3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-35873
SAP NetWeaver Process Integration (Runtime Workbench) General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-306 1 PoC

The Runtime Workbench (RWB) of SAP NetWeaver Process Integration - version SAP_XITOOL 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might access technical data about the product status and its configuration. The vulnerability does not allow access to sensitive information or administrative functionalities. On successful exploitation an attacker can cause limited impact on confidentiality and availability of the application.

CVE-2023-32219
Mazda (2015-2016) General
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

A Mazda model (2015-2016) can be unlocked via an unspecified method.

CVE-2023-24121
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet.

CVE-2023-32271
OAS Platform General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-200 1 PoC

An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to a disclosure of sensitive information. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-1603
Server General
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior versions allows users with restricted rights to bypass entry permission via id collision.

CVE-2023-4560
omeka/omeka-s General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-612 1 PoC

Improper Authorization of Index Containing Sensitive Information in GitHub repository omeka/omeka-s prior to 4.0.4.

CVE-2023-0661
Devolutions Server General
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data.

CVE-2023-23296
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2023 1 PoC

Korenix JetWave 4200 Series 1.3.0 and JetWave 3200 Series 1.6.0 are vulnerable to Denial of Service via /goform/formDefault.

CVE-2023-24122
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the ssid_5g parameter at /goform/WifiBasicSet.

CVE-2023-24524
S/4 HANA (Map Treasury Correspondence Format Data) General
6.5
MEDIUM
EPSS
0.3%
2023 CWE-862 1 PoC

SAP S/4 HANA Map Treasury Correspondence Format Data does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to delete the data with a high impact to availability.

CVE-2023-50129
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2023 1 PoC

Missing encryption in the NFC tags of the Flient Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original tags, which results in an attacker gaining access to the perimeter.

CVE-2023-5840
linkstackorg/linkstack General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-640 1 PoC

Weak Password Recovery Mechanism for Forgotten Password in GitHub repository linkstackorg/linkstack prior to v4.2.9.

CVE-2023-24626
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process.

CVE-2023-0666
Wireshark General
6.5
MEDIUM
EPSS
2.5%
2023 CWE-122 2 PoCs

Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.

CVE-2023-36806
contao General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Contao is an open source content management system. Starting in version 4.0.0 and prior to versions 4.9.42, 4.13.28, and 5.1.10, it is possible for untrusted backend users to inject malicious code into headline fields in the back end, which will be executed both in the element preview (back end) and on the website (front end). Installations are only affected if there are untrusted back end users who have the rights to modify headline fields, or other fields using the input unit widget. Contao 4.9.42, 4.13.28, and 5.1.10 have a patch for this issue. As a workaround, disable the login for all un

CVE-2023-31179
NX General
6.5
MEDIUM
EPSS
0.4%
2023 CWE-22 1 PoC

AgilePoint NX v8.0 SU2.2 & SU2.3 - Path traversal - Vulnerability allows path traversal and downloading files from the server, by an unspecified request.

CVE-2023-25728
Firefox General
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

The <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a child iframe's unredacted URI when interaction with that iframe triggers a redirect. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVE-2023-0609
wallabag/wallabag General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-285 1 PoC

Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.

CVE-2023-28911
Volkswagen MIB3 infotainment system MIB3 OI MQB General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-20 2 PoCs

A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper validation of user-supplied data, which can result in an arbitrary channel disconnection. An attacker can leverage this vulnerability to cause a denial-of-service attack for every connected client of the infotainment device. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources.

CVE-2023-20575
1st Gen AMD EPYC™ Processors General
6.5
MEDIUM
EPSS
0.5%
2023 1 PoC

A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information.