5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-38960
Software Genérico General
7.3
HIGH
EPSS
0.0%
2023 1 PoC

Insecure Permissions issue in Raiden Professional Server RaidenFTPD v.2.4 build 4005 allows a local attacker to gain privileges and execute arbitrary code via crafted executable running from the installation directory.

CVE-2023-0051
vim/vim General
7.3
HIGH
EPSS
0.0%
2023 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1144.

CVE-2023-26159
follow-redirects General
7.3
HIGH
EPSS
0.1%
2023 CWE-20 1 PoC

Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error, it can be manipulated to misinterpret the hostname. An attacker could exploit this weakness to redirect traffic to a malicious site, potentially leading to information disclosure, phishing attacks, or other security breaches.

CVE-2023-0049
vim/vim General
7.3
HIGH
EPSS
0.0%
2023 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.

CVE-2023-0512
vim/vim General
7.3
HIGH
EPSS
0.0%
2023 CWE-369 2 PoCs

Divide By Zero in GitHub repository vim/vim prior to 9.0.1247.

CVE-2023-5036
usememos/memos Web
7.3
HIGH
EPSS
0.1%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.

CVE-2023-6579
osCommerce Database
7.3
HIGH
EPSS
0.5%
2023 CWE-89 1 PoC

A vulnerability, which was classified as critical, has been found in osCommerce 4. Affected by this issue is some unknown functionality of the file /b2b-supermarket/shopping-cart of the component POST Parameter Handler. The manipulation of the argument estimate[country_id] leads to sql injection. The attack may be launched remotely. The identifier of this vulnerability is VDB-247160. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-2904
SAFE Web
7.3
HIGH
EPSS
0.2%
2023 CWE-471 1 PoC

The External Visitor Manager portal of HID’s SAFE versions 5.8.0 through 5.11.3 are vulnerable to manipulation within web fields in the application programmable interface (API). An attacker could log in using account credentials available through a request generated by an internal user and then manipulate the visitor-id within the web API to access the personal data of other users. There is no limit on the number of requests that can be made to the HID SAFE Web Server, so an attacker could also exploit this vulnerability to create a denial-of-service condition.

CVE-2023-6132
AVEVA Edge General
7.3
HIGH
EPSS
0.0%
2023 CWE-427 1 PoC

The vulnerability, if exploited, could allow a malicious entity with access to the file system to achieve arbitrary code execution and privilege escalation by tricking AVEVA Edge to load an unsafe DLL.

CVE-2023-36537
Zoom Rooms for Windows Windows
7.3
HIGH
EPSS
0.0%
2023 CWE-354 1 PoC

Improper privilege management in Zoom Rooms for Windows before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.

CVE-2023-3891
Lapce General
7.3
HIGH
EPSS
0.1%
2023 CWE-367 1 PoC

Race condition in Lapce v0.2.8 allows an attacker to elevate privileges on the system

CVE-2023-0562
Bank Locker Management System Web Database ⚡ nuclei
7.3
HIGH
EPSS
77.3%
2023 CWE-89 0 PoCs

A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php of the component Login. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-219716.

CVE-2023-26214
TIBCO BusinessConnect Web
7.3
HIGH
EPSS
0.7%
2023 1 PoC

The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affected system or the victim's local system. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect: versions 7.3.0 and below.

CVE-2023-3971
Red Hat Ansible Automation Platform 2.3 for RHEL 8 DevOps
7.3
HIGH
EPSS
0.4%
2023 CWE-80 1 PoC

An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.

CVE-2023-42566
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.1%
2023 1 PoC

Out-of-bound write vulnerability in libsavsvc prior to SMR Dec-2023 Release 1 allows local attackers to execute arbitrary code.

CVE-2023-7172
Hospital Management System Web Database
7.3
HIGH
EPSS
1.7%
2023 CWE-89 1 PoC

A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the component Admin Dashboard. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249356.

CVE-2023-53878
Member Login Script Web
7.3
HIGH
EPSS
0.1%
2023 CWE-444 1 PoC

Member Login Script 3.3 contains a client-side desynchronization vulnerability that allows attackers to manipulate HTTP request handling by exploiting Content-Length header parsing. Attackers can send crafted POST requests with smuggled secondary requests to potentially bypass server-side request processing controls.

CVE-2023-2594
Food Ordering Management System Database
7.3
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability, which was classified as critical, was found in SourceCodester Food Ordering Management System 1.0. Affected is an unknown function of the component Registration. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-228396.

CVE-2023-26110
node-bluetooth General
7.3
HIGH
EPSS
0.2%
2023 CWE-120 1 PoC

All versions of the package node-bluetooth are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation.

CVE-2023-6099
Facial Love Cloud Payment System Cloud
7.3
HIGH
EPSS
0.1%
2023 CWE-269 1 PoC

A vulnerability classified as critical has been found in Shenzhen Youkate Industrial Facial Love Cloud Payment System up to 1.0.55.0.0.1. This affects an unknown part of the file /SystemMng.ashx of the component Account Handler. The manipulation of the argument operatorRole with the input 00 leads to improper privilege management. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-245061 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.