9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-1105
flatpressblog/flatpress General
7.5
HIGH
EPSS
0.3%
2023 CWE-73 1 PoC

External Control of File Name or Path in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2023-31185
server framework General
7.5
HIGH
EPSS
3.5%
2023 CWE-200 1 PoC

ROZCOM server framework - Misconfiguration may allow information disclosure via an unspecified request.

CVE-2023-38952
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
15.3%
2023 1 PoC

Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that session ids are not validated for the type of user accessing the application by default. Privilege restrictions between non-admin and admin users are not enforced and any authenticated user can leverage admin functions without restriction by making direct requests to administrative endpoints.

CVE-2023-28097
opensips General
7.5
HIGH
EPSS
0.7%
2023 CWE-190 1 PoC

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.9 and 3.2.6, a malformed SIP message containing a large _Content-Length_ value and a specially crafted Request-URI causes a segmentation fault in OpenSIPS. This issue occurs when a large amount of shared memory using the `-m` flag was allocated to OpenSIPS, such as 10 GB of RAM. On the test system, this issue occurred when shared memory was set to `2362` or higher. This issue is fixed in versions 3.1.9 and 3.2.6. The only workaround is to guarantee that the Content-Length value of input messages is nev

CVE-2023-44829
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the AdminPassword parameter in the SetDeviceSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-1580
Gateway General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Uncontrolled resource consumption in the logging feature in Devolutions Gateway 2023.1.1 and earlier allows an attacker to cause a denial of service by filling up the disk and render the system unusable.

CVE-2023-45854
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

A Business Logic vulnerability in Shopkit 1.0 allows an attacker to add products with negative quantities to the shopping cart via the qtd parameter in the add-to-cart function.

CVE-2023-26152
static-server General
7.5
HIGH
EPSS
0.8%
2023 CWE-22 1 PoC

All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath function of server.js.

CVE-2023-31115
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. Incorrect resource transfer between spheres can cause changes to the activation mode of RCS via a crafted application.

CVE-2023-29740
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 2 PoCs

An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause a denial of service attack by manipulating the database.

CVE-2023-5392
C300 General
7.5
HIGH
EPSS
0.1%
2023 CWE-1295 1 PoC

C300 information leak due to an analysis feature which allows extracting more memory over the network than required by the function. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-22512
Confluence Data Center General
7.5
HIGH
EPSS
14.8%
2023 2 PoCs

This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS Score of 7.5, this vulnerability allows an unauthenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a vulnerable host (Confluence instance) connected to a network, which has no impact to confidentiality, no impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest

CVE-2023-49979
Software Genérico General
7.5
HIGH
EPSS
0.6%
2023 2 PoCs

A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.

CVE-2023-44833
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the GuardInt parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-29743
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database.

CVE-2023-33510
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
71.5%
2023 1 PoC

Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters.

CVE-2023-45966
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

umputun remark42 version 1.12.1 and before has a Blind Server-Side Request Forgery (SSRF) vulnerability.

CVE-2023-50387
Software Genérico General
7.5
HIGH
EPSS
52.0%
2023 2 PoCs

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.

CVE-2023-31726
Software Genérico General
7.5
HIGH
EPSS
2.1%
2023 2 PoCs

AList 3.15.1 is vulnerable to Incorrect Access Control, which can be exploited by attackers to obtain sensitive information.

CVE-2023-31595
Software Genérico General
7.5
HIGH
EPSS
0.5%
2023 1 PoC

IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via unauthenticated port access.