3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-35872
SAP NetWeaver Process Integration (Message Display Tool) General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-306 1 PoC

The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might access technical data about the product status and its configuration. The vulnerability does not allow access to sensitive information or administrative functionalities. On successful exploitation an attacker can cause limited impact on confidentiality and availability of the application.

CVE-2023-3981
omeka/omeka-s General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository omeka/omeka-s prior to 4.0.2.

CVE-2023-28763
NetWeaver AS for ABAP and ABAP Platform General
6.5
MEDIUM
EPSS
0.5%
2023 CWE-400 1 PoC

SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker authenticated as a non-administrative user to craft a request with certain parameters which can consume the server's resources sufficiently to make it unavailable over the network without any user interaction.

CVE-2023-50126
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2023 1 PoC

Missing encryption in the RFID tags of the Hozard alarm system (Alarmsysteem) v1.0 allow attackers to create a cloned tag via brief physical proximity to one of the original tags, which results in an attacker being able to bring the alarm system to a disarmed state.

CVE-2023-47993
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

A Buffer out-of-bound read vulnerability in Exif.cpp::ReadInt32 in FreeImage 3.18.0 allows attackers to cause a denial-of-service.

CVE-2023-45229
edk2 General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-125 1 PoC

EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.

CVE-2023-26987
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2023 2 PoCs

An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST request.

CVE-2023-0668
Wireshark General
6.5
MEDIUM
EPSS
1.9%
2023 CWE-125 2 PoCs

Due to failure in validating the length provided by an attacker-crafted IEEE-C37.118 packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.

CVE-2023-30948
com.palantir.comments:comments General
6.5
MEDIUM
EPSS
0.3%
2023 CWE-285 1 PoC

A security defect in Foundry's Comments functionality resulted in the retrieval of attachments to comments not being gated by additional authorization checks. This could enable an authenticated user to inject a prior discovered attachment UUID into other arbitrary comments to discover it's content. This defect was fixed in Foundry Comments 2.249.0, and a patch was rolled out to affected Foundry environments. No further intervention is required at this time.

CVE-2023-41706
OX App Suite General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-400 1 PoC

Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing of user-defined drive search expressions is not limited No publicly available exploits are known.

CVE-2023-3172
froxlor/froxlor General
6.5
MEDIUM
EPSS
0.3%
2023 CWE-22 1 PoC

Path Traversal in GitHub repository froxlor/froxlor prior to 2.0.20.

CVE-2023-4969
OpenCL General
6.5
MEDIUM
EPSS
2.1%
2023 3 PoCs

A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures.

CVE-2023-31187
IX Workforce Engagement General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-522 1 PoC

Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials

CVE-2023-24045
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2023 1 PoC

In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request.

CVE-2023-4190
admidio/admidio General
6.5
MEDIUM
EPSS
0.5%
2023 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.2.11.

CVE-2023-6533
PC Controller General
6.5
MEDIUM
EPSS
0.0%
2023 CWE-248 1 PoC

Malformed Device Reset Locally Command Class packets can be sent to the controller, causing the controller to assume the end device has left the network. After this, frames sent by the end device will not be acknowledged by the controller. This vulnerability exists in PC Controller v5.54.0, and earlier.

CVE-2023-0666
Wireshark General
6.5
MEDIUM
EPSS
2.5%
2023 CWE-122 2 PoCs

Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.

CVE-2023-0661
Devolutions Server General
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data.

CVE-2023-5214
Bolt General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-269 1 PoC

In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.

CVE-2023-23547
UR32L General
6.5
MEDIUM
EPSS
0.4%
2023 CWE-22 1 PoC

A directory traversal vulnerability exists in the luci2-io file-export mib functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbitrary file read. An attacker can send a network request to trigger this vulnerability.