3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-44833
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the GuardInt parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-22845
OpenImageIO General
7.5
HIGH
EPSS
0.2%
2023 CWE-125 1 PoC

An out-of-bounds read vulnerability exists in the TGAInput::decode_pixel() functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted targa file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-28598
Zoom for Linux clients General
7.5
HIGH
EPSS
0.4%
2023 CWE-79 1 PoC

Zoom for Linux clients prior to 5.13.10 contain an HTML injection vulnerability. If a victim starts a chat with a malicious user it could result in a Zoom application crash.

CVE-2023-4486
Metasys NAE55/SNE/SNC General
7.5
HIGH
EPSS
0.2%
2023 CWE-400 1 PoC

Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to versions 11.0.6 and 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service.

CVE-2023-29743
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database.

CVE-2023-42494
v3.0.6433.1964 General
7.5
HIGH
EPSS
0.2%
2023 CWE-749 1 PoC

EisBaer Scada - CWE-749: Exposed Dangerous Method or Function

CVE-2023-26071
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

An issue was discovered in MCUBO ICT through 10.12.4 (aka 6.0.2). An Observable Response Discrepancy can occur under the login web page. In particular, the web application provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor. That allow an unauthorized actor to perform User Enumeration attacks.

CVE-2023-24506
NCR/Camera General
7.5
HIGH
EPSS
0.3%
2023 CWE-522 1 PoC

Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request.

CVE-2023-27532
🔥 KEV Veeam Backup & Replication General
7.5
HIGH
EPSS
82.3%
2023 CWE-306 3 PoCs

Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.

CVE-2023-25289
Software Genérico General
7.5
HIGH
EPSS
13.3%
2023 1 PoC

Directory Traversal vulnerability in virtualreception Digital Receptie version win7sp1_rtm.101119-1850 6.1.7601.1.0.65792 in embedded web server, allows attacker to gain sensitive information via a crafted GET request.

CVE-2023-5245
Software Genérico General
7.5
HIGH
EPSS
0.4%
2023 CWE-22 1 PoC

FileUtil.extract() enumerates all zip file entries and extracts each file without validating whether file paths in the archive are outside the intended directory. When creating an instance of TensorflowModel using the saved_model format and an exported tensorflow model, the apply() function invokes the vulnerable implementation of FileUtil.extract(). Arbitrary file creation can directly lead to code execution

CVE-2023-34407
Software Genérico General
7.5
HIGH
EPSS
0.7%
2023 1 PoC

OfflinePlayerService.exe in Harbinger Offline Player 4.0.6.0.2 allows directory traversal as LocalSystem via ..\ in a URL.

CVE-2023-44835
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Mac parameter in the SetParentsControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-33510
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
71.5%
2023 1 PoC

Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters.

CVE-2023-39611
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 2 PoCs

An issue in Software FX Chart FX 7 version 7.0.4962.20829 allows attackers to enumerate and read files from the local filesystem by sending crafted web requests.

CVE-2023-23131
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

Selfwealth iOS mobile App 3.3.1 is vulnerable to Insecure App Transport Security (ATS) Settings.

CVE-2023-27191
Software Genérico General
7.5
HIGH
EPSS
0.4%
2023 2 PoCs

An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the SharedPreference files.

CVE-2023-40297
Software Genérico General
7.5
HIGH
EPSS
3.1%
2023 1 PoC

Stakater Forecastle 1.0.139 and before allows %5C../ directory traversal in the website component.

CVE-2023-34614
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

An issue was discovered jmarsden/jsonij thru 0.5.2 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.

CVE-2023-26459
NetWeaver AS for ABAP and ABAP Platform General
7.4
HIGH
EPSS
0.2%
2023 CWE-918 1 PoC

Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, an attacker authenticated as a non-administrative user can craft a request which will trigger the application server to send a request to an arbitrary URL which can reveal, modify or make unavailable non-sensitive information, leading to low impact on Confidentiality, Integrity and Availability.