3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-23854
NetWeaver AS ABAP and ABAP Platform General
3.8
LOW
EPSS
0.3%
2023 CWE-862 1 PoC

SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

CVE-2023-4005
fossbilling/fossbilling General
3.8
LOW
EPSS
0.1%
2023 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5.

CVE-2023-4304
froxlor/froxlor General
3.8
LOW
EPSS
0.2%
2023 CWE-840 1 PoC

Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.22,2.1.0.

CVE-2023-29112
Application Interface Framework (Message Monitoring) General
3.7
LOW
EPSS
0.4%
2023 CWE-80 1 PoC

The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized attacker to input links or headings with custom CSS classes into a comment. The comment will render links and custom CSS classes as HTML objects. After successful exploitations, an attacker can cause limited impact on the confidentiality and integrity of the application.

CVE-2023-33849
TXSeries for Multiplatforms General
3.7
LOW
EPSS
0.0%
2023 CWE-311 1 PoC

IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could transmit sensitive information in query parameters that could be intercepted using man in the middle techniques. IBM X-Force ID: 257105.

CVE-2023-26112
configobj General
3.7
LOW
EPSS
0.1%
2023 CWE-1333 1 PoC

All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate function, using (.+?)\((.*)\). **Note:** This is only exploitable in the case of a developer, putting the offending value in a server side configuration file.

CVE-2023-5461
WPLSoft General
3.7
LOW
EPSS
0.2%
2023 CWE-319 1 PoC

A vulnerability was found in Delta Electronics WPLSoft 2.51. It has been classified as problematic. Affected is an unknown function of the component Modbus Handler. The manipulation leads to cleartext transmission of sensitive information. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-241584. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-34401
Software Genérico General
3.7
LOW
EPSS
0.3%
2023 1 PoC

Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside profile folder there is a file, which is encoded with proprietary UD2 codec. Due to missed size checks in the enapsulate file, attacker can achieve Out-of-Bound Read in heap memory.

CVE-2023-39206
Zoom Clients General
3.7
LOW
EPSS
0.3%
2023 CWE-120 1 PoC

Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.

CVE-2023-29110
Application Interface Framework (Message Dashboard) General
3.7
LOW
EPSS
0.4%
2023 CWE-80 1 PoC

The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows the usage HTML tags. An authorized attacker can use some of the basic HTML codes such as heading, basic formatting and lists, then an attacker can inject images from the foreign domains. After successful exploitations, an attacker can cause limited impact on the confidentiality and integrity of the application.

CVE-2023-32334
Maximo Asset Management General
3.7
LOW
EPSS
0.1%
2023 1 PoC

IBM Maximo Asset Management 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 255074.

CVE-2023-5875
Mattermost Desktop General
3.7
LOW
EPSS
0.2%
2023 CWE-693 1 PoC

Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server

CVE-2023-50804
Software Genérico General
3.7
LOW
EPSS
0.1%
2023 1 PoC

An issue was discovered in Samsung Mobile Processor, and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos Modem 5123, Exynos Modem 5300. The baseband software does not properly check format types specified by the NAS (Non-Access-Stratum) module. This can lead to bypass of authentication.

CVE-2023-50333
Mattermost General
3.7
LOW
EPSS
0.1%
2023 CWE-284 1 PoC

Mattermost fails to update the permissions of the current session for a user who was just demoted to guest, allowing freshly demoted guests to change group names.

CVE-2023-6547
Mattermost General
3.7
LOW
EPSS
0.3%
2023 CWE-284 1 PoC

Mattermost fails to validate team membership when a user attempts to access a playbook, allowing a user with permissions to a playbook but no permissions to the team the playbook is on to access and modify the playbook. This can happen if the user was once a member of the team, got permissions to the playbook and was then removed from the team. 

CVE-2023-4392
Gerencia Web General
3.7
LOW
EPSS
0.1%
2023 CWE-312 2 PoCs

A vulnerability was found in Control iD Gerencia Web 1.30 and classified as problematic. Affected by this issue is some unknown functionality of the component Cookie Handler. The manipulation leads to cleartext storage of sensitive information. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-237380. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-4384
Portal Executivo General
3.7
LOW
EPSS
0.0%
2023 CWE-311 2 PoCs

A vulnerability has been found in MaximaTech Portal Executivo 21.9.1.140 and classified as problematic. This vulnerability affects unknown code of the component Cookie Handler. The manipulation leads to missing encryption of sensitive data. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-237316. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-7113
Mattermost General
3.7
LOW
EPSS
0.7%
2023 CWE-79 1 PoC

Mattermost version 8.1.6 and earlier fails to sanitize channel mention data in posts, which allows an attacker to inject markup in the web client.

CVE-2023-5142
GR-1100-P General
3.7
LOW
EPSS
0.3%
2023 CWE-22 1 PoC

A vulnerability classified as problematic was found in H3C GR-1100-P, GR-1108-P, GR-1200W, GR-1800AX, GR-2200, GR-3200, GR-5200, GR-8300, ER2100n, ER2200G2, ER3200G2, ER3260G2, ER5100G2, ER5200G2 and ER6300G2 up to 20230908. This vulnerability affects unknown code of the file /userLogin.asp of the component Config File Handler. The manipulation leads to path traversal. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. VDB-240238 is the identifier assigned to t

CVE-2023-3761
SGS General
3.7
LOW
EPSS
0.1%
2023 CWE-319 2 PoCs

A vulnerability was found in Intergard SGS 8.7.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Password Change Handler. The manipulation leads to cleartext transmission of sensitive information. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. VDB-234446 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.