3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-5222
Vitogate 300 General ⚡ nuclei
6.3
MEDIUM
EPSS
90.2%
2023 CWE-259 0 PoCs

A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0. This vulnerability affects the function isValidUser of the file /cgi-bin/vitogate.cgi of the component Web Management Interface. The manipulation leads to use of hard-coded password. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240364. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-5796
POS System General
6.3
MEDIUM
EPSS
0.1%
2023 CWE-434 1 PoC

A vulnerability was found in CodeAstro POS System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /setting of the component Logo Handler. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-243602 is the identifier assigned to this vulnerability.

CVE-2023-42483
Software Genérico General
6.3
MEDIUM
EPSS
0.0%
2023 1 PoC

A TOCTOU race condition in Samsung Mobile Processor Exynos 9820, Exynos 980, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, and Exynos 1380 can cause unexpected termination of a system.

CVE-2023-2980
Pydio Cells General
6.3
MEDIUM
EPSS
0.1%
2023 CWE-99 1 PoC

A vulnerability classified as critical was found in Abstrium Pydio Cells 4.2.0. This vulnerability affects unknown code of the component User Creation Handler. The manipulation leads to improper control of resource identifiers. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-230212.

CVE-2023-0648
dst-admin General
6.3
MEDIUM
EPSS
6.3%
2023 CWE-77 1 PoC

A vulnerability, which was classified as critical, was found in dst-admin 1.5.0. This affects an unknown part of the file /home/masterConsole. The manipulation of the argument command leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-220035.

CVE-2023-2160
modoboa/modoboa General
6.3
MEDIUM
EPSS
0.3%
2023 CWE-521 1 PoC

Weak Password Requirements in GitHub repository modoboa/modoboa prior to 2.1.0.

CVE-2023-2950
openemr/openemr General
6.3
MEDIUM
EPSS
0.5%
2023 CWE-285 1 PoC

Improper Authorization in GitHub repository openemr/openemr prior to 7.0.1.

CVE-2023-3759
SGS General
6.3
MEDIUM
EPSS
0.1%
2023 CWE-275 1 PoC

A vulnerability, which was classified as critical, was found in Intergard SGS 8.7.0. Affected is an unknown function. The manipulation leads to permission issues. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-234444. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-30671
Samsung Mobile Devices General
6.3
MEDIUM
EPSS
0.0%
2023 1 PoC

Logic error in package installation via adb command prior to SMR Jul-2023 Release 1 allows local attackers to downgrade installed application.

CVE-2023-5795
POS System General
6.3
MEDIUM
EPSS
0.1%
2023 CWE-434 1 PoC

A vulnerability was found in CodeAstro POS System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /profil of the component Profile Picture Handler. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243601 was assigned to this vulnerability.

CVE-2023-37009
Software Genérico General
6.3
MEDIUM
EPSS
0.2%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Notification` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

CVE-2023-6888
RtspServer General
6.3
MEDIUM
EPSS
0.2%
2023 CWE-121 2 PoCs

A vulnerability classified as critical was found in PHZ76 RtspServer 1.0.0. This vulnerability affects the function ParseRequestLine of the file RtspMesaage.cpp. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-248248. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-4411
EX1200L General
6.3
MEDIUM
EPSS
1.1%
2023 CWE-78 1 PoC

A vulnerability has been found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-237514 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-2946
openemr/openemr General
6.3
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.

CVE-2023-4409
NBS&HappySoftWeChat General
6.3
MEDIUM
EPSS
0.1%
2023 CWE-434 1 PoC

A vulnerability, which was classified as critical, has been found in NBS&HappySoftWeChat 1.1.6. Affected by this issue is some unknown functionality. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-237512.

CVE-2023-4106
Mattermost General
6.3
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

Mattermost fails to check if the requesting user is a guest before performing different actions to public playbooks, resulting a guest being able to view, join, edit, export and archive public playbooks.

CVE-2023-2984
pimcore/pimcore General
6.3
MEDIUM
EPSS
0.0%
2023 CWE-29 1 PoC

Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22.

CVE-2023-43769
Software Genérico General
6.3
MEDIUM
EPSS
0.1%
2023 2 PoCs

An issue was discovered in Couchbase Server through 7.1.4 before 7.1.5 and before 7.2.1. There are Unauthenticated RMI Service Ports Exposed in Analytics.

CVE-2023-3018
Lost and Found Information System General
6.3
MEDIUM
EPSS
0.1%
2023 CWE-284 2 PoCs

A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/?page=user/list. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-230362 is the identifier assigned to this vulnerability.

CVE-2023-3568
alextselegidis/easyappointments General
6.3
MEDIUM
EPSS
0.1%
2023 CWE-601 1 PoC

Open Redirect in GitHub repository alextselegidis/easyappointments prior to 1.5.0.