3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-0901
pixelfed/pixelfed General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pixelfed/pixelfed prior to 0.11.4.

CVE-2023-37004
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial Context Setup Response` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

CVE-2023-21479
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper authorization in Smart suggestions prior to SMR Apr-2023 Release 1 in Android 13 and 4.1.01.0 in Android 12 allows remote attackers to register a schedule.

CVE-2023-41763
🔥 KEV Skype for Business Server 2015 CU13 General ⚡ nuclei
5.3
MEDIUM
EPSS
16.5%
2023 CWE-918 0 PoCs

Skype for Business Elevation of Privilege Vulnerability

CVE-2023-37003
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `E-RAB Setup Response` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

CVE-2023-44982
Perfect Images (Manage Image Sizes, Thumbnails, Replace, Retina) General ⚡ nuclei
5.3
MEDIUM
EPSS
12.9%
2023 CWE-200 0 PoCs

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Perfect Images (Manage Image Sizes, Thumbnails, Replace, Retina).This issue affects Perfect Images (Manage Image Sizes, Thumbnails, Replace, Retina): from n/a through 6.4.5.

CVE-2023-24473
OpenImageIO General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-125 1 PoC

An information disclosure vulnerability exists in the TGAInput::read_tga2_header functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted targa file can lead to a disclosure of sensitive information. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-28536
Branded Social Images General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

Missing Authorization vulnerability in Acato Branded Social Images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Branded Social Images: from n/a through 1.1.0.

CVE-2023-39217
Zoom SDK's General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-80 1 PoC

Improper input validation in Zoom SDK’s before 5.14.10 may allow an unauthenticated user to enable a denial of service via network access.

CVE-2023-2042
DataGear General
5.3
MEDIUM
EPSS
0.5%
2023 CWE-502 1 PoC

A vulnerability, which was classified as problematic, has been found in DataGear up to 4.7.0/5.1.0. Affected by this issue is some unknown functionality of the component JDBC Server Handler. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-0493
btcpayserver/btcpayserver General
5.3
MEDIUM
EPSS
10.0%
2023 CWE-76 2 PoCs

Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.

CVE-2023-20566
3rd Gen AMD EPYC™ Processors General
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.

CVE-2023-26115
word-wrap General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-1333 2 PoCs

All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable.

CVE-2023-6342
Court Case Management Plus General
5.3
MEDIUM
EPSS
1.3%
2023 CWE-287 1 PoC

Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at least the 'CmWebSearchPfp/Login.aspx?xyzldk=' and 'payforprint_CM/Redirector.ashx?userid=' parameters. The vulnerable "pay for print" feature was removed on or around 2023-11-01.

CVE-2023-20532
2nd Gen EPYC General
5.3
MEDIUM
EPSS
0.4%
2023 1 PoC

Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.

CVE-2023-0330
Software Genérico General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-121 1 PoC

A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.

CVE-2023-1538
answerdev/answer General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-208 1 PoC

Observable Timing Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2023-7270
Office General
5.3
MEDIUM
EPSS
0.1%
2023 2 PoCs

An issue was discovered in SoftMaker Office 2024 / NX before revision 1214 and SoftMaker FreeOffice 2014 before revision 1215. FreeOffice 2021 is also affected, but won't be fixed. The SoftMaker Office and FreeOffice MSI installer files were found to produce a visible conhost.exe window running as the SYSTEM user when using the repair function of msiexec.exe. This allows a local, low-privileged attacker to use a chain of actions, to open a fully functional cmd.exe with the privileges of the SYSTEM user.

CVE-2023-43074
Unity General
5.2
MEDIUM
EPSS
0.0%
2023 CWE-73 1 PoC

Dell Unity 5.3 contain(s) an Arbitrary File Creation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by crafting arbitrary files through a request to the server.

CVE-2023-28904
Volkswagen MIB3 infotainment system MIB3 OI MQB General
5.2
MEDIUM
EPSS
0.0%
2023 CWE-120 2 PoCs

A logic flaw leading to a RAM buffer overflow in the bootloader component of the MIB3 infotainment unit allows an attacker with physical access to the MIB3 ECU to bypass firmware signature verification and run arbitrary code in the infotainment system at boot process.