3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-1980
Remote Desktop Manager General
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

Two factor authentication bypass on login in Devolutions Remote Desktop Manager 2022.3.35 and earlier allow user to cancel the two factor authentication via the application user interface and open entries.

CVE-2023-25741
Firefox General
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused web compatibility problems as well as this security concern, so the behavior was disabled until further review. This vulnerability affects Firefox < 110.

CVE-2023-4640
Anywhere General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

The controller responsible for setting the logging level does not include any authorization checks to ensure the user is authenticated. This can be seen by noting that it extends Controller rather than AuthenticatedController and includes no further checks. This issue affects YugabyteDB Anywhere: from 2.0.0 through 2.17.3

CVE-2023-5840
linkstackorg/linkstack General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-640 1 PoC

Weak Password Recovery Mechanism for Forgotten Password in GitHub repository linkstackorg/linkstack prior to v4.2.9.

CVE-2023-3981
omeka/omeka-s General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository omeka/omeka-s prior to 4.0.2.

CVE-2023-30456
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2023 2 PoCs

An issue was discovered in arch/x86/kvm/vmx/nested.c in the Linux kernel before 6.2.8. nVMX on x86_64 lacks consistency checks for CR0 and CR4.

CVE-2023-45231
edk2 General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-125 1 PoC

EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing  Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.

CVE-2023-28763
NetWeaver AS for ABAP and ABAP Platform General
6.5
MEDIUM
EPSS
0.5%
2023 CWE-400 1 PoC

SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker authenticated as a non-administrative user to craft a request with certain parameters which can consume the server's resources sufficiently to make it unavailable over the network without any user interaction.

CVE-2023-24122
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the ssid_5g parameter at /goform/WifiBasicSet.

CVE-2023-35872
SAP NetWeaver Process Integration (Message Display Tool) General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-306 1 PoC

The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might access technical data about the product status and its configuration. The vulnerability does not allow access to sensitive information or administrative functionalities. On successful exploitation an attacker can cause limited impact on confidentiality and availability of the application.

CVE-2023-0666
Wireshark General
6.5
MEDIUM
EPSS
2.5%
2023 CWE-122 2 PoCs

Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.

CVE-2023-2983
pimcore/pimcore General
6.5
MEDIUM
EPSS
0.0%
2023 CWE-267 1 PoC

Privilege Defined With Unsafe Actions in GitHub repository pimcore/pimcore prior to 10.5.23.

CVE-2023-42578
Samsung Data Store General
6.5
MEDIUM
EPSS
0.3%
2023 1 PoC

Improper handling of insufficient permissions or privileges vulnerability in Samsung Data Store prior to version 5.2.00.7 allows remote attackers to access location information without permission.

CVE-2023-32271
OAS Platform General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-200 1 PoC

An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to a disclosure of sensitive information. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-1163
Vigor 2960 General
6.5
MEDIUM
EPSS
0.9%
2023 CWE-22 1 PoC

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5 and classified as critical. Affected by this vulnerability is the function getSyslogFile of the file mainfunction.cgi of the component Web Management Interface. The manipulation of the argument option leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-222259. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-0019
SAP GRC (Process Control) General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

In SAP GRC (Process Control) - versions GRCFND_A V1200, GRCFND_A V8100, GRCPINW V1100_700, GRCPINW V1100_731, GRCPINW V1200_750, remote-enabled function module in the proprietary SAP solution enables an authenticated attacker with minimal privileges to access all the confidential data stored in the database. Successful exploitation of this vulnerability can expose user credentials from client-specific tables of the database, leading to high impact on confidentiality.

CVE-2023-30948
com.palantir.comments:comments General
6.5
MEDIUM
EPSS
0.3%
2023 CWE-285 1 PoC

A security defect in Foundry's Comments functionality resulted in the retrieval of attachments to comments not being gated by additional authorization checks. This could enable an authenticated user to inject a prior discovered attachment UUID into other arbitrary comments to discover it's content. This defect was fixed in Foundry Comments 2.249.0, and a patch was rolled out to affected Foundry environments. No further intervention is required at this time.

CVE-2023-45229
edk2 General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-125 1 PoC

EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.

CVE-2023-23855
Solution Manager General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-601 1 PoC

SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insufficient URL validation. A successful attack could lead an attacker to read or modify the information or expose the user to a phishing attack. As a result, it has a low impact to confidentiality, integrity and availability.

CVE-2023-50126
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2023 1 PoC

Missing encryption in the RFID tags of the Hozard alarm system (Alarmsysteem) v1.0 allow attackers to create a cloned tag via brief physical proximity to one of the original tags, which results in an attacker being able to bring the alarm system to a disarmed state.