5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-37014
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Release Request` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

CVE-2023-7269
ArtPlacer Widget Web Windows
7.5
HIGH
EPSS
0.1%
2023 1 PoC

The ArtPlacer Widget WordPress plugin before 2.21.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2023-2180
KIWIZ Invoices Certification & PDF System Web Windows
7.5
HIGH
EPSS
0.6%
2023 1 PoC

The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unserialization (assuming they can upload a file on the server)

CVE-2023-47091
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10, and SNS 4.7.0 through 4.7.1 before 4.7.2. An attacker can overflow the cookie threshold, making an IPsec connection impossible.

CVE-2023-22620
Software Genérico Networking ⚡ nuclei
7.5
HIGH
EPSS
84.2%
2023 3 PoCs

An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows sessionid information disclosure via an invalid authentication attempt. This can afterwards be used to bypass the device's authentication and get access to the administrative interface.

CVE-2023-40279
Software Genérico General
7.5
HIGH
EPSS
19.8%
2023 3 PoCs

An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to main.do.

CVE-2023-37218
Telecom Aeonix General
7.5
HIGH
EPSS
0.1%
2023 CWE-22 1 PoC

Tadiran Telecom Aeonix - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVE-2023-30445
DB2 for Linux, UNIX and Windows Windows
7.5
HIGH
EPSS
0.1%
2023 CWE-20 1 PoC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253357.

CVE-2023-26758
Software Genérico General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Sme.UP TOKYO V6R1M220406 was discovered to contain an arbitrary file download vulnerabilty via the component /ResourceService.

CVE-2023-52355
Software Genérico Web
7.5
HIGH
EPSS
1.3%
2023 CWE-787 1 PoC

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

CVE-2023-26130
yhirose/cpp-httplib Web
7.5
HIGH
EPSS
0.2%
2023 CWE-93 2 PoCs

Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type header in the HTTP .Patch, .Post, .Put and .Delete requests. This can lead to logical errors and other misbehaviors. **Note:** This issue is present due to an incomplete fix for [CVE-2020-11709](https://security.snyk.io/vuln/SNYK-UNMANAGED-YHIROSECPPHTTPLIB-2366507).

CVE-2023-26256
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
91.8%
2023 7 PoCs

An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying the fileName parameter to the snjFooterNavigationConfig endpoint, it is possible to traverse and read the file system.

CVE-2023-0331
Correos Oficial Web Windows
7.5
HIGH
EPSS
0.5%
2023 1 PoC

The Correos Oficial WordPress plugin through 1.2.0.2 does not have an authorization check user input validation when generating a file path, allowing unauthenticated attackers to download arbitrary files from the server.

CVE-2023-26126
m.static General
7.5
HIGH
EPSS
0.3%
2023 CWE-22 1 PoC

All versions of the package m.static are vulnerable to Directory Traversal due to improper input sanitization of the path being requested via the requestFile function.

CVE-2023-21852
Learning Management Web Database
7.5
HIGH
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Setup). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Learning Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Learning Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).

CVE-2023-1405
Formidable Forms Web Windows
7.5
HIGH
EPSS
0.3%
2023 2 PoCs

The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.

CVE-2023-23907
MilesightVPN Networking
7.5
HIGH
EPSS
0.2%
2023 CWE-22 2 PoCs

A directory traversal vulnerability exists in the server.js start functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to arbitrary file read. An attacker can send a network request to trigger this vulnerability.

CVE-2023-24504
Central AC unit General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

Electra Central AC unit – Adjacent attacker may cause the unit to connect to unauthorized update server.

CVE-2023-39982
MXsecurity Series Networking
7.5
HIGH
EPSS
0.2%
2023 CWE-321 1 PoC

A vulnerability has been identified in MXsecurity versions prior to v1.0.1. The vulnerability may put the confidentiality and integrity of SSH communications at risk on the affected device. This vulnerability is attributed to a hard-coded SSH host key, which might facilitate man-in-the-middle attacks and enable the decryption of SSH traffic.

CVE-2023-45232
edk2 General
7.5
HIGH
EPSS
0.5%
2023 CWE-835 1 PoC

EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.