5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-34367
Software Genérico Windows
6.5
MEDIUM
EPSS
1.2%
2023 2 PoCs

Windows 7 is vulnerable to a full blind TCP/IP hijacking attack. The vulnerability exists in Windows 7 (any Windows until Windows 8) and in any implementation of TCP/IP, which is vulnerable to the Idle scan attack (including many IoT devices). NOTE: The vendor considers this a low severity issue.

CVE-2023-32750
Software Genérico Web
6.5
MEDIUM
EPSS
2.8%
2023 2 PoCs

Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The job "remote-download" can be used to cause the backend to send a HTTP GET request to a specified URL and save the response to a new file. The response file is then available in a user-specified folder in Pydio Cells.

CVE-2023-0952
Devolutions Server General
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an authenticated user to access sensitive data without proper authorization.

CVE-2023-31018
vGPU driver and Cloud gaming driver Cloud Windows
6.5
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

NVIDIA GPU Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a NULL-pointer dereference, which may lead to denial of service.

CVE-2023-27896
BusinessObjects Business Intelligence Platform (Web Services) Web
6.5
MEDIUM
EPSS
0.3%
2023 CWE-918 1 PoC

In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own CMS, leading to a high impact on availability.

CVE-2023-0522
Enable/Disable Auto Login when Register Web Windows
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

The Enable/Disable Auto Login when Register WordPress plugin through 1.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2023-40745
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2023 CWE-190 1 PoC

LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.

CVE-2023-5462
XD5E-30R-E General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-404 2 PoCs

A vulnerability was found in XINJE XD5E-30R-E 3.5.3b. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Modbus Handler. The manipulation leads to denial of service. The exploit has been disclosed to the public and may be used. The identifier VDB-241585 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-45228
Analog FM transmitter Web
6.5
MEDIUM
EPSS
0.0%
2023 CWE-284 2 PoCs

The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissions by sending a single HTTP POST request with modified parameters.

CVE-2023-3413
GitLab DevOps
6.5
MEDIUM
EPSS
0.2%
2023 CWE-201 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to read the source code of a project through a fork created before changing visibility to only project members.

CVE-2023-33477
Software Genérico General
6.5
MEDIUM
EPSS
1.0%
2023 1 PoC

In Harmonic NSG 9000-6G devices, an authenticated remote user can obtain source code by directly requesting a special path.

CVE-2023-24125
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey2_5g parameter at /goform/WifiBasicSet.

CVE-2023-22022
Life Sciences Data Management Workbench Web Database
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Vulnerability in the Oracle Health Sciences Sciences Data Management Workbench product of Oracle Health Sciences Applications (component: Blinding Functionality). Supported versions that are affected are 3.1.0.2, 3.1.1.3 and 3.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Health Sciences Sciences Data Management Workbench. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Health Sciences Sciences Data Management Workbench accessible data. CVS

CVE-2023-35636
Microsoft Office 2019 General
6.5
MEDIUM
EPSS
10.5%
2023 CWE-200 1 PoC

Microsoft Outlook Information Disclosure Vulnerability

CVE-2023-0298
firefly-iii/firefly-iii General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-863 1 PoC

Incorrect Authorization in GitHub repository firefly-iii/firefly-iii prior to 5.8.0.

CVE-2023-0024
Solution Manager (BSP Application) Web
6.5
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information or craft a payload which may restrict access to the desired resources, resulting in Cross-Site Scripting vulnerability.

CVE-2023-37025
Software Genérico Networking
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Reset` packet missing an expected `ResetType` field.

CVE-2023-24117
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepauth_5g parameter at /goform/WifiBasicSet.

CVE-2023-29548
Firefox General
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.

CVE-2023-24126
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey4_5g parameter at /goform/WifiBasicSet.