3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-29111
Application Interface Framework (ODATA service) General
3.1
LOW
EPSS
0.4%
2023 CWE-200 1 PoC

The SAP AIF (ODATA service) - versions 755, 756, discloses more detailed information than is required. An authorized attacker can use the collected information possibly to exploit the component. As a result, an attacker can cause a low impact on the confidentiality of the application.

CVE-2023-0858
Canon Office/Small Office Multifunction Printers and Laser Printers General
3.1
LOW
EPSS
0.1%
2023 CWE-284 1 PoC

Improper Authentication of RemoteUI of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger unauthorized access to the product. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i firmware Ver.11.04 and earlier sold in Europe.

CVE-2023-2281
Mattermost General
3.1
LOW
EPSS
0.3%
2023 CWE-200 1 PoC

When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.

CVE-2023-0057
pyload/pyload General
3.1
LOW
EPSS
0.9%
2023 CWE-1021 1 PoC

Improper Restriction of Rendered UI Layers or Frames in GitHub repository pyload/pyload prior to 0.5.0b3.dev33.

CVE-2023-6599
microweber/microweber General
3.1
LOW
EPSS
0.3%
2023 CWE-544 1 PoC

Missing Standardized Error Handling Mechanism in GitHub repository microweber/microweber prior to 2.0.

CVE-2023-6727
Mattermost General
3.1
LOW
EPSS
0.3%
2023 CWE-200 1 PoC

Mattermost fails to perform correct authorization checks when creating a playbook action, allowing users without access to the playbook to create playbook actions. If the playbook action created is to post a message in a channel based on specific keywords in a post, some playbook information, like the name, can be leaked. 

CVE-2023-35124
OAS Platform General
3.1
LOW
EPSS
0.1%
2023 CWE-209 1 PoC

An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to a disclosure of sensitive information. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-2797
Mattermost Github Plugin General
3.1
LOW
EPSS
0.6%
2023 CWE-74 1 PoC

Mattermost fails to sanitize code permalinks, allowing an attacker to preview code from private repositories by posting a specially crafted permalink on a channel.

CVE-2023-3590
Mattermost General
3.1
LOW
EPSS
0.4%
2023 CWE-863 1 PoC

Mattermost fails to delete card attachments in Boards, allowing an attacker to access deleted attachments.

CVE-2023-5496
PoqDev Add-On General
3.1
LOW
EPSS
0.3%
2023 CWE-79 1 PoC

A vulnerability was found in Translator PoqDev Add-On 1.0.11 on Firefox. It has been rated as problematic. This issue affects some unknown processing of the component Select Text Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-241649 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-3515
go-gitea/gitea General
3.0
LOW
EPSS
0.1%
2023 CWE-601 1 PoC

Open Redirect in GitHub repository go-gitea/gitea prior to 1.19.4.

CVE-2023-2662
Xpdf General
2.9
LOW
EPSS
0.0%
2023 CWE-369 1 PoC

In Xpdf 4.04 (and earlier), a bad color space object in the input PDF file can cause a divide-by-zero.

CVE-2023-2664
Xpdf General
2.9
LOW
EPSS
0.1%
2023 CWE-674 1 PoC

 In Xpdf 4.04 (and earlier), a PDF object loop in the embedded file tree leads to infinite recursion and a stack overflow.

CVE-2023-2663
Xpdf General
2.9
LOW
EPSS
0.1%
2023 CWE-674 1 PoC

 In Xpdf 4.04 (and earlier), a PDF object loop in the page label tree leads to infinite recursion and a stack overflow.

CVE-2023-5920
Mattermost Desktop General
2.9
LOW
EPSS
0.1%
2023 CWE-200 1 PoC

Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input.

CVE-2023-32112
Vendor Master Hierarchy General
2.8
LOW
EPSS
0.1%
2023 CWE-862 1 PoC

Vendor Master Hierarchy - versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, SAP_APPL 606, SAP_APPL 616, SAP_APPL 617, SAP_APPL 618, S4CORE 100, does not perform necessary authorization checks for an authenticated user to access some of its function. This could lead to modification of data impacting the integrity of the system.

CVE-2023-1560
TinyTIFF General
2.8
LOW
EPSS
0.1%
2023 CWE-120 1 PoC

A vulnerability, which was classified as problematic, has been found in TinyTIFF 3.0.0.0. This issue affects some unknown processing of the file tinytiffreader.c of the component File Handler. The manipulation leads to buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The identifier VDB-223553 was assigned to this vulnerability.

CVE-2023-4466
CCX 400 General
2.7
LOW
EPSS
0.1%
2023 CWE-693 1 PoC

A vulnerability has been found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web Interface. The manipulation leads to protection mechanism failure. The attack can be launched remotely. The vendor explains that they do not regard this as a vulnerability as this is a feature that they offer to their customers who have a variety of environmental needs that are met through different firmware builds. To avoid potential roll-back attacks, they remove vulnerable builds from the public servers

CVE-2023-0850
WNDR3700v2 General
2.7
LOW
EPSS
0.4%
2023 CWE-404 1 PoC

A vulnerability was found in Netgear WNDR3700v2 1.0.1.14 and classified as problematic. This issue affects some unknown processing of the component Web Interface. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221153 was assigned to this vulnerability.

CVE-2023-32114
SAP NetWeaver (Change and Transport System) General
2.7
LOW
EPSS
0.1%
2023 CWE-732 1 PoC

SAP NetWeaver (Change and Transport System) - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an authenticated user with admin privileges to maliciously run a benchmark program repeatedly in intent to slowdown or make the server unavailable which may lead to a limited impact on Availability with No impact on Confidentiality and Integrity of the application.