3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-5353
salesagility/suitecrm General
8.1
HIGH
EPSS
0.1%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.

CVE-2023-40463
ALEOS General
8.1
HIGH
EPSS
0.0%
2023 CWE-798 1 PoC

When configured in debugging mode by an authenticated user with administrative privileges, ALEOS 4.16 and earlier store the SHA512 hash of the common root password for that version in a directory accessible to a user with root privileges or equivalent access.

CVE-2023-45839
Buildroot General
8.1
HIGH
EPSS
0.1%
2023 CWE-494 2 PoCs

Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `aufs-util` package.

CVE-2023-20895
VMware vCenter Server (vCenter Server) General
8.1
HIGH
EPSS
0.4%
2023 1 PoC

The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass authentication.

CVE-2023-3615
Mattermost iOS app General
8.1
HIGH
EPSS
0.3%
2023 CWE-295 1 PoC

Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a network attacker to intercept the WebSockets connection.

CVE-2023-26067
Software Genérico General ⚡ nuclei
8.1
HIGH
EPSS
93.0%
2023 2 PoCs

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).

CVE-2023-32284
ImageGear General
8.1
HIGH
EPSS
0.3%
2023 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the tiff_planar_adobe functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-24332
Software Genérico General
8.1
HIGH
EPSS
0.1%
2023 1 PoC

A stack overflow vulnerability in Tenda AC6 with firmware version US_AC6V5.0re_V03.03.02.01_cn_TDC01 allows attackers to run arbitrary commands via crafted POST request to /goform/PowerSaveSet.

CVE-2023-34998
OAS Platform General
8.1
HIGH
EPSS
0.0%
2023 CWE-319 1 PoC

An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary authentication. An attacker can sniff network traffic to trigger this vulnerability.

CVE-2023-5395
Experion Server General
8.1
HIGH
EPSS
1.2%
2023 CWE-121 1 PoC

Server receiving a malformed message that uses the hostname in an internal table may cause a stack overflow resulting in possible remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-47257
Software Genérico General
8.1
HIGH
EPSS
6.4%
2023 1 PoC

ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.

CVE-2023-3314
Enterprise Security Manager General
8.1
HIGH
EPSS
0.6%
2023 CWE-78 1 PoC

A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands used to control the process execution of the .zip application allows an authorized user to obtain control of the .zip application to execute arbitrary commands or obtain elevation of system privileges.

CVE-2023-0569
publify/publify General
8.1
HIGH
EPSS
0.1%
2023 CWE-521 1 PoC

Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10.

CVE-2023-6254
OTRS General
8.1
HIGH
EPSS
0.2%
2023 CWE-522 1 PoC

A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are send back to the client in the server response- This issue affects OTRS: from 8.0.X through 8.0.37.

CVE-2023-34216
TN-5900 Series General
8.1
HIGH
EPSS
0.3%
2023 CWE-22 1 PoC

TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability derives from insufficient input validation in the key-delete function, which could potentially allow malicious users to delete arbitrary files.

CVE-2023-3224
nuxt/nuxt General
8.1
HIGH
EPSS
2.1%
2023 CWE-94 1 PoC

Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3.

CVE-2023-30729
Samsung Email General
8.1
HIGH
EPSS
0.3%
2023 1 PoC

Improper Certificate Validation in Samsung Email prior to version 6.1.82.0 allows remote attacker to intercept the network traffic including sensitive information.

CVE-2023-43608
Buildroot General
8.1
HIGH
EPSS
0.1%
2023 CWE-494 2 PoCs

A data integrity vulnerability exists in the BR_NO_CHECK_HASH_FOR functionality of Buildroot 2023.08.1 and dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.

CVE-2023-0947
flatpressblog/flatpress General ⚡ nuclei
8.1
HIGH
EPSS
53.0%
2023 CWE-22 1 PoC

Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2023-52043
Software Genérico General
8.1
HIGH
EPSS
0.1%
2023 1 PoC

An issue in D-Link COVR 1100, 1102, 1103 AC1200 Dual-Band Whole-Home Mesh Wi-Fi System (Hardware Rev B1) truncates Wireless Access Point Passwords (WPA-PSK) allowing an attacker to gain unauthorized network access via weak authentication controls.