3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-26116
angular General
5.3
MEDIUM
EPSS
0.3%
2023 CWE-1333 4 PoCs

Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.

CVE-2023-2042
DataGear General
5.3
MEDIUM
EPSS
0.5%
2023 CWE-502 1 PoC

A vulnerability, which was classified as problematic, has been found in DataGear up to 4.7.0/5.1.0. Affected by this issue is some unknown functionality of the component JDBC Server Handler. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-1678
DriverGenius General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-119 1 PoC

A vulnerability classified as critical has been found in DriverGenius 9.70.0.346. This affects the function 0x9C40A0D8/0x9C40A0DC/0x9C40A0E0 in the library mydrivers64.sys of the component IOCTL Handler. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224235.

CVE-2023-1539
answerdev/answer General
5.3
MEDIUM
EPSS
0.4%
2023 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2023-6353
Civil and Criminal Electronic Filing General
5.3
MEDIUM
EPSS
1.6%
2023 CWE-287 1 PoC

Tyler Technologies Civil and Criminal Electronic Filing allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the Upload.aspx 'enky' parameter.

CVE-2023-24505
NCR/Camera General
5.3
MEDIUM
EPSS
0.3%
2023 CWE-200 1 PoC

Milesight NCR/camera version 71.8.0.6-r5 discloses sensitive information through an unspecified request.

CVE-2023-7033
MELSEC iQ-R series CPU module R00CPU General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-410 1 PoC

Insufficient Resource Pool vulnerability in Ethernet function of Mitsubishi Electric Corporation MELSEC iQ-R series CPU module, MELSEC iQ-L series CPU module, MELSEC iQ-R Ethernet Interface Module, MELSEC iQ-R CC-Link IE TSN Master/Local Module, CC-Link IE TSN Remote I/O Module, CC-Link IE TSN Analog-Digital Converter Module, CC-Link IE TSN Digital-Analog Converter Module, CC-Link IE TSN - CC-Link IE Field Network Bridge Module, CC-Link IE TSN - AnyWireASLINK Bridge Module, CC-Link IE TSN FPGA Module, CC-Link IE TSN Remote Station Communication LSI CP620 with GbE-PHY, MELSEC iQ-R Motion Module

CVE-2023-2241
PoDoFo General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-122 1 PoC

A vulnerability, which was classified as critical, was found in PoDoFo 0.10.0. Affected is the function readXRefStreamEntry of the file PdfXRefStreamParserObject.cpp. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as 535a786f124b739e3c857529cecc29e4eeb79778. It is recommended to apply a patch to fix this issue. VDB-227226 is the identifier assigned to this vulnerability.

CVE-2023-6459
Mattermost General
5.3
MEDIUM
EPSS
0.5%
2023 CWE-200 1 PoC

Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint is revealing channelIDs.

CVE-2023-26144
graphql General
5.3
MEDIUM
EPSS
2.1%
2023 CWE-400 1 PoC

Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries. This vulnerability allows an attacker to degrade system performance. **Note:** It was not proven that this vulnerability can crash the process.

CVE-2023-47668
Membership Plugin – Restrict Content General
5.3
MEDIUM
EPSS
5.5%
2023 CWE-200 2 PoCs

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StellarWP Membership Plugin – Restrict Content plugin <= 3.2.7 versions.

CVE-2023-1540
answerdev/answer General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-204 1 PoC

Observable Response Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2023-1999
libwebp General
5.3
MEDIUM
EPSS
0.4%
2023 CWE-416 1 PoC

There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.

CVE-2023-6354
Magistrate Court Case Management Plus General
5.3
MEDIUM
EPSS
1.0%
2023 CWE-287 1 PoC

Tyler Technologies Magistrate Court Case Management Plus allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the PDFViewer.aspx 'filename' parameter.

CVE-2023-30458
Software Genérico General
5.3
MEDIUM
EPSS
0.5%
2023 3 PoCs

A username enumeration issue was discovered in Medicine Tracker System 1.0. The login functionality allows a malicious user to guess a valid username due to a different response time from invalid usernames. When one enters a valid username, the response time increases depending on the length of the supplied password.

CVE-2023-37367
Software Genérico General
5.3
MEDIUM
EPSS
0.0%
2023 1 PoC

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem (Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. In the NAS Task, an improperly implemented security check for standard can disallow desired services for a while via consecutive NAS messages.

CVE-2023-2187
SCADA Data Gateway General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-306 1 PoC

On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can use this vulnerability to forcefully log out of any currently logged-in user by sending a "password change event". Furthermore, an attacker could use this vulnerability to spam the logged-in user with false events.

CVE-2023-37005
Software Genérico General
5.3
MEDIUM
EPSS
0.0%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial Context Setup Failure` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

CVE-2023-46197
Popup by Supsystic General
5.3
MEDIUM
EPSS
17.3%
2023 CWE-22 1 PoC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by Supsystic allows Relative Path Traversal.This issue affects Popup by Supsystic: from n/a through 1.10.19.

CVE-2023-41763
🔥 KEV Skype for Business Server 2015 CU13 General ⚡ nuclei
5.3
MEDIUM
EPSS
16.5%
2023 CWE-918 0 PoCs

Skype for Business Elevation of Privilege Vulnerability