3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-24503
OSK201 General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW.

CVE-2023-26451
OX App Suite General
7.5
HIGH
EPSS
0.1%
2023 CWE-330 1 PoC

Functions with insufficient randomness were used to generate authorization tokens of the integrated oAuth Authorization Service. Authorization codes were predictable for third parties and could be used to intercept and take over the client authorization process. As a result, other users accounts could be compromised. The oAuth Authorization Service is not enabled by default. We have updated the implementation to use sources with sufficient randomness to generate authorization tokens. No publicly available exploits are known.

CVE-2023-24506
NCR/Camera General
7.5
HIGH
EPSS
0.3%
2023 CWE-522 1 PoC

Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request.

CVE-2023-48834
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion.

CVE-2023-44830
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the EndTime parameter in the SetParentsControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-37478
pnpm General
7.5
HIGH
EPSS
1.6%
2023 CWE-284 2 PoCs

pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed via pnpm is malicious, due to how pnpm parses tar archives. This can result in a package that appears safe on the npm registry or when installed via npm being replaced with a compromised or malicious version when installed via pnpm. This issue has been patched in version(s) 7.33.4 and 8.6.8.

CVE-2023-26597
C300 General
7.5
HIGH
EPSS
0.1%
2023 CWE-400 1 PoC

Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-24500
Electra Central AC unit General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW.

CVE-2023-26071
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

An issue was discovered in MCUBO ICT through 10.12.4 (aka 6.0.2). An Observable Response Discrepancy can occur under the login web page. In particular, the web application provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor. That allow an unauthorized actor to perform User Enumeration attacks.

CVE-2023-46346
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 4.1.1 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a path traversal to view all files on the information system.

CVE-2023-42487
Soundminer General
7.5
HIGH
EPSS
0.4%
2023 CWE-22 1 PoC

Soundminer – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVE-2023-29748
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 2 PoCs

Story Saver for Instragram - Video Downloader 1.0.6 for Android has an exposed component that provides a method to modify the SharedPreference file. An attacker can leverage this method to inject a large amount of data into any SharedPreference file, which will be loaded into memory when the application is opened. When an attacker injects too much data, the application will trigger an OOM error and crash at startup, resulting in a persistent denial of service.

CVE-2023-29298
🔥 KEV ColdFusion General ⚡ nuclei
7.5
HIGH
EPSS
94.3%
2023 CWE-284 0 PoCs

Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.

CVE-2023-20531
2nd Gen EPYC General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a denial of service.

CVE-2023-48831
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.

CVE-2023-29723
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

The Glitter Unicorn Wallpaper app for Android 7.0 thru 8.0 allows unauthorized applications to actively request permission to insert data into the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the application is opened. By injecting data, the attacker can force the application to load malicious image URLs and display them in the UI. As the amount of data increases, it will eventually cause the application to trigger an OOM error and crash, resulting in a persistent denial of service attack.

CVE-2023-27599
opensips General
7.5
HIGH
EPSS
0.4%
2023 CWE-20 1 PoC

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, when the function `append_hf` handles a SIP message with a malformed To header, a call to the function `abort()` is performed, resulting in a crash. This is due to the following check in `data_lump.c:399` in the function `anchor_lump`. An attacker abusing this vulnerability will crash OpenSIPS leading to Denial of Service. It affects configurations containing functions that make use of the affected code, such as the function `append_hf`. This issue has been fixed in versions 3.1.7 and 3.2.

CVE-2023-26256
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
91.8%
2023 7 PoCs

An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying the fileName parameter to the snjFooterNavigationConfig endpoint, it is possible to traverse and read the file system.

CVE-2023-26139
underscore-keypath General
7.5
HIGH
EPSS
0.1%
2023 CWE-1321 1 PoC

Versions of the package underscore-keypath from 0.0.11 are vulnerable to Prototype Pollution via the name argument of the setProperty() function. Exploiting this vulnerability is possible due to improper input sanitization which allows the usage of arguments like “__proto__”.

CVE-2023-47117
label-studio General ⚡ nuclei
7.5
HIGH
EPSS
65.8%
2023 CWE-200 0 PoCs

Label Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token