3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-24528
Fiori apps 1.0 for travel management in SAP ERP (My Travel Requests) General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests) - version 600, allows an authenticated attacker to exploit a certain misconfigured application endpoint to view sensitive data. This endpoint is normally exposed over the network and successful exploitation can lead to exposure of data like travel documents.

CVE-2023-51955
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.

CVE-2023-33477
Software Genérico General
6.5
MEDIUM
EPSS
1.0%
2023 1 PoC

In Harmonic NSG 9000-6G devices, an authenticated remote user can obtain source code by directly requesting a special path.

CVE-2023-0667
Wireshark General
6.5
MEDIUM
EPSS
0.3%
2023 CWE-122 2 PoCs

Due to failure in validating the length provided by an attacker-crafted MSMMS packet, Wireshark version 4.0.5 and prior, in an unusual configuration, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark

CVE-2023-50915
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2023 2 PoCs

An issue exists in GalaxyClientService.exe in GOG Galaxy (Beta) 2.0.67.2 through 2.0.71.2 that could allow authenticated users to overwrite and corrupt critical system files via a combination of an NTFS Junction and an RPC Object Manager symbolic link and could result in a denial of service.

CVE-2023-24125
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey2_5g parameter at /goform/WifiBasicSet.

CVE-2023-0661
Devolutions Server General
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data.

CVE-2023-35636
Microsoft Office 2019 General
6.5
MEDIUM
EPSS
10.5%
2023 CWE-200 1 PoC

Microsoft Outlook Information Disclosure Vulnerability

CVE-2023-51775
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

CVE-2023-24126
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey4_5g parameter at /goform/WifiBasicSet.

CVE-2023-5195
Mattermost General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-863 1 PoC

Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of

CVE-2023-49339
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2023 1 PoC

Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/ssb/studentCard/retrieveData endpoint.

CVE-2023-20525
2nd Gen EPYC General
6.5
MEDIUM
EPSS
0.3%
2023 1 PoC

Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the bounds of a mapped register potentially leading to a denial of service.

CVE-2023-41705
OX App Suite General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-400 1 PoC

Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of DAV user-agents now gets monitored, and the related request is terminated if a resource threshold is reached. No publicly available exploits are known.

CVE-2023-34317
OAS Platform General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-20 1 PoC

An improper input validation vulnerability exists in the OAS Engine User Creation functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to unexpected data in the configuration. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-7004
TTLock App General
6.5
MEDIUM
EPSS
0.0%
2023 1 PoC

The TTLock App does not employ proper verification procedures to ensure that it is communicating with the expected device, allowing for connection to a device that spoofs the MAC address of a lock, which compromises the legitimate locks integrity.

CVE-2023-24626
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process.

CVE-2023-23547
UR32L General
6.5
MEDIUM
EPSS
0.4%
2023 CWE-22 1 PoC

A directory traversal vulnerability exists in the luci2-io file-export mib functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbitrary file read. An attacker can send a network request to trigger this vulnerability.

CVE-2023-35016
Security Verify Governance, Identity Manager General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-22 1 PoC

IBM Security Verify Governance, Identity Manager 10.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 257772.

CVE-2023-29548
Firefox General
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.