3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-31445
Software Genérico General
N/A
UNKNOWN
EPSS
2.8%
2023 3 PoCs

Cassia Access controller before 2.1.1.2203171453, was discovered to have a unprivileged -information disclosure vulnerability that allows read-only users have the ability to enumerate all other users and discover e-mail addresses, phone numbers, and privileges of all other users.

CVE-2023-34553
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

An issue was discovered in WAFU Keyless Smart Lock v1.0 allows attackers to unlock a device via code replay attack.

CVE-2023-31067
Software Genérico General
N/A
UNKNOWN
EPSS
1.6%
2023 2 PoCs

An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\Clients\www.

CVE-2023-45690
Titan MFT General
N/A
UNKNOWN
EPSS
0.3%
2023 CWE-276 1 PoC

Default file permissions on South River Technologies' Titan MFT and Titan SFTP servers on Linux allows a user that's authentication to the OS to read sensitive files on the filesystem

CVE-2023-29491
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO or TERM environment variable.

CVE-2023-2156
Linux kernel (RPL protocol) General
N/A
UNKNOWN
EPSS
2.1%
2023 CWE-617 1 PoC

A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the system.

CVE-2023-24129
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey4 parameter at /goform/WifiBasicSet.

CVE-2023-43201
Software Genérico General
N/A
UNKNOWN
EPSS
2.0%
2023 1 PoC

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the hi_up parameter in the qos_ext.asp function.

CVE-2023-37734
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 3 PoCs

EZ softmagic MP3 Audio Converter 2.7.3.700 was discovered to contain a buffer overflow.

CVE-2023-37791
Software Genérico General
N/A
UNKNOWN
EPSS
14.8%
2023 1 PoC

D-Link DIR-619L v2.04(TW) was discovered to contain a stack overflow via the curTime parameter at /goform/formLogin.

CVE-2023-40359
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e., neither alphanumeric nor underscore), aka a pointer/overflow issue. This can only occur for xterm installations that are configured at compile time to use a certain experimental feature.

CVE-2023-42362
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

An arbitrary file upload vulnerability in Teller Web App v.4.4.0 allows a remote attacker to execute arbitrary commands and obtain sensitive information via uploading a crafted file.

CVE-2023-32205
Firefox General
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusion and spoofing attacks. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

CVE-2023-29856
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

D-Link DIR-868L Hardware version A1, firmware version 1.12 is vulnerable to Buffer Overflow. The vulnerability is in scandir.sgi binary.

CVE-2023-20780
MT6580, MT6731, MT6735, MT6737, MT6739, MT6753, MT6757, MT6757C, MT6757CD, MT6757CH, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6891, MT6893, MT6895, MT6983, MT6985, MT8185, MT8321, MT8385, MT8666, MT8673, MT8675, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8797 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In keyinstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017756; Issue ID: ALPS08017756.

CVE-2023-5732
Firefox General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

An attacker could have created a malicious link using bidirectional characters to spoof the location in the address bar when visited. This vulnerability affects Firefox < 117, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

CVE-2023-45688
Titan MFT General
N/A
UNKNOWN
EPSS
0.3%
2023 CWE-22 1 PoC

Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Linux allows an authenticated attacker to get the size of an arbitrary file on the filesystem using path traversal in the ftp "SIZE" command

CVE-2023-45542
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
43.3%
2023 1 PoC

Cross Site Scripting vulnerability in mooSocial 3.1.8 allows a remote attacker to obtain sensitive information via a crafted script to the q parameter in the Search function.

CVE-2023-26762
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an arbitrary file upload vulnerability.

CVE-2023-33668
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2023 1 PoC

DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared computers.