5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-33920
CP-8031 MASTER MODULE General
6.8
MEDIUM
EPSS
0.1%
2023 CWE-798 2 PoCs

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The affected devices contain the hash of the root password in a hard-coded form, which could be exploited for UART console login to the device. An attacker with direct physical access could exploit this vulnerability.

CVE-2023-49983
Software Genérico Web
6.8
MEDIUM
EPSS
0.4%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.

CVE-2023-5309
Puppet Enterprise General
6.8
MEDIUM
EPSS
0.3%
2023 CWE-384 1 PoC

Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.

CVE-2023-29090
Software Genérico General
6.8
MEDIUM
EPSS
0.6%
2023 2 PoCs

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficient parameter validation while decoding an SIP Via header.

CVE-2023-2666
froxlor/froxlor General
6.8
MEDIUM
EPSS
0.1%
2023 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository froxlor/froxlor prior to 2.0.16.

CVE-2023-30672
Samsung Smart Switch Windows
6.8
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper privilege management vulnerability in Samsung Smart Switch for Windows Installer prior to version 4.3.23043_3 allows attackers to cause permanent DoS via directory junction.

CVE-2023-22880
Zoom for Windows Windows
6.8
MEDIUM
EPSS
0.5%
2023 CWE-200 1 PoC

Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 contain an information disclosure vulnerability. A recent update to the Microsoft Edge WebView2 runtime used by the affected Zoom clients, transmitted text to Microsoft’s online Spellcheck service instead of the local Windows Spellcheck. Updating Zoom remediates this vulnerability by disabling the feature. Updating Microsoft Edge WebView2 Runtime to at least version 109.0.1481.0 and restarting Zoom remediates this vulnerability by updating Microsof

CVE-2023-29091
Software Genérico General
6.8
MEDIUM
EPSS
0.6%
2023 2 PoCs

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficient parameter validation while decoding an SIP URI.

CVE-2023-30705
Galaxy Store General
6.8
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.56.6?allows local attackers to access privileged content providers as Galaxy Store permission.

CVE-2023-3589
Teamwork Cloud - Business Edition Web Cloud
6.8
MEDIUM
EPSS
0.2%
2023 CWE-352 1 PoC

A Cross-Site Request Forgery (CSRF) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x could allow with some very specific conditions an attacker to send a specifically crafted query to the server.

CVE-2023-1288
ENOVIA Live Collaboration General
6.8
MEDIUM
EPSS
0.4%
2023 CWE-611 1 PoC

An XML External Entity injection (XXE) vulnerability in ENOVIA Live Collaboration V6R2013xE allows an attacker to read local files on the server.

CVE-2023-0642
squidex/squidex Web
6.8
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository squidex/squidex prior to 7.4.0.

CVE-2023-0795
libtiff General
6.8
MEDIUM
EPSS
0.0%
2023 1 PoC

LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3488, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit afaabc3e.

CVE-2023-7003
Kontrol Lux General
6.8
MEDIUM
EPSS
0.1%
2023 CWE-323 1 PoC

The AES key utilized in the pairing process between a lock using Sciener firmware and a wireless keypad is not unique, and can be reused to compromise other locks using the Sciener firmware.

CVE-2023-28613
Software Genérico General
6.8
MEDIUM
EPSS
1.0%
2023 2 PoCs

An issue was discovered in Samsung Exynos Mobile Processor and Baseband Modem Processor for Exynos 1280, Exynos 2200, and Exynos Modem 5300. An integer overflow in IPv4 fragment handling can occur due to insufficient parameter validation when reassembling these fragments.

CVE-2023-43477
Smart Modem Gen 2 (Arcadyan LH1000) General
6.8
MEDIUM
EPSS
20.8%
2023 CWE-77 1 PoC

The ping_from parameter of ping_tracerte.cgi in the web UI of Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, was not properly sanitized before being used in a system call, which could allow an authenticated attacker to achieve command injection as root on the device. 

CVE-2023-0803
libtiff General
6.8
MEDIUM
EPSS
0.0%
2023 1 PoC

LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3516, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.

CVE-2023-37467
discourse Web
6.8
MEDIUM
EPSS
0.2%
2023 CWE-323 1 PoC

Discourse is an open source discussion platform. Prior to version 3.1.0.beta7 of the `beta` and `tests-passed` branches, a CSP (Content Security Policy) nonce reuse vulnerability was discovered could allow cross-site scripting (XSS) attacks to bypass CSP protection for anonymous (i.e. unauthenticated) users. There are no known XSS vectors at the moment, but should one be discovered, this vulnerability would allow the XSS attack to bypass CSP and execute successfully. This vulnerability isn't applicable to logged-in users. Version 3.1.0.beta7 contains a patch. The stable branch doesn't have thi

CVE-2023-1543
answerdev/answer General
6.8
MEDIUM
EPSS
0.3%
2023 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2023-29085
Software Genérico General
6.8
MEDIUM
EPSS
0.9%
2023 2 PoCs

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficient parameter validation while decoding an SIP status line.