3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-20593
Ryzen™ 3000 Series Desktop Processors “Matisse” AM4 General
N/A
UNKNOWN
EPSS
5.9%
2023 3 PoCs

An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.

CVE-2023-34260
Software Genérico General
N/A
UNKNOWN
EPSS
3.4%
2023 1 PoC

Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow a denial of service (service outage) via /wlmdeu%2f%2e%2e%2f%2e%2e followed by a directory reference such as %2fetc%00index.htm to try to read the /etc directory.

CVE-2023-34937
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A stack overflow in the UpdateSnat function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2023-38633
Software Genérico General
N/A
UNKNOWN
EPSS
43.6%
2023 2 PoCs

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.

CVE-2023-39910
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

The cryptocurrency wallet entropy seeding mechanism used in Libbitcoin Explorer 3.0.0 through 3.6.0 is weak, aka the Milk Sad issue. The use of an mt19937 Mersenne Twister PRNG restricts the internal entropy to 32 bits regardless of settings. This allows remote attackers to recover any wallet private keys generated from "bx seed" entropy output and steal funds. (Affected users need to move funds to a secure new cryptocurrency wallet.) NOTE: the vendor's position is that there was sufficient documentation advising against "bx seed" but others disagree. NOTE: this was exploited in the wild in Ju

CVE-2023-28874
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary sites.

CVE-2023-51016
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the setRebootScheCfg interface of the cstecgi .cgi.

CVE-2023-33626
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a stack overflow via the gena.cgi binary.

CVE-2023-6112
Chrome General
N/A
UNKNOWN
EPSS
28.2%
2023 1 PoC

Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-35866
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In KeePassXC through 2.7.5, a local attacker can make changes to the Database security settings, including master password and second-factor authentication, within an authenticated KeePassXC Database session, without the need to authenticate these changes by entering the password and/or second-factor authentication to confirm changes. NOTE: the vendor's position is "asking the user for their password prior to making any changes to the database settings adds no additional protection against a local attacker."

CVE-2023-39138
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue in ZIPFoundation v0.9.16 allows attackers to execute a path traversal via extracting a crafted zip file.

CVE-2023-46449
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 3 PoCs

Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function.

CVE-2023-48929
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Session Fixation. The 'sid' parameter in the group_status.asp resource allows an attacker to escalate privileges and obtain sensitive information.

CVE-2023-36143
Software Genérico General
N/A
UNKNOWN
EPSS
11.6%
2023 2 PoCs

Maxprint Maxlink 1200G v3.4.11E has an OS command injection vulnerability in the "Diagnostic tool" functionality of the device.

CVE-2023-51027
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘apcliAuthMode’ parameter of the setWiFiExtenderConfig interface of the cstecgi .cgi.

CVE-2023-40292
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Harman Infotainment 20190525031613 and later discloses the IP address via CarPlay CTRL packets.

CVE-2023-42882
macOS General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2. Processing an image may lead to arbitrary code execution.

CVE-2023-47271
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

PKP-WAL (aka PKP Web Application Library or pkp-lib) before 3.3.0-16, as used in Open Journal Systems (OJS) and other products, does not verify that the file named in an XML document (used for the native import/export plugin) is an image file, before trying to use it for an issue cover image.

CVE-2023-26510
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsistent with a security policy in which a contributor's draft can only be read by editors until published by an editor. NOTE: the vendor's position is that this behavior has no security impact.