5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-26031
Apache Hadoop DevOps Web
7.5
HIGH
EPSS
9.3%
2023 CWE-426 3 PoCs

Relative library resolution in linux container-executor binary in Apache Hadoop 3.3.1-3.3.4 on Linux allows local user to gain root privileges. If the YARN cluster is accepting work from remote (authenticated) users, this MAY permit remote users to gain root privileges. Hadoop 3.3.0 updated the " YARN Secure Containers https://hadoop.apache.org/docs/stable/hadoop-yarn/hadoop-yarn-site/SecureContainer.html " to add a feature for executing user-submitted applications in isolated linux containers. The native binary HADOOP_HOME/bin/container-executor is used to launch these containers; it must b

CVE-2023-4703
All in One B2B for WooCommerce Web Windows
7.5
HIGH
EPSS
0.3%
2023 1 PoC

The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating user details, allowing an unauthenticated attacker to update the details of any user. Updating the password of an Admin user leads to privilege escalation.

CVE-2023-46380
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2023 1 PoC

LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) send password-change requests via cleartext HTTP.

CVE-2023-22435
Experion Server General
7.5
HIGH
EPSS
0.1%
2023 CWE-697 1 PoC

Experion server may experience a DoS due to a stack overflow when handling a specially crafted message.

CVE-2023-6021
ray-project/ray Web ⚡ nuclei
7.5
HIGH
EPSS
87.3%
2023 CWE-29 2 PoCs

LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here: https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-2023-48022-cve-2023-48023

CVE-2023-34092
vite General ⚡ nuclei
7.5
HIGH
EPSS
44.8%
2023 CWE-50 1 PoC

Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (`server.fs.deny`) can be bypassed using double forward-slash (//) allows any unauthenticated user to read file from the Vite root-path of the application including the default `fs.deny` settings (`['.env', '.env.*', '*.{crt,pem}']`). Only users explicitly exposing the Vite dev server to the network (using `--host` or `server.host` config option) are affected, and only files in the immediate Vite project root folder could be exposed. This issue is fixed in vite@4.3.9, vite@4.2.3

CVE-2023-45233
edk2 General
7.5
HIGH
EPSS
0.5%
2023 CWE-835 1 PoC

EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.

CVE-2023-31059
Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
91.2%
2023 1 PoC

Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstrated by connectionLost.php.

CVE-2023-50096
Software Genérico General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bus. This is caused by an StSafeA_ReceiveBytes buffer overflow in the X-CUBE-SAFEA1 Software Package for STSAFE-A sample applications (1.2.0), and thus can affect user-written code that was derived from a published sample application.

CVE-2023-21854
Sales Offline Web Database
7.5
HIGH
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Core Components). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Sales Offline. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Sales Offline accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).

CVE-2023-27598
opensips General
7.5
HIGH
EPSS
0.4%
2023 CWE-908 1 PoC

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, sending a malformed `Via` header to OpenSIPS triggers a segmentation fault when the function `calc_tag_suffix` is called. A specially crafted `Via` header, which is deemed correct by the parser, will pass uninitialized strings to the function `MD5StringArray` which leads to the crash. Abuse of this vulnerability leads to Denial of Service due to a crash. Since the uninitialized string points to memory location `0x0`, no further exploitation appears to be possible. No special network privil

CVE-2023-36643
Software Genérico General
7.5
HIGH
EPSS
0.9%
2023 1 PoC

Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all orders from the online shop via oordershow component in customer function.

CVE-2023-6595
WhatsUp Gold Web
7.5
HIGH
EPSS
0.3%
2023 CWE-306 1 PoC

In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate ancillary credential information stored within WhatsUp Gold.

CVE-2023-32767
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

The web interface of Symcon IP-Symcon before 6.3 (i.e., before 2023-05-12) allows a remote attacker to read sensitive files via .. directory-traversal sequences in the URL.

CVE-2023-26597
C300 General
7.5
HIGH
EPSS
0.1%
2023 CWE-400 1 PoC

Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-26925
Software Genérico General
7.5
HIGH
EPSS
0.9%
2023 2 PoCs

An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-882 1.30. A specially crafted network request can lead to the disclosure of sensitive information.

CVE-2023-42490
v3.0.6433.1964 General
7.5
HIGH
EPSS
0.2%
2023 CWE-200 1 PoC

EisBaer Scada - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CVE-2023-47108
opentelemetry-go-contrib General
7.5
HIGH
EPSS
4.3%
2023 CWE-770 1 PoC

OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. Starting in version 0.37.0 and prior to version 0.46.0, the grpc Unary Server Interceptor out of the box adds labels `net.peer.sock.addr` and `net.peer.sock.port` that have unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests are sent. An attacker can easily flood the peer address and port for requests. Version 0.46.0 contains a fix for this issue. As a workaround to stop being affected, a view removing the attributes can be used. The other possibility is to

CVE-2023-7204
WP STAGING WordPress Backup Plugin Web Windows
7.5
HIGH
EPSS
0.2%
2023 1 PoC

The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the cloning process which provides

CVE-2023-49356
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

A stack buffer overflow vulnerability in MP3Gain v1.6.2 allows an attacker to cause a denial of service via the WriteMP3GainAPETag function at apetag.c:592.