5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-30056
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

A session takeover vulnerability exists in FICO Origination Manager Decision Module 4.8.1 due to insufficient protection of the JSESSIONID cookie.

CVE-2023-21857
HCM Common Architecture Web Database
7.5
HIGH
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Auomated Test Suite). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HCM Common Architecture. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HCM Common Architecture accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/

CVE-2023-21912
MySQL Server Database
7.5
HIGH
EPSS
0.2%
2023 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 5.7.41 and prior and 8.0.30 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVE-2023-25265
Software Genérico General
7.5
HIGH
EPSS
0.7%
2023 1 PoC

Docmosis Tornado <= 2.9.4 is vulnerable to Directory Traversal leading to the disclosure of arbitrary content on the file system.

CVE-2023-1605
radareorg/radare2 General
7.5
HIGH
EPSS
0.3%
2023 CWE-400 1 PoC

Denial of Service in GitHub repository radareorg/radare2 prior to 5.8.6.

CVE-2023-39167
Storage Box V1 General
7.5
HIGH
EPSS
0.4%
2023 CWE-862 2 PoCs

In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices' logfiles that contain sensitive data.

CVE-2023-30061
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2023 1 PoC

D-Link DIR-879 v105A1 is vulnerable to Authentication Bypass via phpcgi.

CVE-2023-4316
Zod General
7.5
HIGH
EPSS
0.1%
2023 CWE-1333 1 PoC

Zod in versions 3.21.0 up to and including 3.22.3 allows an attacker to perform a denial of service while validating emails.

CVE-2023-49355
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

decToString in decNumber/decNumber.c in jq 88f01a7 has a one-byte out-of-bounds write via the " []-1.2e-1111111111" input. NOTE: this is not the same as CVE-2023-50246. The CVE-2023-50246 71c2ab5 reference mentions -10E-1000010001, which is not in normalized scientific notation.

CVE-2023-30285
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 2 PoCs

An issue in Deviniti Issue Sync Synchronization v3.5.2 for Jira allows attackers to obtain the login credentials of a user via a crafted request sent to /rest/synchronizer/1.0/technicalUser.

CVE-2023-1874
WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards Web Windows
7.5
HIGH
EPSS
5.5%
2023 CWE-266 2 PoCs

The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.3.7. This is due to a lack of authorization checks on the multiple_roles_update function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wpda_role[]' parameter during a profile update. This requires the 'Enable role management' setting to be enabled for the site.

CVE-2023-23040
Software Genérico Networking
7.5
HIGH
EPSS
0.2%
2023 1 PoC

TP-Link router TL-WR940N V6 3.19.1 Build 180119 uses a deprecated MD5 algorithm to hash the admin password used for basic authentication.

CVE-2023-45131
discourse General
7.5
HIGH
EPSS
7.4%
2023 CWE-200 1 PoC

Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticated POST request to MessageBus. This issue is patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2023-30861
flask General
7.5
HIGH
EPSS
0.2%
2023 CWE-539 2 PoCs

Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one client may be cached and subsequently sent by the proxy to other clients. If the proxy also caches `Set-Cookie` headers, it may send one client's `session` cookie to other clients. The severity depends on the application's use of the session and the proxy's behavior regarding cookies. The risk depends on all these conditions being met. 1. The application must be hosted behind a caching proxy that does not strip cookies or ignore responses with cookie

CVE-2023-2968
Software Genérico Web
7.5
HIGH
EPSS
0.6%
2023 CWE-232 1 PoC

A remote attacker can trigger a denial of service in the socket.remoteAddress variable, by sending a crafted HTTP request. Usage of the undefined variable raises a TypeError exception.

CVE-2023-5922
Royal Elementor Addons and Templates Web Windows
7.5
HIGH
EPSS
1.1%
2023 1 PoC

The Royal Elementor Addons and Templates WordPress plugin before 1.3.81 does not ensure that users accessing posts via an AJAX action (and REST endpoint, currently disabled in the plugin) have the right to do so, allowing unauthenticated users to access arbitrary draft, private and password protected posts/pages content

CVE-2023-39539
AptioV General
7.5
HIGH
EPSS
0.3%
2023 CWE-20 1 PoC

AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability. 

CVE-2023-25260
Software Genérico General
7.5
HIGH
EPSS
0.9%
2023 2 PoCs

Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.

CVE-2023-21931
WebLogic Server Database
7.5
HIGH
EPSS
83.8%
2023 4 PoCs

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).