9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-33263
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

In WFTPD 3.25, usernames and password hashes are stored in an openly viewable wftpd.ini configuration file within the WFTPD directory. NOTE: this is a product from 2006.

CVE-2023-24498
ProSAFE 24 Port 10/100 FS726TP General
7.5
HIGH
EPSS
0.2%
2023 CWE-522 1 PoC

An uspecified endpoint in the web server of the switch does not properly authenticate the user identity, and may allow downloading a config page with the password to the switch in clear text.

CVE-2023-28095
opensips General
7.5
HIGH
EPSS
0.7%
2023 CWE-20 1 PoC

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.1.7 and 3.2.4 have a potential issue in `msg_translator.c:2628` which might lead to a server crash. This issue was found while fuzzing the function `build_res_buf_from_sip_req` but could not be reproduced against a running instance of OpenSIPS. This issue could not be exploited against a running instance of OpenSIPS since no public function was found to make use of this vulnerable code. Even in the case of exploitation through unknown vectors, it is highly unlikely that this issue would lead to anything

CVE-2023-43862
Software Genérico General
7.5
HIGH
EPSS
1.0%
2023 1 PoC

D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formLanguageChange function.

CVE-2023-30591
NodeBB General
7.5
HIGH
EPSS
2.2%
2023 CWE-241 1 PoC

Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.startsWith()` or `eventName.toString()`, while processing Socket.IO messages via crafted Socket.IO messages containing array or object type for the event name respectively.

CVE-2023-49980
Software Genérico General
7.5
HIGH
EPSS
0.6%
2023 2 PoCs

A directory listing vulnerability in Best Student Result Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.

CVE-2023-52340
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

The IPv6 implementation in the Linux kernel before 6.3 has a net/ipv6/route.c max_size threshold that can be consumed easily, e.g., leading to a denial of service (network is unreachable errors) when IPv6 packets are sent in a loop via a raw socket.

CVE-2023-40278
Software Genérico General
7.5
HIGH
EPSS
11.3%
2023 3 PoCs

An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsp component of OpenClinic GA. By changing the AppointmentUid parameter, an attacker can determine whether a specific appointment exists based on the error message.

CVE-2023-37014
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Release Request` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

CVE-2023-47091
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10, and SNS 4.7.0 through 4.7.1 before 4.7.2. An attacker can overflow the cookie threshold, making an IPsec connection impossible.

CVE-2023-40279
Software Genérico General
7.5
HIGH
EPSS
19.8%
2023 3 PoCs

An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to main.do.

CVE-2023-37218
Telecom Aeonix General
7.5
HIGH
EPSS
0.1%
2023 CWE-22 1 PoC

Tadiran Telecom Aeonix - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVE-2023-26758
Software Genérico General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Sme.UP TOKYO V6R1M220406 was discovered to contain an arbitrary file download vulnerabilty via the component /ResourceService.

CVE-2023-26256
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
91.8%
2023 7 PoCs

An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying the fileName parameter to the snjFooterNavigationConfig endpoint, it is possible to traverse and read the file system.

CVE-2023-26126
m.static General
7.5
HIGH
EPSS
0.3%
2023 CWE-22 1 PoC

All versions of the package m.static are vulnerable to Directory Traversal due to improper input sanitization of the path being requested via the requestFile function.

CVE-2023-24504
Central AC unit General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

Electra Central AC unit – Adjacent attacker may cause the unit to connect to unauthorized update server.

CVE-2023-45232
edk2 General
7.5
HIGH
EPSS
0.5%
2023 CWE-835 1 PoC

EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.

CVE-2023-7012
Chrome General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convinced a user to install a malicious app to potentially perform a sandbox escape via a malicious file. (Chromium security severity: Medium)

CVE-2023-44834
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the StartTime parameter in the SetParentsControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-26255
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
93.6%
2023 3 PoCs

An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying the fileName parameter to the snjCustomDesignConfig endpoint, it is possible to traverse and read the file system.