5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-4197
Dolibarr ERP CRM Web
7.5
HIGH
EPSS
51.1%
2023 CWE-20 2 PoCs

Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.

CVE-2023-38370
Security Access Manager Docker DevOps
7.5
HIGH
EPSS
0.0%
2023 CWE-276 2 PoCs

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages. IBM X-Force ID: 261197.

CVE-2023-21850
Demantra Demand Management Web Database
7.5
HIGH
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: E-Business Collections). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Demantra Demand Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Demantra Demand Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/

CVE-2023-49298
Software Genérico General
7.5
HIGH
EPSS
0.7%
2023 1 PoC

OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios involving applications that try to rely on efficient copying of file data, can replace file contents with zero-valued bytes and thus potentially disable security mechanisms. NOTE: this issue is not always security related, but can be security related in realistic situations. A possible example is cp, from a recent GNU Core Utilities (coreutils) version, when attempting to preserve a rule set for denying unauthorized access. (One might use cp when configuring access control, such as with the /etc/hosts.deny file specified in t

CVE-2023-37608
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

An issue in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information because there is an automaticsystems super admin account with astech as its hardcoded password.

CVE-2023-26111
@nubosoftware/node-static General
7.5
HIGH
EPSS
1.3%
2023 CWE-22 2 PoCs

All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function.

CVE-2023-32328
Security Verify Access Appliance General
7.5
HIGH
EPSS
0.0%
2023 CWE-319 1 PoC

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attacker on the network to take control of the server. IBM X-Force Id: 254957.

CVE-2023-37478
pnpm General
7.5
HIGH
EPSS
1.6%
2023 CWE-284 2 PoCs

pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed via pnpm is malicious, due to how pnpm parses tar archives. This can result in a package that appears safe on the npm registry or when installed via npm being replaced with a compromised or malicious version when installed via pnpm. This issue has been patched in version(s) 7.33.4 and 8.6.8.

CVE-2023-6042
Getwid General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Any unauthenticated user may send e-mail from the site with any title or content to the admin

CVE-2023-34398
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Some values of this table are serialized archive according boost library. The boost library contains a vulnerability/null pointer dereference.

CVE-2023-42580
Galaxy Store Web
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Improper URL validation from MCSLaunch deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to install APK from Galaxy Store.

CVE-2023-1444
Twister Antivirus General
7.5
HIGH
EPSS
0.6%
2023 CWE-404 1 PoC

A vulnerability was found in Filseclab Twister Antivirus 8. It has been rated as critical. This issue affects the function 0x8011206B in the library fildds.sys of the component IoControlCode Handler. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-223289 was assigned to this vulnerability.

CVE-2023-6029
EazyDocs Web Windows
7.5
HIGH
EPSS
0.1%
2023 1 PoC

The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from the plugin, allowing unauthenticated users to delete arbitrary posts, as well as add and delete documents/sections.

CVE-2023-21853
Mobile Field Service Web Database
7.5
HIGH
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component: Synchronization). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Mobile Field Service. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Mobile Field Service accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).

CVE-2023-20524
2nd Gen AMD EPYC™ General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

An attacker with a compromised ASP could possibly send malformed commands to an ASP on another CPU, resulting in an out of bounds write, potentially leading to a loss a loss of integrity.

CVE-2023-43261
Software Genérico Networking ⚡ nuclei
7.5
HIGH
EPSS
93.1%
2023 3 PoCs

An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.

CVE-2023-21515
Galaxy Store Web
7.5
HIGH
EPSS
0.2%
2023 CWE-20 1 PoC

InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.

CVE-2023-31300
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via transmission of unencrypted, cleartext credentials during Password Reset feature.

CVE-2023-31315
3rd Gen AMD EPYC™ Processors General
7.5
HIGH
EPSS
0.0%
2023 1 PoC

Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.

CVE-2023-31594
Software Genérico Web
7.5
HIGH
EPSS
0.4%
2023 1 PoC

IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via an exposed HTTP channel using VLC network.