5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-1587
Avast Antivirus Windows
5.8
MEDIUM
EPSS
0.1%
2023 CWE-476 1 PoC

Avast and AVG Antivirus for Windows were susceptible to a NULL pointer dereference issue via RPC-interface. The issue was fixed with Avast and AVG Antivirus version 22.11

CVE-2023-5318
microweber/microweber General
5.8
MEDIUM
EPSS
0.3%
2023 CWE-798 1 PoC

Use of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0.

CVE-2023-2021
nilsteampassnet/teampass Web
5.8
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.3.

CVE-2023-4914
cecilapp/cecil General
5.8
MEDIUM
EPSS
0.2%
2023 CWE-23 1 PoC

Relative Path Traversal in GitHub repository cecilapp/cecil prior to 7.47.1.

CVE-2023-50358
QTS Cloud
5.8
MEDIUM
EPSS
1.8%
2023 CWE-78 3 PoCs

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.5.2645 build 20240116 and later QTS 4.5.4.2627 build 20231225 and later QTS 4.3.6.2665 build 20240131 and later QTS 4.3.4.2675 build 20240131 and later QTS 4.3.3.2644 build 20240131 and later QTS 4.2.6 build 20240131 and later QuTS hero h5.1.5.2647 build 20240118 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5

CVE-2023-47218
QTS Cloud ⚡ nuclei
5.8
MEDIUM
EPSS
93.2%
2023 CWE-77 2 PoCs

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.5.2645 build 20240116 and later QuTS hero h5.1.5.2647 build 20240118 and later QuTScloud c5.1.5.2651 and later

CVE-2023-21422
Samsung Mobile Devices General
5.7
MEDIUM
EPSS
0.1%
2023 CWE-285 1 PoC

Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server without permission via binding WifiService.

CVE-2023-27370
RAX30 Networking
5.7
MEDIUM
EPSS
0.0%
2023 CWE-312 1 PoC

NETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of device configuration. The issue results from the storage of configuration secrets in plaintext. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromi

CVE-2023-41812
Pandora FMS Web
5.7
MEDIUM
EPSS
0.0%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Pandora FMS on all allows Accessing Functionality Not Properly Constrained by ACLs. This vulnerability allowed PHP executable files to be uploaded through the file manager. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-21970
BI Publisher (formerly XML Publisher) Web Database
5.7
MEDIUM
EPSS
0.5%
2023 1 PoC

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Security). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L

CVE-2023-6051
GitLab DevOps
5.7
MEDIUM
EPSS
0.2%
2023 CWE-94 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when source code or installation packages are pulled from a specific tag.

CVE-2023-6147
Policy Compliance Connector Jenkins Plugin DevOps Cloud
5.7
MEDIUM
EPSS
0.2%
2023 CWE-611 1 PoC

Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a permission check while performing a connectivity check to Qualys Cloud Services. This allowed any user with login access to configure or edit jobs to utilize the plugin and configure potential a rouge endpoint via which it was possible to control response for certain request which could be injected with XXE payloads leading to XXE while processing the response data

CVE-2023-29680
Software Genérico Networking
5.7
MEDIUM
EPSS
0.1%
2023 3 PoCs

Cleartext Transmission in set-cookie:ecos_pw: Tenda N301 v6.0, Firmware v12.02.01.61_multi allows an authenticated attacker on the LAN or WLAN to intercept communications with the router and obtain the password.

CVE-2023-42940
macOS General
5.7
MEDIUM
EPSS
0.2%
2023 1 PoC

A session rendering issue was addressed with improved session tracking. This issue is fixed in macOS Sonoma 14.2.1. A user who shares their screen may unintentionally share the incorrect content.

CVE-2023-28436
tailscale Networking
5.7
MEDIUM
EPSS
0.2%
2023 CWE-269 1 PoC

Tailscale is software for using Wireguard and multi-factor authentication (MFA). A vulnerability identified in the implementation of Tailscale SSH starting in version 1.34.0 and prior to prior to 1.38.2 in FreeBSD allows commands to be run with a higher privilege group ID than that specified in Tailscale SSH access rules. A difference in the behavior of the FreeBSD `setgroups` system call from POSIX meant that the Tailscale client running on a FreeBSD-based operating system did not appropriately restrict groups on the host when using Tailscale SSH. When accessing a FreeBSD host over Tailscale

CVE-2023-26441
OX App Suite General
5.7
MEDIUM
EPSS
0.0%
2023 CWE-200 1 PoC

Cacheservice did not correctly check if relative cache object were pointing to the defined absolute location when accessing resources. An attacker with access to the database and a local or restricted network would be able to read arbitrary local file system resources that are accessible by the services system user account. We have improved path validation and make sure that any access is contained to the defined root directory. No publicly available exploits are known.

CVE-2023-2630
pimcore/pimcore Web
5.7
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-53886
Xlight FTP Server General
5.7
MEDIUM
EPSS
0.1%
2023 CWE-121 1 PoC

Xlight FTP Server 3.9.3.6 contains a stack buffer overflow vulnerability in the 'Execute Program' configuration that allows attackers to crash the application. Attackers can trigger the vulnerability by inserting 294 characters into the program execution configuration, causing a denial of service condition.

CVE-2023-1149
btcpayserver/btcpayserver General
5.7
MEDIUM
EPSS
0.4%
2023 CWE-76 1 PoC

Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.8.0.

CVE-2023-1708
GitLab DevOps
5.7
MEDIUM
EPSS
5.2%
2023 1 PoC

An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-printable characters gets copied from clipboard, allowing unexpected commands to be executed on victim machine.