9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-46662
PolyEco1000 General
7.5
HIGH
EPSS
0.1%
2023 CWE-284 1 PoC

Sielco PolyEco1000 is vulnerable to an information disclosure vulnerability due to improper access control enforcement. An unauthenticated remote attacker can exploit this via a specially crafted request to gain access to sensitive information.

CVE-2023-26121
safe-eval General
7.5
HIGH
EPSS
0.3%
2023 CWE-1321 1 PoC

All versions of the package safe-eval are vulnerable to Prototype Pollution via the safeEval function, due to improper sanitization of its parameter content.

CVE-2023-30056
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

A session takeover vulnerability exists in FICO Origination Manager Decision Module 4.8.1 due to insufficient protection of the JSESSIONID cookie.

CVE-2023-25265
Software Genérico General
7.5
HIGH
EPSS
0.7%
2023 1 PoC

Docmosis Tornado <= 2.9.4 is vulnerable to Directory Traversal leading to the disclosure of arbitrary content on the file system.

CVE-2023-1605
radareorg/radare2 General
7.5
HIGH
EPSS
0.3%
2023 CWE-400 1 PoC

Denial of Service in GitHub repository radareorg/radare2 prior to 5.8.6.

CVE-2023-39167
Storage Box V1 General
7.5
HIGH
EPSS
0.4%
2023 CWE-862 2 PoCs

In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices' logfiles that contain sensitive data.

CVE-2023-4316
Zod General
7.5
HIGH
EPSS
0.1%
2023 CWE-1333 1 PoC

Zod in versions 3.21.0 up to and including 3.22.3 allows an attacker to perform a denial of service while validating emails.

CVE-2023-49355
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

decToString in decNumber/decNumber.c in jq 88f01a7 has a one-byte out-of-bounds write via the " []-1.2e-1111111111" input. NOTE: this is not the same as CVE-2023-50246. The CVE-2023-50246 71c2ab5 reference mentions -10E-1000010001, which is not in normalized scientific notation.

CVE-2023-30285
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 2 PoCs

An issue in Deviniti Issue Sync Synchronization v3.5.2 for Jira allows attackers to obtain the login credentials of a user via a crafted request sent to /rest/synchronizer/1.0/technicalUser.

CVE-2023-45131
discourse General
7.5
HIGH
EPSS
7.4%
2023 CWE-200 1 PoC

Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticated POST request to MessageBus. This issue is patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2023-30861
flask General
7.5
HIGH
EPSS
0.2%
2023 CWE-539 2 PoCs

Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one client may be cached and subsequently sent by the proxy to other clients. If the proxy also caches `Set-Cookie` headers, it may send one client's `session` cookie to other clients. The severity depends on the application's use of the session and the proxy's behavior regarding cookies. The risk depends on all these conditions being met. 1. The application must be hosted behind a caching proxy that does not strip cookies or ignore responses with cookie

CVE-2023-39539
AptioV General
7.5
HIGH
EPSS
0.3%
2023 CWE-20 1 PoC

AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability. 

CVE-2023-25260
Software Genérico General
7.5
HIGH
EPSS
0.9%
2023 2 PoCs

Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.

CVE-2023-49298
Software Genérico General
7.5
HIGH
EPSS
0.7%
2023 1 PoC

OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios involving applications that try to rely on efficient copying of file data, can replace file contents with zero-valued bytes and thus potentially disable security mechanisms. NOTE: this issue is not always security related, but can be security related in realistic situations. A possible example is cp, from a recent GNU Core Utilities (coreutils) version, when attempting to preserve a rule set for denying unauthorized access. (One might use cp when configuring access control, such as with the /etc/hosts.deny file specified in t

CVE-2023-37608
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

An issue in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information because there is an automaticsystems super admin account with astech as its hardcoded password.

CVE-2023-26111
@nubosoftware/node-static General
7.5
HIGH
EPSS
1.3%
2023 CWE-22 2 PoCs

All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function.

CVE-2023-32328
Security Verify Access Appliance General
7.5
HIGH
EPSS
0.0%
2023 CWE-319 1 PoC

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attacker on the network to take control of the server. IBM X-Force Id: 254957.

CVE-2023-37478
pnpm General
7.5
HIGH
EPSS
1.6%
2023 CWE-284 2 PoCs

pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed via pnpm is malicious, due to how pnpm parses tar archives. This can result in a package that appears safe on the npm registry or when installed via npm being replaced with a compromised or malicious version when installed via pnpm. This issue has been patched in version(s) 7.33.4 and 8.6.8.

CVE-2023-6042
Getwid General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Any unauthenticated user may send e-mail from the site with any title or content to the admin