5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-33105
Snapdragon General
7.5
HIGH
EPSS
2.4%
2023 CWE-16 1 PoC

Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number.

CVE-2023-49981
Software Genérico General
7.5
HIGH
EPSS
0.6%
2023 2 PoCs

A directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.

CVE-2023-29929
Software Genérico General
7.5
HIGH
EPSS
2.8%
2023 2 PoCs

Buffer Overflow vulnerability found in Kemptechnologies Loadmaster before v.7.2.60.0 allows a remote attacker to casue a denial of service via the libkemplink.so, isreverse library.

CVE-2023-27159
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
80.2%
2023 0 PoCs

Appwrite up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /v1/avatars/favicon. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.

CVE-2023-42488
v3.0.6433.1964 General
7.5
HIGH
EPSS
0.2%
2023 CWE-22 1 PoC

EisBaer Scada - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVE-2023-42358
Software Genérico Web
7.5
HIGH
EPSS
0.5%
2023 1 PoC

An issue was discovered in O-RAN Software Community ric-plt-e2mgr in the G-Release environment, allows remote attackers to cause a denial of service (DoS) via a crafted request to the E2Manager API component.

CVE-2023-30112
Software Genérico Web Database
7.5
HIGH
EPSS
0.3%
2023 1 PoC

Medicine Tracker System in PHP 1.0.0 is vulnerable to SQL Injection.

CVE-2023-23131
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

Selfwealth iOS mobile App 3.3.1 is vulnerable to Insecure App Transport Security (ATS) Settings.

CVE-2023-24033
Software Genérico General
7.5
HIGH
EPSS
1.8%
2023 2 PoCs

The Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T512 baseband modem chipsets do not properly check format types specified by the Session Description Protocol (SDP) module, which can lead to a denial of service.

CVE-2023-44828
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the CurrentPassword parameter in the CheckPasswdSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-40297
Software Genérico General
7.5
HIGH
EPSS
3.1%
2023 1 PoC

Stakater Forecastle 1.0.139 and before allows %5C../ directory traversal in the website component.

CVE-2023-44835
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Mac parameter in the SetParentsControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-42581
Galaxy Store Web
7.5
HIGH
EPSS
0.3%
2023 1 PoC

Improper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to access data.

CVE-2023-24506
NCR/Camera General
7.5
HIGH
EPSS
0.3%
2023 CWE-522 1 PoC

Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request.

CVE-2023-36667
Software Genérico General
7.5
HIGH
EPSS
1.0%
2023 1 PoC

Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal.

CVE-2023-5590
seleniumhq/selenium General
7.5
HIGH
EPSS
0.1%
2023 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository seleniumhq/selenium prior to 4.14.0.

CVE-2023-30198
Software Genérico Web
7.5
HIGH
EPSS
5.7%
2023 1 PoC

Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download.php.

CVE-2023-21996
WebLogic Server Web Database
7.5
HIGH
EPSS
0.9%
2023 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVE-2023-21893
Data Provider for .NET Database Windows
7.5
HIGH
EPSS
1.1%
2023 1 PoC

Vulnerability in the Oracle Data Provider for .NET component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCPS to compromise Oracle Data Provider for .NET. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Data Provider for .NET. Note: Applies also to Database client-only on Windows platform. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability

CVE-2023-26774
Software Genérico Web
7.5
HIGH
EPSS
0.6%
2023 3 PoCs

An issue found in Sales Tracker Management System v.1.0 allows a remote attacker to access sensitive information via sales.php component of the admin/reports endpoint.