3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-36163
Software Genérico General
N/A
UNKNOWN
EPSS
16.7%
2023 2 PoCs

Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the mc parameter of the URL.

CVE-2023-27974
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Bitwarden through 2023.2.1 offers password auto-fill when the second-level domain matches, e.g., a password stored for an example.com hosting provider when customer-website.example.com is visited. NOTE: the vendor's position is that "Auto-fill on page load" is not enabled by default.

CVE-2023-35695
Trend Micro Moibile Security for Enterprise General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A remote attacker could leverage a vulnerability in Trend Micro Mobile Security (Enterprise) 9.8 SP5 to download a particular log file which may contain sensitive information regarding the product.

CVE-2023-34934
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A stack overflow in the Edit_BasicSSID_5G function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2023-21389
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In Settings, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-37456
Firefox for iOS General
N/A
UNKNOWN
EPSS
0.4%
2023 2 PoCs

The session restore helper crashed whenever there was no parameter sent to the message handler. This vulnerability affects Firefox for iOS < 115.

CVE-2023-38907
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to replay old messages encrypted with a still valid session key.

CVE-2023-38872
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of the attachment.

CVE-2023-44271
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument.

CVE-2023-29656
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

An improper authorization vulnerability in Darktrace mobile app (Android) prior to version 6.0.15 allows disabled and low-privilege users to control "antigena" actions(block/unblock traffic) from the mobile application. This vulnerability could create a "shutdown", blocking all ingress or egress traffic in the entire infrastructure where darktrace agents are deployed.

CVE-2023-33270
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2023 1 PoC

An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the Curl check function is vulnerable to OS command injection (blind).

CVE-2023-33743
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Access Control; specifically, Android Debug Bridge (adb) is available.

CVE-2023-38433
IP-HE950E General ⚡ nuclei
N/A
UNKNOWN
EPSS
53.2%
2023 0 PoCs

Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or reboot the products, and as a result, terminate the video transmission. Affected products and versions are as follows: IP-HE950E firmware versions V01L001 to V01L053, IP-HE950D firmware versions V01L001 to V01L053, IP-HE900E firmware versions V01L001 to V01L010, IP-HE900D firmware versions V01L001 to V01L004, IP-900E / IP-920E firmware versions V01L001 to V02L061, IP-900D / IP-900ⅡD / IP-920D firmware versions V01L001 to V02L061, IP-90 firmware ve

CVE-2023-47250
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 3 PoCs

In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, broken Access Control on X11 server sockets allows authenticated attackers (with access to a VNC session) to access the X11 desktops of other users by specifying their DISPLAY ID. This allows complete control of their desktop, including the ability to inject keystrokes and perform a keylogging attack.

CVE-2023-36619
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2023 2 PoCs

Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users.

CVE-2023-36123
Software Genérico General
N/A
UNKNOWN
EPSS
11.9%
2023 1 PoC

Directory Traversal vulnerability in Hex-Dragon Plain Craft Launcher 2 version Alpha 1.3.9, allows local attackers to execute arbitrary code and gain sensitive information.

CVE-2023-36621
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictions temporarily or uninstall the application without the parents noticing.

CVE-2023-36168
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Sin descripción disponible.

CVE-2023-34196
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an authentication issue. In configurations using OAuth, disclosure of CA certificates (attributes and public keys) to unauthenticated or less privileged users may occur.

CVE-2023-2002
Kernel General
N/A
UNKNOWN
EPSS
0.6%
2023 CWE-250 2 PoCs

A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows an attacker to unauthorized execution of management commands, compromising the confidentiality, integrity, and availability of Bluetooth communication.