3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-33744
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671.

CVE-2023-33902
SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In bluetooth service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVE-2023-31320
Radeon™ RX 5000/6000/7000 Series Graphics Cards General
N/A
UNKNOWN
EPSS
5.2%
2023 2 PoCs

Improper input validation in the AMD RadeonTM Graphics display driver may allow an attacker to corrupt the display potentially resulting in denial of service.

CVE-2023-37599
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
85.6%
2023 1 PoC

An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory

CVE-2023-1103
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Sin descripción disponible.

CVE-2023-30223
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packets containing requests to perform arbitrary actions.

CVE-2023-47675
CubeCart General
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to execute an arbitrary OS command.

CVE-2023-38351
Software Genérico General
N/A
UNKNOWN
EPSS
6.0%
2023 1 PoC

MiniTool Partition Wizard 12.8 contains an insecure installation mechanism that allows attackers to achieve remote code execution through a man in the middle attack.

CVE-2023-43241
Software Genérico General
N/A
UNKNOWN
EPSS
2.5%
2023 1 PoC

D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter TXPower and GuardInt in SetWLanRadioSecurity.

CVE-2023-36348
Software Genérico General
N/A
UNKNOWN
EPSS
5.5%
2023 3 PoCs

POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter.

CVE-2023-41149
F-RevoCRM General
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

F-RevoCRM version7.3.7 and version7.3.8 contains an OS command injection vulnerability. If this vulnerability is exploited, an attacker who can access the product may execute an arbitrary OS command on the server where the product is running.

CVE-2023-47327
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The "Create a Space" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access control, allowing any authenticated user to create a space by navigating to the correct URL.

CVE-2023-40779
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
35.9%
2023 2 PoCs

An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL.

CVE-2023-41105
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejected a filename for security reasons in Python 3.10.x or earlier, but that filename is no longer rejected in Python 3.11.x.

CVE-2023-20583
Processors General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A potential power side-channel vulnerability in AMD processors may allow an authenticated attacker to monitor the CPU power consumption as the data in a cache line changes over time potentially resulting in a leak of sensitive information.

CVE-2023-28508
UniData General
N/A
UNKNOWN
EPSS
0.5%
2023 CWE-120 1 PoC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based overflow vulnerability, where certain input can corrupt the heap and crash the forked process.

CVE-2023-37207
Firefox General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.

CVE-2023-33469
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

In instances where the screen is visible and remote mouse connection is enabled, KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 can be exploited to achieve local code execution at the root level.

CVE-2023-37307
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.

CVE-2023-39638
Software Genérico General
N/A
UNKNOWN
EPSS
2.4%
2023 1 PoC

D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 was discovered to contain a command injection vulnerability via the lxmldbc_system function at /htdocs/cgibin.