5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-5405
Experion Server General
5.9
MEDIUM
EPSS
0.1%
2023 CWE-787 1 PoC

Server information leak for the CDA Server process memory can occur when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-37368
Software Genérico General
5.9
MEDIUM
EPSS
0.1%
2023 1 PoC

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem (Exynos Mobile Processor, Automotive Processor, and Modem - Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123). In the Shannon MM Task, Missing validation of a NULL pointer can cause abnormal termination via a malformed NR MM packet.

CVE-2023-49083
cryptography General
5.9
MEDIUM
EPSS
0.9%
2023 CWE-476 1 PoC

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` could lead to a NULL-pointer dereference and segfault. Exploitation of this vulnerability poses a serious risk of Denial of Service (DoS) for any application attempting to deserialize a PKCS7 blob/certificate. The consequences extend to potential disruptions in system availability and stability. This vulnerability has been patched in version 41.0.6.

CVE-2023-1436
jettison General
5.9
MEDIUM
EPSS
0.1%
2023 CWE-674 1 PoC

An infinite recursion is triggered in Jettison when constructing a JSONArray from a Collection that contains a self-reference in one of its elements. This leads to a StackOverflowError exception being thrown.

CVE-2023-5398
Experion Server General
5.9
MEDIUM
EPSS
0.0%
2023 CWE-1327 1 PoC

Server receiving a malformed message based on a list of IPs resulting in heap corruption causing a denial of service. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-22899
Software Genérico General
5.9
MEDIUM
EPSS
0.3%
2023 2 PoCs

Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.

CVE-2023-41792
Pandora FMS Web
5.9
MEDIUM
EPSS
0.0%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed Javascript code to be executed in the SNMP Trap Editor. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-30446
DB2 for Linux, UNIX and Windows Windows
5.9
MEDIUM
EPSS
0.1%
2023 CWE-20 1 PoC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253361 .

CVE-2023-22043
Java SE JDK and JRE Database
5.9
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u371. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrus

CVE-2023-4758
gpac/gpac General
5.9
MEDIUM
EPSS
0.0%
2023 CWE-126 1 PoC

Buffer Over-read in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-6566
microweber/microweber General
5.9
MEDIUM
EPSS
0.1%
2023 CWE-840 1 PoC

Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.

CVE-2023-27624
Redirect After Login Web ⚡ nuclei
5.9
MEDIUM
EPSS
0.7%
2023 CWE-79 0 PoCs

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marcelotorres Redirect After Login plugin <= 0.1.9 versions.

CVE-2023-31421
Beats General
5.9
MEDIUM
EPSS
0.1%
2023 CWE-295 1 PoC

It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate is valid for the target IP address; however, certificate signature validation is still performed. More specifically, when the client is configured to connect to an IP address (instead of a hostname) it does not validate the server certificate's IP SAN values against that IP address and certificate validation fails, and therefore the connection is not blocked as expected.

CVE-2023-3782
Software Genérico Web
5.9
MEDIUM
EPSS
0.3%
2023 CWE-400 1 PoC

DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb into an HTTP response

CVE-2023-30448
DB2 for Linux, UNIX and Windows Windows
5.9
MEDIUM
EPSS
0.1%
2023 CWE-20 1 PoC

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253437.

CVE-2023-1212
phpipam/phpipam Web
5.9
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository phpipam/phpipam prior to v1.5.2.

CVE-2023-22325
SoftEther VPN Networking
5.9
MEDIUM
EPSS
0.2%
2023 CWE-835 1 PoC

A denial of service vulnerability exists in the DCRegister DDNS_RPC_MAX_RECV_SIZE functionality of SoftEther VPN 4.41-9782-beta, 5.01.9674 and 5.02. A specially crafted network packet can lead to denial of service. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

CVE-2023-48795
Software Genérico Web Networking
5.9
MEDIUM
EPSS
50.7%
2023 11 PoCs

The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack agai

CVE-2023-52432
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper input validation in IpcTxSndSetLoopbackCtrl in libsec-ril prior to SMR Sep-2023 Release 1 allows local attackers to write out-of-bounds memory.

CVE-2023-6237
OpenSSL General
5.9
MEDIUM
EPSS
0.9%
2023 CWE-606 1 PoC

Issue summary: Checking excessively long invalid RSA public keys may take a long time. Impact summary: Applications that use the function EVP_PKEY_public_check() to check RSA public keys may experience long delays. Where the key that is being checked has been obtained from an untrusted source this may lead to a Denial of Service. When function EVP_PKEY_public_check() is called on RSA public keys, a computation is done to confirm that the RSA modulus, n, is composite. For valid RSA keys, n is a product of two or more large primes and this computation completes quickly. However, if n is an ove