Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In May 2023
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alex Benfica Publish to Schedule plugin <= 4.5.4 versions.
CVSS Score
5.9
EPSS Score
0.001
Published
2023-05-06
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 246115.
CVSS Score
5.4
EPSS Score
0.002
Published
2023-05-06
IBM UrbanCode Deploy (UCD) versions up to 7.3.0.1 could disclose sensitive password information during a manual edit of the agentrelay.properties file. IBM X-Force ID: 240148.
CVSS Score
5.1
EPSS Score
0.0
Published
2023-05-06
IBM QRadar Data Synchronization App 1.0 through 3.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 217370.
CVSS Score
4.4
EPSS Score
0.0
Published
2023-05-06
A vulnerability was found in PHP-Login 1.0. It has been declared as critical. This vulnerability affects the function checkLogin of the file login/scripts/class.loginscript.php of the component POST Parameter Handler. The manipulation of the argument myusername leads to sql injection. The attack can be initiated remotely. Upgrading to version 2.0 is able to address this issue. The patch is identified as 0083ec652786ddbb81335ea20da590df40035679. It is recommended to upgrade the affected component. VDB-228022 is the identifier assigned to this vulnerability.
CVSS Score
7.3
EPSS Score
0.001
Published
2023-05-06
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVSS Score
7.5
EPSS Score
0.002
Published
2023-05-05
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVSS Score
4.7
EPSS Score
0.003
Published
2023-05-05
S-CMS v5.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /admin/ajax.php.
CVSS Score
7.2
EPSS Score
0.015
Published
2023-05-05
MitraStar GPT-2741GNAC-N2 with firmware BR_g5.9_1.11(WVK.0)b32 was discovered to contain a remote code execution (RCE) vulnerability in the ping function.
CVSS Score
8.8
EPSS Score
0.014
Published
2023-05-05
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.13.
CVSS Score
8.2
EPSS Score
0.0
Published
2023-05-05


Contact Us

Shodan ® - All rights reserved