9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-25368
Software Genérico General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS is vulnerable to Incorrect Access Control. An unauthenticated attacker can overwrite firmnware.

CVE-2023-21444
Samsung Flow for PC General
7.5
HIGH
EPSS
0.1%
2023 CWE-326 1 PoC

Improper cryptographic implementation in Samsung Flow for PC 4.9.14.0 allows adjacent attackers to decrypt encrypted messages or inject commands.

CVE-2023-43768
Software Genérico General
7.5
HIGH
EPSS
0.5%
2023 2 PoCs

An issue was discovered in Couchbase Server 6.6.x through 7.2.0, before 7.1.5 and 7.2.1. Unauthenticated users may cause memcached to run out of memory via large commands.

CVE-2023-37022
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `UE Context Release Request` packet handler. A packet containing an invalid `MME_UE_S1AP_ID` field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of service.

CVE-2023-28465
Software Genérico General
7.5
HIGH
EPSS
0.7%
2023 2 PoCs

The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain directories via directory traversal, if an allowed directory name is a substring of the directory name chosen by the attacker. NOTE: this issue exists because of an incomplete fix for CVE-2023-24057.

CVE-2023-24474
Experion Server General
7.5
HIGH
EPSS
0.0%
2023 CWE-122 1 PoC

Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message

CVE-2023-36644
Software Genérico General
7.5
HIGH
EPSS
0.7%
2023 1 PoC

Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all order confirmations from the online shop via the printmail plugin.

CVE-2023-27600
opensips General
7.5
HIGH
EPSS
0.8%
2023 CWE-20 1 PoC

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, OpenSIPS crashes when a malformed SDP body is received and is processed by the `delete_sdp_line` function in the sipmsgops module. This issue can be reproduced by calling the function with an SDP body that does not terminate by a line feed (i.e. `\n`). The vulnerability was found while performing black-box fuzzing against an OpenSIPS server running a configuration that made use of the functions `codec_delete_except_re` and `codec_delete_re`. The same issue was also discovered while perfor

CVE-2023-4486
Metasys NAE55/SNE/SNC General
7.5
HIGH
EPSS
0.2%
2023 CWE-400 1 PoC

Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to versions 11.0.6 and 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service.

CVE-2023-27532
🔥 KEV Veeam Backup & Replication General
7.5
HIGH
EPSS
82.3%
2023 CWE-306 3 PoCs

Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.

CVE-2023-23330
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

amano Xparc parking solutions 7.1.3879 was discovered to be vulnerable to local file inclusion.

CVE-2023-29731
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

SoLive 1.6.14 thru 1.6.20 for Android has an exposed component that provides a method to modify the SharedPreference file. An attacker can leverage this method to inject a large amount of data into any SharedPreference file, which will be loaded into memory when the application is opened. When an attacker injects too much data, the application will trigger an OOM error and crash at startup, resulting in a persistent denial of service.

CVE-2023-24329
Software Genérico General
7.5
HIGH
EPSS
1.4%
2023 4 PoCs

An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.

CVE-2023-3127
iSTAR Ultra General
7.5
HIGH
EPSS
0.2%
2023 CWE-287 1 PoC

An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.

CVE-2023-37474
copyparty General ⚡ nuclei
7.5
HIGH
EPSS
89.9%
2023 CWE-22 2 PoCs

Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path Traversal attack technique allows an attacker access to files, directories, and commands that reside outside the web document root directory. This issue has been addressed in commit `043e3c7d` which has been included in release 1.8.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2023-30699
Samsung Mobile Devices General
7.5
HIGH
EPSS
3.0%
2023 1 PoC

Out-of-bounds write vulnerability in parser_hvcC function of libsimba library prior to SMR Aug-2023 Release 1 allows code execution by remote attackers.

CVE-2023-26451
OX App Suite General
7.5
HIGH
EPSS
0.1%
2023 CWE-330 1 PoC

Functions with insufficient randomness were used to generate authorization tokens of the integrated oAuth Authorization Service. Authorization codes were predictable for third parties and could be used to intercept and take over the client authorization process. As a result, other users accounts could be compromised. The oAuth Authorization Service is not enabled by default. We have updated the implementation to use sources with sufficient randomness to generate authorization tokens. No publicly available exploits are known.

CVE-2023-44830
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the EndTime parameter in the SetParentsControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-22960
Software Genérico General
7.5
HIGH
EPSS
42.8%
2023 3 PoCs

Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.

CVE-2023-25264
Software Genérico General
7.5
HIGH
EPSS
0.6%
2023 1 PoC

An issue was discovered in Docmosis Tornado prior to version 2.9.5. An unauthenticated attacker can bypass the authentication check filter completely by introducing a specially crafted request with relative path segments.