3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-38039
curl Web
7.5
HIGH
EPSS
12.3%
2023 1 PoC

When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory.

CVE-2023-26031
Apache Hadoop DevOps Web
7.5
HIGH
EPSS
9.3%
2023 CWE-426 3 PoCs

Relative library resolution in linux container-executor binary in Apache Hadoop 3.3.1-3.3.4 on Linux allows local user to gain root privileges. If the YARN cluster is accepting work from remote (authenticated) users, this MAY permit remote users to gain root privileges. Hadoop 3.3.0 updated the " YARN Secure Containers https://hadoop.apache.org/docs/stable/hadoop-yarn/hadoop-yarn-site/SecureContainer.html " to add a feature for executing user-submitted applications in isolated linux containers. The native binary HADOOP_HOME/bin/container-executor is used to launch these containers; it must b

CVE-2023-25171
kiwi Web
7.5
HIGH
EPSS
0.8%
2023 CWE-770 1 PoC

Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt denial-of-service attacks against the Password reset page. An attacker could potentially send a large number of emails if they know the email addresses of users in Kiwi TCMS. Additionally that may strain SMTP resources. Users should upgrade to v12.0 or later to receive a patch. As potential workarounds, users may install and configure a rate-limiting proxy in front of Kiwi TCMS and/or configure rate limits on their email server when possible.

CVE-2023-1874
WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards Web Windows
7.5
HIGH
EPSS
5.5%
2023 CWE-266 2 PoCs

The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.3.7. This is due to a lack of authorization checks on the multiple_roles_update function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wpda_role[]' parameter during a profile update. This requires the 'Enable role management' setting to be enabled for the site.

CVE-2023-31594
Software Genérico Web
7.5
HIGH
EPSS
0.4%
2023 1 PoC

IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via an exposed HTTP channel using VLC network.

CVE-2023-4703
All in One B2B for WooCommerce Web Windows
7.5
HIGH
EPSS
0.3%
2023 1 PoC

The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating user details, allowing an unauthenticated attacker to update the details of any user. Updating the password of an Admin user leads to privilege escalation.

CVE-2023-1405
Formidable Forms Web Windows
7.5
HIGH
EPSS
0.3%
2023 2 PoCs

The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.

CVE-2023-23590
Software Genérico Web
7.5
HIGH
EPSS
1.0%
2023 1 PoC

Mercedes-Benz XENTRY Retail Data Storage 7.8.1 allows remote attackers to cause a denial of service (device restart) via an unauthenticated API request. The attacker must be on the same network as the device.

CVE-2023-6271
Backup Migration Web Windows
7.5
HIGH
EPSS
0.3%
2023 2 PoCs

The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to leak sensitive information from the site's backups.

CVE-2023-5454
Templately Web Windows
7.5
HIGH
EPSS
0.8%
2023 1 PoC

The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, allowing unauthenticated users to delete arbitrary posts.

CVE-2023-39375
SiberianCMS Web
7.5
HIGH
EPSS
0.1%
2023 CWE-274 1 PoC

SiberianCMS - CWE-274: Improper Handling of Insufficient Privileges

CVE-2023-52355
Software Genérico Web
7.5
HIGH
EPSS
1.3%
2023 CWE-787 1 PoC

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

CVE-2023-6294
Popup Builder Web Windows
7.5
HIGH
EPSS
0.3%
2023 1 PoC

The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the administrator role to perform SSRF attack in Multisite WordPress configurations.

CVE-2023-32077
netmaker DevOps Web ⚡ nuclei
7.5
HIGH
EPSS
86.6%
2023 CWE-321 0 PoCs

Netmaker makes networks with WireGuard. Prior to versions 0.17.1 and 0.18.6, hardcoded DNS key usage has been found in Netmaker allowing unauth users to interact with DNS API endpoints. The issue is patched in 0.17.1 and fixed in 0.18.6. If users are using 0.17.1, they should run `docker pull gravitl/netmaker:v0.17.1` and `docker-compose up -d`. This will switch them to the patched users. If users are using v0.18.0-0.18.5, they should upgrade to v0.18.6 or later. As a workaround, someone who is using version 0.17.1 can pull the latest docker image of the backend and restart the server.

CVE-2023-46380
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2023 1 PoC

LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) send password-change requests via cleartext HTTP.

CVE-2023-22047
PeopleSoft Enterprise PT PeopleTools Web Database ⚡ nuclei
7.5
HIGH
EPSS
91.6%
2023 2 PoCs

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2023-7165
JetBackup Web Windows ⚡ nuclei
7.5
HIGH
EPSS
31.6%
2023 1 PoC

The JetBackup WordPress plugin before 2.0.9.9 doesn't use index files to prevent public directory listing of sensitive directories in certain configurations, which allows malicious actors to leak backup files.

CVE-2023-21515
Galaxy Store Web
7.5
HIGH
EPSS
0.2%
2023 CWE-20 1 PoC

InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.

CVE-2023-21851
Marketing Web Database
7.5
HIGH
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Marketing accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).

CVE-2023-21516
Galaxy Store Web
7.5
HIGH
EPSS
0.5%
2023 CWE-20 1 PoC

XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.