). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Self-Service Human Resources. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Self-Service Human Resources accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/

CVE-2023-4113
Service Booking Script Web ⚡ nuclei
4.3
MEDIUM
EPSS
15.1%
2023 CWE-79 1 PoC

A vulnerability was found in PHP Jabbers Service Booking Script 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is VDB-235960. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-7198
WP Dashboard Notes Web Windows
4.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses a significant security risk as it violates the principle of least privilege and compromises the integrity and privacy of user data.