3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-47091
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10, and SNS 4.7.0 through 4.7.1 before 4.7.2. An attacker can overflow the cookie threshold, making an IPsec connection impossible.

CVE-2023-45893
Software Genérico General
7.5
HIGH
EPSS
1.0%
2023 1 PoC

An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.

CVE-2023-20529
2nd Gen EPYC General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Insufficient bound checks in the SMU may allow an attacker to update the from/to address space to an invalid value potentially resulting in a denial of service.

CVE-2023-27705
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

APNG_Optimizer v1.4 was discovered to contain a buffer overflow via the component /apngopt/ubuntu.png.

CVE-2023-51065
Software Genérico General
7.5
HIGH
EPSS
0.6%
2023 1 PoC

Incorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to obtain system backups and other sensitive information from the QStar Server.

CVE-2023-26575
IDWeb General
7.5
HIGH
EPSS
0.1%
2023 CWE-306 1 PoC

Missing authentication in the SearchStudentsStaff method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student and teacher data by unauthenticated attackers.

CVE-2023-29748
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 2 PoCs

Story Saver for Instragram - Video Downloader 1.0.6 for Android has an exposed component that provides a method to modify the SharedPreference file. An attacker can leverage this method to inject a large amount of data into any SharedPreference file, which will be loaded into memory when the application is opened. When an attacker injects too much data, the application will trigger an OOM error and crash at startup, resulting in a persistent denial of service.

CVE-2023-27598
opensips General
7.5
HIGH
EPSS
0.4%
2023 CWE-908 1 PoC

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, sending a malformed `Via` header to OpenSIPS triggers a segmentation fault when the function `calc_tag_suffix` is called. A specially crafted `Via` header, which is deemed correct by the parser, will pass uninitialized strings to the function `MD5StringArray` which leads to the crash. Abuse of this vulnerability leads to Denial of Service due to a crash. Since the uninitialized string points to memory location `0x0`, no further exploitation appears to be possible. No special network privil

CVE-2023-29723
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

The Glitter Unicorn Wallpaper app for Android 7.0 thru 8.0 allows unauthorized applications to actively request permission to insert data into the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the application is opened. By injecting data, the attacker can force the application to load malicious image URLs and display them in the UI. As the amount of data increases, it will eventually cause the application to trigger an OOM error and crash, resulting in a persistent denial of service attack.

CVE-2023-26105
utilities General
7.5
HIGH
EPSS
0.2%
2023 CWE-1321 1 PoC

All versions of the package utilities are vulnerable to Prototype Pollution via the _mix function.

CVE-2023-36643
Software Genérico General
7.5
HIGH
EPSS
0.9%
2023 1 PoC

Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all orders from the online shop via oordershow component in customer function.

CVE-2023-26139
underscore-keypath General
7.5
HIGH
EPSS
0.1%
2023 CWE-1321 1 PoC

Versions of the package underscore-keypath from 0.0.11 are vulnerable to Prototype Pollution via the name argument of the setProperty() function. Exploiting this vulnerability is possible due to improper input sanitization which allows the usage of arguments like “__proto__”.

CVE-2023-47117
label-studio General ⚡ nuclei
7.5
HIGH
EPSS
65.8%
2023 CWE-200 0 PoCs

Label Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token

CVE-2023-31300
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via transmission of unencrypted, cleartext credentials during Password Reset feature.

CVE-2023-49356
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

A stack buffer overflow vulnerability in MP3Gain v1.6.2 allows an attacker to cause a denial of service via the WriteMP3GainAPETag function at apetag.c:592.

CVE-2023-47108
opentelemetry-go-contrib General
7.5
HIGH
EPSS
4.3%
2023 CWE-770 1 PoC

OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. Starting in version 0.37.0 and prior to version 0.46.0, the grpc Unary Server Interceptor out of the box adds labels `net.peer.sock.addr` and `net.peer.sock.port` that have unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests are sent. An attacker can easily flood the peer address and port for requests. Version 0.46.0 contains a fix for this issue. As a workaround to stop being affected, a view removing the attributes can be used. The other possibility is to

CVE-2023-28450
Software Genérico General
7.5
HIGH
EPSS
0.0%
2023 1 PoC

An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2020.

CVE-2023-1105
flatpressblog/flatpress General
7.5
HIGH
EPSS
0.3%
2023 CWE-73 1 PoC

External Control of File Name or Path in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2023-45233
edk2 General
7.5
HIGH
EPSS
0.5%
2023 CWE-835 1 PoC

EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.

CVE-2023-25283
Software Genérico General
7.5
HIGH
EPSS
0.8%
2023 1 PoC

A stack overflow vulnerability in D-Link DIR820LA1_FW106B02 allows attackers to cause a denial of service via the reserveDHCP_HostName_1.1.1.0 parameter to lan.asp.