5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-33921
CP-8031 MASTER MODULE General
6.8
MEDIUM
EPSS
0.2%
2023 CWE-749 2 PoCs

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The affected devices contain an exposed UART console login interface. An attacker with direct physical access could try to bruteforce or crack the root password to login to the device.

CVE-2023-49965
Software Genérico Web Networking
6.8
MEDIUM
EPSS
0.4%
2023 1 PoC

SpaceX Starlink Wi-Fi router Gen 2 before 2023.48.0 allows XSS via the ssid and password parameters on the Setup Page.

CVE-2023-21493
Samsung Mobile Devices General
6.8
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control vulnerability in SemShareFileProvider prior to SMR May-2023 Release 1 allows local attackers to access protected data.

CVE-2023-30962
com.palantir.acme.cerberus:cerberus Web
6.8
MEDIUM
EPSS
0.6%
2023 CWE-434 1 PoC

The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Gotham to launch attacks against other users. This vulnerability is resolved in Cerberus 100.230704.0-27-g031dd58 .

CVE-2023-0378
Greenshift Web Windows
6.8
MEDIUM
EPSS
0.5%
2023 1 PoC

The Greenshift WordPress plugin before 5.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0801
libtiff General
6.8
MEDIUM
EPSS
0.0%
2023 1 PoC

LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tools/tiffcrop.c:6778, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.

CVE-2023-44090
Pandora FMS DevOps Database
6.8
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows CVE-2008-5817. This vulnerability allowed SQL changes to be made to several files in the Grafana module. This issue affects Pandora FMS: from 700 through <776.

CVE-2023-0799
libtiff General
6.8
MEDIUM
EPSS
0.0%
2023 1 PoC

LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3701, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit afaabc3e.

CVE-2023-2839
gpac/gpac General
6.8
MEDIUM
EPSS
0.1%
2023 CWE-369 1 PoC

Divide By Zero in GitHub repository gpac/gpac prior to 2.2.2.

CVE-2023-1965
GitLab DevOps
6.8
MEDIUM
EPSS
0.1%
2023 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd party Group SAML SSO logins. This feature isn't enabled by default.

CVE-2023-29087
Software Genérico General
6.8
MEDIUM
EPSS
0.6%
2023 2 PoCs

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficient parameter validation while decoding an SIP Retry-After header.

CVE-2023-4422
cockpit-hq/cockpit Web
6.8
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

CVE-2023-0800
libtiff General
6.8
MEDIUM
EPSS
0.0%
2023 1 PoC

LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3502, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.

CVE-2023-26461
NetWeaver (SAP Enterprise Portal) General
6.8
MEDIUM
EPSS
0.3%
2023 CWE-611 1 PoC

SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges to access the XML parser which can submit a crafted XML file which when parsed will enable them to access but not modify sensitive files and data. It allows the attacker to view sensitive data which is owned by certain privileges.

CVE-2023-20116
Cisco Unified Communications Manager Web Networking
6.8
MEDIUM
EPSS
0.5%
2023 CWE-835 1 PoC

A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the web UI of the Self Care Portal. An attacker could exploit this vulnerability by sending crafted HTTP input to an affected device. A successful exploit could allow the attacker to cause a DoS conditi

CVE-2023-29088
Software Genérico General
6.8
MEDIUM
EPSS
0.6%
2023 2 PoCs

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficient parameter validation while decoding an SIP Session-Expires header.

CVE-2023-21922
Health Sciences InForm Web Database
6.8
MEDIUM
EPSS
0.7%
2023 1 PoC

Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Health Sciences InForm accessible

CVE-2023-0797
libtiff General
6.8
MEDIUM
EPSS
0.0%
2023 1 PoC

LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tools/tiffcrop.c:6921, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit afaabc3e.

CVE-2023-3394
fossbilling/fossbilling General
6.8
MEDIUM
EPSS
0.1%
2023 CWE-384 1 PoC

Session Fixation in GitHub repository fossbilling/fossbilling prior to 0.5.1.

CVE-2023-46446
Software Genérico Networking
6.8
MEDIUM
EPSS
0.4%
2023 1 PoC

An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulation, aka a "Rogue Session Attack."