3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-3218
it-novum/openitcockpit General
6.5
MEDIUM
EPSS
0.0%
2023 CWE-366 1 PoC

Race Condition within a Thread in GitHub repository it-novum/openitcockpit prior to 4.6.5.

CVE-2023-45873
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 2 PoCs

An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (application exist) because of the OOM killer.

CVE-2023-34096
Thruk General
6.5
MEDIUM
EPSS
45.1%
2023 CWE-22 4 PoCs

Thruk is a multibackend monitoring webinterface which currently supports Naemon, Icinga, Shinken and Nagios as backends. In versions 3.06 and prior, the file `panorama.pm` is vulnerable to a Path Traversal vulnerability which allows an attacker to upload a file to any folder which has write permissions on the affected system. The parameter location is not filtered, validated or sanitized and it accepts any kind of characters. For a path traversal attack, the only characters required were the dot (`.`) and the slash (`/`). A fix is available in version 3.06.2.

CVE-2023-32615
OAS Platform General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-73 1 PoC

A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary file creation or overwrite. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-28180
macOS General
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

A denial-of-service issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. A user in a privileged network position may be able to cause a denial-of-service.

CVE-2023-6533
PC Controller General
6.5
MEDIUM
EPSS
0.0%
2023 CWE-248 1 PoC

Malformed Device Reset Locally Command Class packets can be sent to the controller, causing the controller to assume the end device has left the network. After this, frames sent by the end device will not be acknowledged by the controller. This vulnerability exists in PC Controller v5.54.0, and earlier.

CVE-2023-24117
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepauth_5g parameter at /goform/WifiBasicSet.

CVE-2023-4190
admidio/admidio General
6.5
MEDIUM
EPSS
0.5%
2023 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.2.11.

CVE-2023-24124
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wrlEn parameter at /goform/WifiBasicSet.

CVE-2023-6119
GetSusp General
6.5
MEDIUM
EPSS
0.0%
2023 CWE-269 1 PoC

An Improper Privilege Management vulnerability in Trellix GetSusp prior to version 5.0.0.27 allows a local, low privilege attacker to gain access to files that usually require a higher privilege level. This is caused by GetSusp not correctly protecting a directory that it creates during execution, allowing an attacker to take over file handles used by GetSusp. As this runs with high privileges, the attacker gains elevated permissions. The file handles are opened as read-only.

CVE-2023-0978
Trellix Intelligent Sandbox General
6.4
MEDIUM
EPSS
0.4%
2023 CWE-77 1 PoC

A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and execute arbitrary operating system commands using specially crafted strings. This vulnerability is due to insufficient validation of arguments that are passed to specific CLI command. The vulnerability allows the attack

CVE-2023-21483
Galaxy Store General
6.4
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper Access Control vulnerability in Galaxy Store prior to version 4.5.53.6 allows local attacker to access protected data using exported service.

CVE-2023-30772
Software Genérico General
6.4
MEDIUM
EPSS
0.1%
2023 2 PoCs

The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/power/supply/da9150-charger.c if a physically proximate attacker unplugs a device.

CVE-2023-33203
Software Genérico General
6.4
MEDIUM
EPSS
0.0%
2023 2 PoCs

The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/net/ethernet/qualcomm/emac/emac.c if a physically proximate attacker unplugs an emac based device.

CVE-2023-0748
btcpayserver/btcpayserver General
6.4
MEDIUM
EPSS
0.8%
2023 CWE-601 2 PoCs

Open Redirect in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.

CVE-2023-28153
Software Genérico General
6.4
MEDIUM
EPSS
0.1%
2023 1 PoC

An issue was discovered in the Kiddoware Kids Place Parental Control application before 3.8.50 for Android. The child can remove all restrictions temporarily without the parents noticing by rebooting into Android Safe Mode and disabling the "Display over other apps" permission.

CVE-2023-3711
PM23/43 General
6.4
MEDIUM
EPSS
0.1%
2023 CWE-384 2 PoCs

Session Fixation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Session Credential Falsification through Prediction.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).

CVE-2023-24517
Pandora FMS General
6.4
MEDIUM
EPSS
0.2%
2023 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in the Pandora FMS File Manager component, allows an attacker to make make use of this issue ( unrestricted file upload ) to execute arbitrary system commands. This issue affects Pandora FMS v767 version and prior versions on all platforms.

CVE-2023-2807
Pandora FMS General
6.4
MEDIUM
EPSS
0.1%
2023 CWE-290 1 PoC

Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication. This issue affects PandoraFMS v771 and prior versions on all platforms.

CVE-2023-2946
openemr/openemr General
6.3
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.