3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-50373
Alt Manager General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

Missing Authorization vulnerability in WPSAAD Alt Manager alt-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Alt Manager: from n/a through <= 1.6.1.

CVE-2023-29922
Software Genérico General ⚡ nuclei
5.3
MEDIUM
EPSS
91.2%
2023 1 PoC

PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create user/save interface.

CVE-2023-23545
T&D Corporation and ESPEC MIC CORP. data logger products General
5.3
MEDIUM
EPSS
0.4%
2023 1 PoC

Missing authentication for critical function exists in T&D Corporation and ESPEC MIC CORP. data logger products, which may allow a remote unauthenticated attacker to alter the product settings without authentication. Affected products and versions are as follows: T&D Corporation data logger products (TR-71W/72W all firmware versions, RTR-5W all firmware versions, WDR-7 all firmware versions, WDR-3 all firmware versions, and WS-2 all firmware versions), and ESPEC MIC CORP. data logger products (RT-12N/RS-12N all firmware versions, RT-22BN all firmware versions, and TEU-12N all firmware versions

CVE-2023-4755
gpac/gpac General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-416 1 PoC

Use After Free in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-1176
mlflow/mlflow General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-36 1 PoC

Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.2.2.

CVE-2023-30700
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

PendingIntent hijacking vulnerability in SemWifiApTimeOutImpl in framework prior to SMR Aug-2023 Release 1 allows local attackers to access ContentProvider without proper permission.

CVE-2023-0029
RE708 General
5.3
MEDIUM
EPSS
0.5%
2023 CWE-404 1 PoC

A vulnerability was found in Multilaser RE708 RE1200R4GC-2T2R-V3_v3411b_MUL029B. It has been rated as problematic. This issue affects some unknown processing of the component Telnet Service. The manipulation leads to denial of service. The attack may be initiated remotely. The identifier VDB-217169 was assigned to this vulnerability.

CVE-2023-26103
deno General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-1333 1 PoC

Versions of the package deno before 1.31.0 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the upgradeWebSocket function, which contains regexes in the form of /s*,s*/, used for splitting the Connection/Upgrade header. A specially crafted Connection/Upgrade header can be used to significantly slow down a web socket server.

CVE-2023-4230
ioLogik 4000 Series General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-200 1 PoC

A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which has the potential to facilitate the collection of information on ioLogik 4000 Series devices. This vulnerability may enable attackers to gather information for the purpose of assessing vulnerabilities and potential attack vectors.

CVE-2023-51393
Ember ZNet SDK General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-770 1 PoC

Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v7.4.0.0 (delivered as part of Silicon Labs Gecko SDK v4.4.0) which may enable attackers to trigger a bus fault and crash of the device, requiring a reboot in order to rejoin the network.

CVE-2023-29185
NetWeaver AS for ABAP (Business Server Pages) General
5.3
MEDIUM
EPSS
0.5%
2023 CWE-400 1 PoC

SAP NetWeaver AS for ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an attacker authenticated as a non-administrative user to craft a request with certain parameters in certain circumstances which can consume the server's resources sufficiently to make it unavailable over the network without any user interaction.

CVE-2023-1646
Malware Fighter General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-121 1 PoC

A vulnerability was found in IObit Malware Fighter 9.4.0.776. It has been declared as critical. This vulnerability affects the function 0x8018E000/0x8018E004 in the library IMFCameraProtect.sys of the component IOCTL Handler. The manipulation leads to stack-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. VDB-224026 is the identifier assigned to this vulnerability.

CVE-2023-26460
NetWeaver AS for Java General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-284 1 PoC

Cache Management Service in SAP NetWeaver Application Server for Java - version 7.50, does not perform any authentication checks for functionalities that require user identity

CVE-2023-6401
NotePad++ General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-427 1 PoC

A vulnerability classified as problematic was found in NotePad++ up to 8.1. Affected by this vulnerability is an unknown functionality of the file dbghelp.exe. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The identifier VDB-246421 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-4513
Wireshark General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-401 1 PoC

BT SDP dissector memory leak in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture file

CVE-2023-21486
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-926 1 PoC

Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.

CVE-2023-30956
com.palantir.comments:comments General
5.3
MEDIUM
EPSS
0.3%
2023 CWE-639 1 PoC

A security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if they knew the internal UUID of the target attachment. This defect was resolved with the release of Foundry Comments 2.267.0.

CVE-2023-7216
Red Hat Enterprise Linux 6 General
5.3
MEDIUM
EPSS
0.3%
2023 CWE-59 1 PoC

A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory, which allows files to be written in arbitrary directories through symlinks.

CVE-2023-49927
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123, Exynos Modem 5300. The baseband software does not properly check format types specified by the RRC. This can lead to a lack of encryption.

CVE-2023-0440
healthchecks/healthchecks General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-203 1 PoC

Observable Discrepancy in GitHub repository healthchecks/healthchecks prior to v2.6.