5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-35874
SAP NetWeaver AS ABAP and ABAP Platform General
6.0
MEDIUM
EPSS
0.1%
2023 CWE-306 1 PoC

SAP NetWeaver Application Server ABAP and ABAP Platform - version KRNL64NUC, 7.22, KRNL64NUC 7.22EXT, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KERNEL 7.22, KERNEL, 7.53, KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERNEL 7.89, KERNEL 7.54, KERNEL 7.92, KERNEL 7.93, under some conditions, performs improper authentication checks for functionalities that require user identity. An attacker can perform malicious actions over the network, extending the scope of impact, causing a limited impact on confidentiality, integrity and availability.

CVE-2023-21961
Hyperion Essbase Administration Services Database
6.0
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle Hyperion Essbase Administration Services product of Oracle Essbase (component: EAS Administration and EAS Console). The supported version that is affected is 21.4.3.0.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Essbase Administration Services executes to compromise Oracle Hyperion Essbase Administration Services. While the vulnerability is in Oracle Hyperion Essbase Administration Services, attacks may significantly impact additional products (scope change). Successful attacks of this

CVE-2023-1367
alextselegidis/easyappointments General
6.0
MEDIUM
EPSS
0.2%
2023 CWE-94 1 PoC

Code Injection in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

CVE-2023-22002
VM VirtualBox Database
6.0
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM Virtu

CVE-2023-21498
Samsung Mobile Devices General
6.0
MEDIUM
EPSS
0.1%
2023 CWE-20 1 PoC

Improper input validation vulnerability in setPartnerTAInfo in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to overwrite the trustlet memory.

CVE-2023-31026
vGPU driver and Cloud gaming driver Cloud Windows
6.0
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a NULL-pointer dereference may lead to denial of service.

CVE-2023-21453
Samsung Mobile Devices General
6.0
MEDIUM
EPSS
0.1%
2023 CWE-20 1 PoC

Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local attackers access to protected data.

CVE-2023-2998
thorsten/phpmyfaq Web
6.0
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14.

CVE-2023-6832
microweber/microweber General
6.0
MEDIUM
EPSS
0.1%
2023 CWE-840 1 PoC

Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.

CVE-2023-41787
Pandora FMS General
6.0
MEDIUM
EPSS
0.1%
2023 CWE-427 1 PoC

Uncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File Search Paths. This vulnerability allows access to files with sensitive information. This issue affects Pandora FMS: from 700 through 772.

CVE-2023-21907
Banking Virtual Account Management Web Database
6.0
MEDIUM
EPSS
0.6%
2023 1 PoC

Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Banking Virtual Acco

CVE-2023-1541
answerdev/answer General
6.0
MEDIUM
EPSS
0.4%
2023 CWE-840 1 PoC

Business Logic Errors in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2023-27897
CRM General
6.0
MEDIUM
EPSS
1.3%
2023 CWE-94 1 PoC

In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed, the attack can can have limited impact on confidentiality and integrity of non-critical user or application data and application availability.

CVE-2023-20075
Cisco Secure Email Networking
6.0
MEDIUM
EPSS
0.1%
2023 CWE-77 1 PoC

Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands. These vulnerability is due to improper input validation in the CLI. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A successful exploit could allow the attacker to escape the restricted command prompt and execute arbitrary commands on the underlying operating system. To successfully exploit this vulnerability, an attacker would need valid Administrator credentials.

CVE-2023-3822
pimcore/pimcore Web
6.0
MEDIUM
EPSS
10.9%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.6.4.

CVE-2023-21478
Samsung Mobile Devices General
6.0
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.

CVE-2023-4722
gpac/gpac General
5.9
MEDIUM
EPSS
0.0%
2023 CWE-190 1 PoC

Integer Overflow or Wraparound in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-38371
Security Access Manager Docker DevOps
5.9
MEDIUM
EPSS
0.0%
2023 CWE-327 2 PoCs

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 261198.

CVE-2023-4653
instantsoft/icms2 Web
5.9
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

CVE-2023-21924
Health Sciences InForm Web Database
5.9
MEDIUM
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Health Sciences InForm, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can