3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-1603
Server General
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior versions allows users with restricted rights to bypass entry permission via id collision.

CVE-2023-33140
Microsoft OneNote for Universal General
6.5
MEDIUM
EPSS
5.5%
2023 2 PoCs

Microsoft OneNote Spoofing Vulnerability

CVE-2023-47459
Software Genérico General
6.5
MEDIUM
EPSS
0.8%
2023 1 PoC

An issue in Knovos Discovery v.22.67.0 allows a remote attacker to obtain sensitive information via the /DiscoveryReview/Service/CaseManagement.svc/GetProductSiteName component.

CVE-2023-5196
Mattermost General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-400 1 PoC

Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_prop resulting in the server consuming an abnormal quantity of computing resources and possibly becoming temporarily unavailable for its users.

CVE-2023-39208
Zoom Desktop Client for Linux General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Improper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allow an unauthenticated user to conduct a denial of service via network access.

CVE-2023-27035
Software Genérico General
6.5
MEDIUM
EPSS
26.3%
2023 3 PoCs

An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page.

CVE-2023-4190
admidio/admidio General
6.5
MEDIUM
EPSS
0.5%
2023 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.2.11.

CVE-2023-40745
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2023 CWE-190 1 PoC

LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.

CVE-2023-51955
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.

CVE-2023-24119
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the ssid parameter at /goform/WifiBasicSet.

CVE-2023-5462
XD5E-30R-E General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-404 2 PoCs

A vulnerability was found in XINJE XD5E-30R-E 3.5.3b. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Modbus Handler. The manipulation leads to denial of service. The exploit has been disclosed to the public and may be used. The identifier VDB-241585 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-43040
Spectrum Fusion HCI General
6.5
MEDIUM
EPSS
5.7%
2023 CWE-1220 1 PoC

IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM X-Force ID: 266807.

CVE-2023-5571
vriteio/vrite General
6.5
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

Improper Input Validation in GitHub repository vriteio/vrite prior to 0.3.0.

CVE-2023-24528
Fiori apps 1.0 for travel management in SAP ERP (My Travel Requests) General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests) - version 600, allows an authenticated attacker to exploit a certain misconfigured application endpoint to view sensitive data. This endpoint is normally exposed over the network and successful exploitation can lead to exposure of data like travel documents.

CVE-2023-32271
OAS Platform General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-200 1 PoC

An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to a disclosure of sensitive information. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-0666
Wireshark General
6.5
MEDIUM
EPSS
2.5%
2023 CWE-122 2 PoCs

Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.

CVE-2023-24126
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey4_5g parameter at /goform/WifiBasicSet.

CVE-2023-33477
Software Genérico General
6.5
MEDIUM
EPSS
1.0%
2023 1 PoC

In Harmonic NSG 9000-6G devices, an authenticated remote user can obtain source code by directly requesting a special path.

CVE-2023-4640
Anywhere General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

The controller responsible for setting the logging level does not include any authorization checks to ensure the user is authenticated. This can be seen by noting that it extends Controller rather than AuthenticatedController and includes no further checks. This issue affects YugabyteDB Anywhere: from 2.0.0 through 2.17.3

CVE-2023-0667
Wireshark General
6.5
MEDIUM
EPSS
0.3%
2023 CWE-122 2 PoCs

Due to failure in validating the length provided by an attacker-crafted MSMMS packet, Wireshark version 4.0.5 and prior, in an unusual configuration, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark