3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-5403
Experion Server General
8.1
HIGH
EPSS
1.0%
2023 CWE-121 1 PoC

Server hostname translation to IP address manipulation which could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-0569
publify/publify General
8.1
HIGH
EPSS
0.1%
2023 CWE-521 1 PoC

Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10.

CVE-2023-31178
NX General
8.1
HIGH
EPSS
0.2%
2023 1 PoC

AgilePoint NX v8.0 SU2.2 & SU2.3 – Arbitrary File Delete Vulnerability allows arbitrary file deletion, by an unspecified request.

CVE-2023-6254
OTRS General
8.1
HIGH
EPSS
0.2%
2023 CWE-522 1 PoC

A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are send back to the client in the server response- This issue affects OTRS: from 8.0.X through 8.0.37.

CVE-2023-30729
Samsung Email General
8.1
HIGH
EPSS
0.3%
2023 1 PoC

Improper Certificate Validation in Samsung Email prior to version 6.1.82.0 allows remote attacker to intercept the network traffic including sensitive information.

CVE-2023-5397
Experion Server General
8.1
HIGH
EPSS
0.3%
2023 CWE-20 1 PoC

Server receiving a malformed message to create a new connection could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-0919
kareadita/kavita General
8.1
HIGH
EPSS
0.3%
2023 CWE-306 1 PoC

Missing Authentication for Critical Function in GitHub repository kareadita/kavita prior to 0.7.0.

CVE-2023-43608
Buildroot General
8.1
HIGH
EPSS
0.1%
2023 CWE-494 2 PoCs

A data integrity vulnerability exists in the BR_NO_CHECK_HASH_FOR functionality of Buildroot 2023.08.1 and dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.

CVE-2023-51073
Software Genérico General
8.1
HIGH
EPSS
26.0%
2023 1 PoC

An issue in Buffalo LS210D v.1.78-0.03 allows a remote attacker to execute arbitrary code via the Firmware Update Script at /etc/init.d/update_notifications.sh.

CVE-2023-0947
flatpressblog/flatpress General ⚡ nuclei
8.1
HIGH
EPSS
53.0%
2023 CWE-22 1 PoC

Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2023-46694
Software Genérico General
8.1
HIGH
EPSS
9.1%
2023 1 PoC

Vtenext 21.02 allows an authenticated attacker to upload arbitrary files, potentially enabling them to execute remote commands. This flaw exists due to the application's failure to enforce proper authentication controls when accessing the Ckeditor file manager functionality.

CVE-2023-34998
OAS Platform General
8.1
HIGH
EPSS
0.0%
2023 CWE-319 1 PoC

An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary authentication. An attacker can sniff network traffic to trigger this vulnerability.

CVE-2023-5401
Experion Server General
8.1
HIGH
EPSS
1.6%
2023 CWE-121 1 PoC

Server receiving a malformed message based on a using the specified key values can cause a stack overflow vulnerability which could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-5353
salesagility/suitecrm General
8.1
HIGH
EPSS
0.1%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.

CVE-2023-45838
Buildroot General
8.1
HIGH
EPSS
0.1%
2023 CWE-494 2 PoCs

Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `aufs` package.

CVE-2023-23567
ImageGear General
8.1
HIGH
EPSS
0.2%
2023 CWE-119 1 PoC

A heap-based buffer overflow vulnerability exists in the CreateDIBfromPict functionality of Accusoft ImageGear 20.1. A specially crafted file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-45840
Buildroot General
8.1
HIGH
EPSS
0.1%
2023 CWE-494 2 PoCs

Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `riscv64-elf-toolchain` package.

CVE-2023-2942
openemr/openemr General
8.1
HIGH
EPSS
0.5%
2023 CWE-20 1 PoC

Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.1.

CVE-2023-2315
Opencart General
8.1
HIGH
EPSS
0.3%
2023 CWE-22 1 PoC

Path Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2 allows an authenticated user with access/modify privilege on the Log component to empty out arbitrary files on the server

CVE-2023-1542
answerdev/answer General
8.1
HIGH
EPSS
0.3%
2023 CWE-840 1 PoC

Business Logic Errors in GitHub repository answerdev/answer prior to 1.0.6.