3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-29911
Software Genérico General
4.9
MEDIUM
EPSS
0.4%
2023 1 PoC

H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the AddMacList interface at /goform/aspForm.

CVE-2023-27804
Software Genérico General
4.9
MEDIUM
EPSS
0.4%
2023 1 PoC

H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the DelvsList interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.

CVE-2023-29917
Software Genérico General
4.9
MEDIUM
EPSS
0.4%
2023 1 PoC

H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via go parameter at /goform/aspForm.

CVE-2023-27807
Software Genérico General
4.9
MEDIUM
EPSS
0.4%
2023 1 PoC

H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the Delstlist interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.

CVE-2023-29905
Software Genérico General
4.9
MEDIUM
EPSS
0.4%
2023 1 PoC

H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the UpdateSnat interface at /goform/aspForm.

CVE-2023-27806
Software Genérico General
4.9
MEDIUM
EPSS
0.4%
2023 1 PoC

H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the ipqos_lanip_dellist interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.

CVE-2023-5968
Mattermost General
4.9
MEDIUM
EPSS
0.1%
2023 CWE-200 1 PoC

Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body. 

CVE-2023-27805
Software Genérico General
4.9
MEDIUM
EPSS
0.4%
2023 1 PoC

H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the EditSTList interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.

CVE-2023-2445
Devolutions Server General
4.9
MEDIUM
EPSS
0.2%
2023 1 PoC

Improper access control in Subscriptions Folder path filter in Devolutions Server 2023.1.1 and earlier allows attackers with administrator privileges to retrieve usage information on folders in user vaults via a specific folder name.

CVE-2023-42559
Samsung Mobile Devices General
4.9
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Knox Guard lock bypass via changing system time.

CVE-2023-27810
Software Genérico General
4.9
MEDIUM
EPSS
0.4%
2023 1 PoC

H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the ipqos_lanip_editlist interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.

CVE-2023-27803
Software Genérico General
4.9
MEDIUM
EPSS
0.4%
2023 1 PoC

H3C Magic R100 R100V100R005.bin was discovered to contain a stack overflow via the EdittriggerList interface at /goform/aspForm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.

CVE-2023-36924
SAP ERP Defense Forces and Public Security General
4.9
MEDIUM
EPSS
0.1%
2023 CWE-117 1 PoC

While using a specific function, SAP ERP Defense Forces and Public Security - versions 600, 603, 604, 605, 616, 617, 618, 802, 803, 804, 805, 806, 807, allows an authenticated attacker with admin privileges to write arbitrary data to the syslog file. On successful exploitation, an attacker could modify all the syslog data causing a complete compromise of integrity of the application.

CVE-2023-34403
Software Genérico General
4.9
MEDIUM
EPSS
0.1%
2023 1 PoC

Mercedes-Benz head-unit NTG6 has Ethernet pins on Base Board to connect module CSB. Attacker can connect to this pins and get access to internal network. A race condition can be acquired and attacker can spoof “UserData” with desirable file path and access it though backup on USB.

CVE-2023-40028
Ghost General
4.9
MEDIUM
EPSS
77.6%
2023 CWE-22 11 PoCs

Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload files that are symlinks. This can be exploited to perform an arbitrary file read of any file on the host operating system. Site administrators can check for exploitation of this issue by looking for unknown symlinks within Ghost's `content/` folder. Version 5.59.1 contains a fix for this issue. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2023-44395
Autolab General
4.9
MEDIUM
EPSS
0.1%
2023 CWE-22 1 PoC

Autolab is a course management service that enables instructors to offer autograded programming assignments to their students over the Web. Path traversal vulnerabilities were discovered in Autolab's assessment functionality in versions of Autolab prior to 2.12.0, whereby instructors can perform arbitrary file reads. Version 2.12.0 contains a patch. There are no feasible workarounds for this issue.

CVE-2023-29907
Software Genérico General
4.9
MEDIUM
EPSS
0.4%
2023 1 PoC

H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the Edit_BasicSSID_5G interface at /goform/aspForm.

CVE-2023-29910
Software Genérico General
4.9
MEDIUM
EPSS
0.4%
2023 1 PoC

H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the UpdateMacClone interface at /goform/aspForm.

CVE-2023-43122
Software Genérico General
4.8
MEDIUM
EPSS
0.0%
2023 1 PoC

Samsung Mobile Processor and Wearable Processor (Exynos 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, and W920) allow Information Disclosure in the Bootloader.

CVE-2023-3591
Mattermost General
4.8
MEDIUM
EPSS
0.2%
2023 CWE-287 1 PoC

Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created.