9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-31181
InnoKB Server, InnoKB/Console General
7.5
HIGH
EPSS
0.4%
2023 CWE-22 1 PoC

WJJ Software - InnoKB Server, InnoKB/Console 2.2.1 - CWE-22: Path Traversal

CVE-2023-7005
TTLock App General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

A specially crafted message can be sent to the TTLock App that downgrades the encryption protocol used for communication, and can be utilized to compromise the lock, such as through revealing the unlockKey field.

CVE-2023-27098
Software Genérico General
7.5
HIGH
EPSS
0.0%
2023 1 PoC

TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.

CVE-2023-0122
Kernel General
7.5
HIGH
EPSS
0.2%
2023 CWE-476 1 PoC

A NULL pointer dereference vulnerability in the Linux kernel NVMe functionality, in nvmet_setup_auth(), allows an attacker to perform a Pre-Auth Denial of Service (DoS) attack on a remote machine. Affected versions v6.0-rc1 to v6.0-rc3, fixed in v6.0-rc4.

CVE-2023-6929
ETL3100 General
7.5
HIGH
EPSS
0.0%
2023 CWE-639 1 PoC

EuroTel ETL3100 versions v01c01 and v01x37 are vulnerable to insecure direct object references that occur when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability, attackers can bypass authorization, access the hidden resources on the system, and execute privileged functionalities.

CVE-2023-25369
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS is vulnerable to Denial of Service on the user interface triggered by malformed SCPI command.

CVE-2023-51065
Software Genérico General
7.5
HIGH
EPSS
0.6%
2023 1 PoC

Incorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to obtain system backups and other sensitive information from the QStar Server.

CVE-2023-40211
Post Grid Combo – 36+ Gutenberg Blocks General ⚡ nuclei
7.5
HIGH
EPSS
31.5%
2023 CWE-200 0 PoCs

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid Combo – 36+ Gutenberg Blocks.This issue affects Post Grid Combo – 36+ Gutenberg Blocks: from n/a through 2.2.50.

CVE-2023-0248
ioSmart Gen1 General
7.5
HIGH
EPSS
0.1%
2023 CWE-200 1 PoC

An attacker with physical access to the Kantech Gen1 ioSmart card reader with firmware version prior to 1.07.02 in certain circumstances can recover the reader's communication memory between the card and reader.

CVE-2023-27599
opensips General
7.5
HIGH
EPSS
0.4%
2023 CWE-20 1 PoC

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, when the function `append_hf` handles a SIP message with a malformed To header, a call to the function `abort()` is performed, resulting in a crash. This is due to the following check in `data_lump.c:399` in the function `anchor_lump`. An attacker abusing this vulnerability will crash OpenSIPS leading to Denial of Service. It affects configurations containing functions that make use of the affected code, such as the function `append_hf`. This issue has been fixed in versions 3.1.7 and 3.2.

CVE-2023-38205
🔥 KEV ColdFusion General ⚡ nuclei
7.5
HIGH
EPSS
94.2%
2023 CWE-284 0 PoCs

Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.

CVE-2023-22506
Bamboo Data Center General
7.5
HIGH
EPSS
3.7%
2023 3 PoCs

This High severity Injection and RCE (Remote Code Execution) vulnerability known as CVE-2023-22506 was introduced in version 8.0.0 of Bamboo Data Center.   This Injection and RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.5, allows an authenticated attacker to modify the actions taken by a system call and execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user interaction.     Atlassian recommends that you upgrade your instance to latest version. If you're unable to upgrade to latest, upgrade to one

CVE-2023-28598
Zoom for Linux clients General
7.5
HIGH
EPSS
0.4%
2023 CWE-79 1 PoC

Zoom for Linux clients prior to 5.13.10 contain an HTML injection vulnerability. If a victim starts a chat with a malicious user it could result in a Zoom application crash.

CVE-2023-30455
Software Genérico General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

An issue was discovered in ebankIT before 7. A Denial-of-Service attack is possible through the GET parameter EStatementsIds located on the /Controls/Generic/EBMK/Handlers/EStatements/DownloadEStatement.ashx endpoint. The GET parameter accepts over 100 comma-separated e-statement IDs without throwing an error. When this many IDs are supplied, the server takes around 60 seconds to respond and successfully generate the expected ZIP archive (during this time period, no other pages load). A threat actor could issue a request to this endpoint with 100+ statement IDs every 30 seconds, potentially re

CVE-2023-27643
Software Genérico General
7.5
HIGH
EPSS
0.8%
2023 1 PoC

An issue found in POWERAMP 925-bundle-play and Poweramp 954-uni allows a remote attacker to cause a denial of service via the Rescan button in Queue and Select Folders button in Library

CVE-2023-5724
Firefox General
7.5
HIGH
EPSS
0.8%
2023 1 PoC

Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

CVE-2023-24502
Electra Central AC unit General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

Electra Central AC unit – The unit opens an AP with an easily calculated password.

CVE-2023-45892
Software Genérico General
7.5
HIGH
EPSS
1.0%
2023 1 PoC

An issue discovered in the Order and Invoice pages in Floorsight Insights Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.

CVE-2023-5245
Software Genérico General
7.5
HIGH
EPSS
0.4%
2023 CWE-22 1 PoC

FileUtil.extract() enumerates all zip file entries and extracts each file without validating whether file paths in the archive are outside the intended directory. When creating an instance of TensorflowModel using the saved_model format and an exported tensorflow model, the apply() function invokes the vulnerable implementation of FileUtil.extract(). Arbitrary file creation can directly lead to code execution

CVE-2023-34397
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

Mercedes Benz head-unit NTG 6 contains functions to import or export profile settings over USB. During parsing you can trigger that the service will be crashed.