3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-43769
Software Genérico General
6.3
MEDIUM
EPSS
0.1%
2023 2 PoCs

An issue was discovered in Couchbase Server through 7.1.4 before 7.1.5 and before 7.2.1. There are Unauthenticated RMI Service Ports Exposed in Analytics.

CVE-2023-2946
openemr/openemr General
6.3
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.

CVE-2023-3568
alextselegidis/easyappointments General
6.3
MEDIUM
EPSS
0.1%
2023 CWE-601 1 PoC

Open Redirect in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

CVE-2023-37010
Software Genérico General
6.3
MEDIUM
EPSS
0.2%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `eNB Status Transfer` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

CVE-2023-3836
Smart Park Management General ⚡ nuclei
6.3
MEDIUM
EPSS
91.4%
2023 CWE-434 2 PoCs

A vulnerability classified as critical was found in Dahua Smart Park Management up to 20230713. This vulnerability affects unknown code of the file /emap/devicePoint_addImgIco?hasSubsystem=true. The manipulation of the argument upload leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235162 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-42534
Samsung Mobile Devices General
6.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper input validation vulnerability in ChooserActivity prior to SMR Nov-2023 Release 1 allows local attackers to read arbitrary files with system privilege.

CVE-2023-38060
OTRS General
6.3
MEDIUM
EPSS
0.2%
2023 CWE-20 1 PoC

Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate operations of the OTRS Generic Interface modules allows any authenticated attacker to to perform an host header injection for the ContentType header of the attachment.  This issue affects OTRS: from 7.0.X before 7.0.45, from 8.0.X before 8.0.35; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.

CVE-2023-37011
Software Genérico General
6.3
MEDIUM
EPSS
0.2%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Required` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

CVE-2023-3574
pimcore/customer-data-framework General
6.3
MEDIUM
EPSS
0.0%
2023 CWE-285 1 PoC

Improper Authorization in GitHub repository pimcore/customer-data-framework prior to 3.4.1.

CVE-2023-0649
dst-admin General
6.3
MEDIUM
EPSS
6.3%
2023 CWE-77 1 PoC

A vulnerability has been found in dst-admin 1.5.0 and classified as critical. This vulnerability affects unknown code of the file /home/sendBroadcast. The manipulation of the argument message leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220036.

CVE-2023-29113
Volkswagen MIB3 infotainment system MIB3 OI MQB General
6.3
MEDIUM
EPSS
0.1%
2023 CWE-284 2 PoCs

The MIB3 infotainment unit used in Skoda and Volkswagen vehicles does not incorporate any privilege separation for the proprietary inter-process communication mechanism, leaving attackers with presence in the system an ability to undermine access control restrictions implemented at the operating system level. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources.

CVE-2023-37215
soundbar multibeam General
6.2
MEDIUM
EPSS
0.1%
2023 CWE-798 1 PoC

JBL soundbar multibeam 5.1 - CWE-798: Use of Hard-coded Credentials

CVE-2023-30661
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2023 1 PoC

Exposure of Sensitive Information vulnerability in getChipInfos in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.

CVE-2023-46048
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2023 1 PoC

Tex Live 944e257 has a NULL pointer dereference in texk/web2c/pdftexdir/writet1.c. NOTE: this is disputed because it should be categorized as a usability problem.

CVE-2023-21458
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2023 CWE-269 1 PoC

Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent.

CVE-2023-30657
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in EnhancedAttestationResult prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

CVE-2023-5441
vim/vim General
6.2
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository vim/vim prior to 20d161ace307e28690229b68584f2d84556f8960.

CVE-2023-42543
Bixby Voice General
6.2
MEDIUM
EPSS
0.3%
2023 1 PoC

Improper verification of intent by broadcast receiver vulnerability in Bixby Voice prior to version 3.3.35.12 allows attackers to access arbitrary data with Bixby Voice privilege.

CVE-2023-21440
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2023 CWE-285 1 PoC

Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a screen capture.

CVE-2023-2788
Mattermost General
6.2
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while the attacker's account is deactivated.