3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-0190
NVIDIA GPU Display Driver General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-476 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where a NULL pointer dereference may lead to denial of service.

CVE-2023-29506
xwiki-platform General ⚡ nuclei
5.4
MEDIUM
EPSS
11.5%
2023 CWE-79 1 PoC

XWiki Commons are technical libraries common to several other top level XWiki projects. It was possible to inject some code using the URL of authenticated endpoints. This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10.

CVE-2023-28908
Volkswagen MIB3 infotainment system MIB3 OI MQB General
5.4
MEDIUM
EPSS
0.2%
2023 CWE-190 2 PoCs

A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow when receiving non-fragmented HCI packets on a channel. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources.

CVE-2023-29918
Software Genérico General
5.4
MEDIUM
EPSS
5.9%
2023 1 PoC

RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.

CVE-2023-26998
Software Genérico General
5.4
MEDIUM
EPSS
0.7%
2023 1 PoC

Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the creator parameter of the Alert Configuration page.

CVE-2023-30788
MonicaHQ General
5.4
MEDIUM
EPSS
0.3%
2023 1 PoC

MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people/add` endpoint and nickName, description, lastName, middleName and firstName parameter.

CVE-2023-45828
RumbleTalk Live Group Chat General
5.4
MEDIUM
EPSS
4.7%
2023 CWE-862 1 PoC

Missing Authorization vulnerability in RumbleTalk RumbleTalk Live Group Chat rumbletalk-chat-a-chat-with-themes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RumbleTalk Live Group Chat: from n/a through <= 6.2.5.

CVE-2023-41708
OX App Suite General
5.4
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

References to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypass existing safeguards to inject malicious script code. Please deploy the provided updates and patch releases. References to apps are now controlled more strict to avoid relative references. No publicly available exploits are known.

CVE-2023-46615
KD Coming Soon General
5.4
MEDIUM
EPSS
5.6%
2023 CWE-502 1 PoC

Deserialization of Untrusted Data vulnerability in Kalli Dan. KD Coming Soon.This issue affects KD Coming Soon: from n/a through 1.7.

CVE-2023-26138
drogonframework/drogon General
5.4
MEDIUM
EPSS
0.3%
2023 CWE-93 1 PoC

All versions of the package drogonframework/drogon are vulnerable to CRLF Injection when untrusted user input is used to set request headers in the addHeader function. An attacker can add the \r\n (carriage return line feeds) characters and inject additional headers in the request sent.

CVE-2023-34732
Software Genérico General
5.4
MEDIUM
EPSS
0.2%
2023 1 PoC

An issue in the userId parameter in the change password function of Flytxt NEON-dX v0.0.1-SNAPSHOT-6.9-qa-2-9-g5502a0c allows attackers to execute brute force attacks to discover user passwords.

CVE-2023-51157
Software Genérico General
5.4
MEDIUM
EPSS
0.8%
2023 1 PoC

Cross Site Scripting vulnerability in ZKTeco WDMS v.5.1.3 Pro allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script to the Emp Name parameter.

CVE-2023-0610
wallabag/wallabag General
5.4
MEDIUM
EPSS
0.2%
2023 CWE-285 1 PoC

Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.

CVE-2023-2972
antfu/utils General
5.4
MEDIUM
EPSS
0.1%
2023 CWE-1321 1 PoC

Prototype Pollution in GitHub repository antfu/utils prior to 0.7.3.

CVE-2023-41710
OX App Suite General
5.4
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added sanitization for this content. No publicly available exploits are known.

CVE-2023-26148
ithewei/libhv General
5.4
MEDIUM
EPSS
0.1%
2023 CWE-93 1 PoC

All versions of the package ithewei/libhv are vulnerable to CRLF Injection when untrusted user input is used to set request headers. An attacker can add the \r\n (carriage return line feeds) characters and inject additional headers in the request sent.

CVE-2023-6125
salesagility/suitecrm General
5.4
MEDIUM
EPSS
0.1%
2023 CWE-94 1 PoC

Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

CVE-2023-1788
firefly-iii/firefly-iii General
5.4
MEDIUM
EPSS
0.2%
2023 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository firefly-iii/firefly-iii prior to 6.

CVE-2023-26120
com.xuxueli:xxl-job General
5.4
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

This affects all versions of the package com.xuxueli:xxl-job. HTML uploaded payload executed successfully through /xxl-job-admin/user/add and /xxl-job-admin/user/update.

CVE-2023-6127
salesagility/suitecrm General
5.4
MEDIUM
EPSS
0.2%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.