9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-24500
Electra Central AC unit General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW.

CVE-2023-24503
OSK201 General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW.

CVE-2023-51127
Software Genérico General
7.5
HIGH
EPSS
5.2%
2023 1 PoC

FLIR AX8 thermal sensor cameras up to and including 1.46.16 are vulnerable to Directory Traversal due to improper access restriction. This vulnerability allows an unauthenticated, remote attacker to obtain arbitrary sensitive file contents by uploading a specially crafted symbolic link file. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16.

CVE-2023-33105
Snapdragon General
7.5
HIGH
EPSS
2.4%
2023 CWE-16 1 PoC

Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number.

CVE-2023-49981
Software Genérico General
7.5
HIGH
EPSS
0.6%
2023 2 PoCs

A directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.

CVE-2023-29929
Software Genérico General
7.5
HIGH
EPSS
2.8%
2023 2 PoCs

Buffer Overflow vulnerability found in Kemptechnologies Loadmaster before v.7.2.60.0 allows a remote attacker to casue a denial of service via the libkemplink.so, isreverse library.

CVE-2023-27159
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
80.2%
2023 0 PoCs

Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.

CVE-2023-42488
v3.0.6433.1964 General
7.5
HIGH
EPSS
0.2%
2023 CWE-22 1 PoC

EisBaer Scada - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVE-2023-23131
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

Selfwealth iOS mobile App 3.3.1 is vulnerable to Insecure App Transport Security (ATS) Settings.

CVE-2023-24033
Software Genérico General
7.5
HIGH
EPSS
1.8%
2023 2 PoCs

The Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T512 baseband modem chipsets do not properly check format types specified by the Session Description Protocol (SDP) module, which can lead to a denial of service.

CVE-2023-44828
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the CurrentPassword parameter in the CheckPasswdSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-40297
Software Genérico General
7.5
HIGH
EPSS
3.1%
2023 1 PoC

Stakater Forecastle 1.0.139 and before allows %5C../ directory traversal in the website component.

CVE-2023-44835
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Mac parameter in the SetParentsControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-24506
NCR/Camera General
7.5
HIGH
EPSS
0.3%
2023 CWE-522 1 PoC

Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request.

CVE-2023-36667
Software Genérico General
7.5
HIGH
EPSS
1.0%
2023 1 PoC

Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal.

CVE-2023-5590
seleniumhq/selenium General
7.5
HIGH
EPSS
0.1%
2023 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository seleniumhq/selenium prior to 4.14.0.

CVE-2023-29748
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 2 PoCs

Story Saver for Instragram - Video Downloader 1.0.6 for Android has an exposed component that provides a method to modify the SharedPreference file. An attacker can leverage this method to inject a large amount of data into any SharedPreference file, which will be loaded into memory when the application is opened. When an attacker injects too much data, the application will trigger an OOM error and crash at startup, resulting in a persistent denial of service.

CVE-2023-6245
Candid General
7.5
HIGH
EPSS
0.1%
2023 CWE-835 1 PoC

The Candid library causes a Denial of Service while parsing a specially crafted payload with 'empty' data type. For example, if the payload is `record { * ; empty }` and the canister interface expects `record { * }` then the Rust candid decoder treats empty as an extra field required by the type. The problem with the type empty is that the candid Rust library wrongly categorizes empty as a recoverable error when skipping the field and thus causing an infinite decoding loop. Canisters using affected versions of candid are exposed to denial of service by causing the decoding to run indefi

CVE-2023-20522
2nd Gen EPYC General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Insufficient input validation in ASP may allow an attacker with a malicious BIOS to potentially cause a denial of service.

CVE-2023-0464
OpenSSL General
7.5
HIGH
EPSS
0.8%
2023 1 PoC

A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function.