3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-48268
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

Mattermost fails to limit the amount of data extracted from compressed archives during board import in Mattermost Boards allowing an attacker to consume excessive resources, possibly leading to Denial of Service, by importing a board using a specially crafted zip (zip bomb).

CVE-2023-30486
Square General
4.3
MEDIUM
EPSS
3.7%
2023 CWE-862 1 PoC

Missing Authorization vulnerability in HashThemes Square allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Square: from n/a through 2.0.0.

CVE-2023-3760
SGS General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability has been found in Intergard SGS 8.7.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Change Password Handler. The manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-234445 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-34115
Zoom Meeting SDK General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-120 1 PoC

Buffer copy without checking size of input in Zoom Meeting SDK before 5.13.0 may allow an authenticated user to potentially enable a denial of service via local access. This issue may result in the Zoom Meeting SDK to crash and need to be restarted.

CVE-2023-26433
OX App Suite General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

When adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue IMAP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit accepted IMAP server response to reasonable length/size. No publicly available exploits are known.

CVE-2023-5375
mosparo/mosparo General ⚡ nuclei
4.3
MEDIUM
EPSS
43.3%
2023 CWE-601 1 PoC

Open Redirect in GitHub repository mosparo/mosparo prior to 1.0.2.

CVE-2023-21426
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-798 1 PoC

Hardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardemulation PIN.

CVE-2023-48369
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

Mattermost fails to limit the log size of server logs allowing an attacker sending specially crafted requests to different endpoints to potentially overflow the log.

CVE-2023-2945
openemr/openemr General
4.3
MEDIUM
EPSS
0.3%
2023 CWE-862 1 PoC

Missing Authorization in GitHub repository openemr/openemr prior to 7.0.1.

CVE-2023-32115
Master Data Synchronization (MDS COMPARE TOOL) General
4.2
MEDIUM
EPSS
0.2%
2023 CWE-89 1 PoC

An attacker can exploit MDS COMPARE TOOL and use specially crafted inputs to read and modify database commands, resulting in the retrieval of additional information persisted by the system.

CVE-2023-3192
froxlor/froxlor General
4.2
MEDIUM
EPSS
0.2%
2023 CWE-384 1 PoC

Session Fixation in GitHub repository froxlor/froxlor prior to 2.1.0.

CVE-2023-2784
Mattermost App Framework General
4.2
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

Mattermost fails to verify if the requestor is a sysadmin or not, before allowing `install` requests to the Apps allowing a regular user send install requests to the Apps.

CVE-2023-25758
Software Genérico General
4.2
MEDIUM
EPSS
0.1%
2023 1 PoC

Onekey Touch devices through 4.0.0 and Onekey Mini devices through 2.10.0 allow man-in-the-middle attackers to obtain the seed phase. The man-in-the-middle access can only be obtained after disassembling a device (i.e., here, "man-in-the-middle" does not refer to the attacker's position on an IP network). NOTE: the vendor states that "our hardware team has updated the security patch without anyone being affected."

CVE-2023-21432
Smart Things General
4.2
MEDIUM
EPSS
0.0%
2023 CWE-285 1 PoC

Improper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without authorization of the owner.

CVE-2023-3586
Mattermost General
4.2
MEDIUM
EPSS
0.2%
2023 CWE-863 1 PoC

Mattermost fails to disable public Boards after the "Enable Publicly-Shared Boards" configuration option is disabled, resulting in previously-shared public Boards to remain accessible.

CVE-2023-4138
ikus060/rdiffweb General
4.2
MEDIUM
EPSS
0.1%
2023 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.0.

CVE-2023-1774
Mattermost General
4.2
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.

CVE-2023-21462
Quick Share Agent General
4.2
MEDIUM
EPSS
0.1%
2023 CWE-215 1 PoC

The sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 allows to local attacker to access MAC address without related permission.

CVE-2023-38058
OTRS General
4.1
MEDIUM
EPSS
0.2%
2023 CWE-269 1 PoC

An improper privilege check in the OTRS ticket move action in the agent interface allows any as agent authenticated attacker to to perform a move of an ticket without the needed permission. This issue affects OTRS: from 8.0.X before 8.0.35.

CVE-2023-5838
linkstackorg/linkstack General
4.1
MEDIUM
EPSS
0.0%
2023 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9.