5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-50125
Software Genérico General
5.9
MEDIUM
EPSS
0.2%
2023 1 PoC

A default engineer password set on the Hozard alarm system (Alarmsysteem) v1.0 allows an attacker to bring the alarm system to a disarmed state.

CVE-2023-0400
Data Loss Prevention (DLP) Windows
5.9
MEDIUM
EPSS
0.1%
2023 CWE-670 1 PoC

The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP controls when uploading sensitive data from a mapped drive into a web email client. Loading from a local driver was correctly prevented. Versions prior to 11.9 correctly detected and blocked the attempted upload of sensitive data.

CVE-2023-4721
gpac/gpac General
5.9
MEDIUM
EPSS
0.0%
2023 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-4756
gpac/gpac General
5.9
MEDIUM
EPSS
0.0%
2023 CWE-121 1 PoC

Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-39209
Zoom Desktop Client for Windows Windows
5.9
MEDIUM
EPSS
0.1%
2023 CWE-449 1 PoC

Improper input validation in Zoom Desktop Client for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via network access.

CVE-2023-2589
GitLab DevOps
5.9
MEDIUM
EPSS
0.2%
2023 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker can clone a repository from a public project, from a disallowed IP, even after the top-level group has enabled IP restrictions on the group.

CVE-2023-0857
Canon Office/Small Office Multifunction Printers and Laser Printers General
5.9
MEDIUM
EPSS
0.1%
2023 CWE-286 1 PoC

Unintentional change of settings during initial registration of system administrators which uses control protocols. The affected Office / Small Office Multifunction Printers and Laser Printers(*) may allow an attacker on the network segment to trigger unauthorized access to the product. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C

CVE-2023-50127
Software Genérico General
5.9
MEDIUM
EPSS
0.1%
2023 1 PoC

Hozard alarm system (Alarmsysteem) v1.0 is vulnerable to Improper Authentication. Commands sent via the SMS functionality are accepted from random phone numbers, which allows an attacker to bring the alarm system to a disarmed state from any given phone number.

CVE-2023-38730
Spectrum Copy Data Management General
5.9
MEDIUM
EPSS
0.0%
2023 CWE-327 1 PoC

IBM Storage Copy Data Management 2.2.0.0 through 2.2.19.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 262268.

CVE-2023-4985
InPlant SCADA General
5.9
MEDIUM
EPSS
0.1%
2023 CWE-287 1 PoC

A vulnerability classified as critical has been found in Supcon InPlant SCADA up to 20230901. Affected is an unknown function of the file Project.xml. The manipulation leads to improper authentication. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239796. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-42532
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.3%
2023 1 PoC

Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmware information.

CVE-2023-44088
Pandora FMS Database
5.9
MEDIUM
EPSS
0.2%
2023 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitrary SQL queries were allowed to be executed using any account with low privileges. This issue affects Pandora FMS: from 700 through 774.

CVE-2023-22053
MySQL Server Database
5.9
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 5.7.42 and prior and 8.0.33 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server and unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impac

CVE-2023-4682
gpac/gpac General
5.9
MEDIUM
EPSS
0.0%
2023 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-30447
DB2 for Linux, UNIX and Windows Windows
5.9
MEDIUM
EPSS
0.1%
2023 CWE-20 1 PoC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253436.

CVE-2023-36917
SAP BusinessObjects Business Intelligence Platform General
5.9
MEDIUM
EPSS
0.1%
2023 CWE-307 1 PoC

SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized attacker who had hijacked a user session, to be able to bypass the victim’s old password via brute force, due to unrestricted rate limit for password change functionality. Although the attack has no impact on integrity loss or system availability, this could lead to an attacker to completely takeover a victim’s account.

CVE-2023-42538
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.1%
2023 1 PoC

An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

CVE-2023-21875
MySQL Server Database
5.9
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 8.0.31 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.9 (Integri

CVE-2023-3304
admidio/admidio General
5.9
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9.

CVE-2023-21455
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.2%
2023 CWE-287 1 PoC

Improper authorization implementation in Exynos baseband prior to SMR Mar-2023 Release 1 allows incorrect handling of unencrypted message.