5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-21986
GraalVM Enterprise Edition Database
5.7
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Native Image). Supported versions that are affected are Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle GraalVM Enterprise Edition executes to compromise Oracle GraalVM Enterprise Edition. While the vulnerability is in Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in

CVE-2023-37027
Software Genérico Networking
5.7
MEDIUM
EPSS
0.1%
2023 1 PoC

Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `E-RAB Modification Indication` packet missing an expected `eNB_UE_S1AP_ID` field.

CVE-2023-21502
Samsung Mobile Devices General
5.7
MEDIUM
EPSS
0.1%
2023 CWE-20 1 PoC

Improper input validation vulnerability in FactoryTest application prior to SMR May-2023 Release 1 allows local attackers to get privilege escalation via debugging commands.

CVE-2023-0028
linagora/twake Web
5.7
MEDIUM
EPSS
0.7%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository linagora/twake prior to 2023.Q1.1200+.

CVE-2023-46889
Software Genérico Networking
5.7
MEDIUM
EPSS
0.0%
2023 1 PoC

Meross MSH30Q 4.5.23 is vulnerable to Cleartext Transmission of Sensitive Information. During the device setup phase, the MSH30Q creates an unprotected Wi-Fi access point. In this phase, MSH30Q needs to connect to the Internet through a Wi-Fi router. This is why MSH30Q asks for the Wi-Fi network name (SSID) and the Wi-Fi network password. When the user enters the password, the transmission of the Wi-Fi password and name between the MSH30Q and mobile application is observed in the Wi-Fi network. Although the Wi-Fi password is encrypted, a part of the decryption algorithm is public so we complem

CVE-2023-6148
Policy Compliance Connector Jenkins Plugin DevOps Web Cloud
5.7
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a permission check while performing a connectivity check to Qualys Cloud Services. This allowed any user with login access and access to configure or edit jobs to utilize the plugin to configure a potential rouge endpoint via which it was possible to control response for certain request which could be injected with XSS payloads leading to XSS while processing the response data

CVE-2023-28912
Volkswagen MIB3 infotainment system MIB3 OI MQB General
5.7
MEDIUM
EPSS
0.1%
2023 CWE-312 2 PoCs

The MIB3 unit stores the synchronized phone contact book in clear-text, allowing an attacker with either code execution privilege on the system or physical access to the system to obtain vehicle owner's contact data. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources.

CVE-2023-6149
Web App Scanning Connector Jenkins Plugin DevOps Cloud
5.7
MEDIUM
EPSS
0.2%
2023 CWE-611 1 PoC

Qualys Jenkins Plugin for WAS prior to version and including 2.0.11 was identified to be affected by a security flaw, which was missing a permission check while performing a connectivity check to Qualys Cloud Services. This allowed any user with login access to configure or edit jobs to utilize the plugin and configure potential a rouge endpoint via which it was possible to control response for certain request which could be injected with XXE payloads leading to XXE while processing the response data

CVE-2023-21448
Samsung Cloud Cloud
5.7
MEDIUM
EPSS
0.1%
2023 CWE-22 1 PoC

Path traversal vulnerability in Samsung Cloud prior to version 5.3.0.32 allows attacker to access specific png file.

CVE-2023-5104
nocodb/nocodb General
5.7
MEDIUM
EPSS
0.8%
2023 CWE-20 1 PoC

Improper Input Validation in GitHub repository nocodb/nocodb prior to 0.96.0.

CVE-2023-1178
GitLab DevOps
5.7
MEDIUM
EPSS
2.5%
2023 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source code or installation packages are pulled from a tag or from a release containing a ref to another commit.

CVE-2023-6146
Qualysguard Web
5.7
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnerability allowed a user with login access to the application to introduce XSS payload via browser details. 

CVE-2023-29681
Software Genérico Networking
5.7
MEDIUM
EPSS
0.1%
2023 3 PoCs

Cleartext Transmission in cookie:ecos_pw: in Tenda N301 v6.0, firmware v12.03.01.06_pt allows an authenticated attacker on the LAN or WLAN to intercept communications with the router and obtain the password.

CVE-2023-20523
2nd Gen EPYC General
5.7
MEDIUM
EPSS
0.1%
2023 1 PoC

TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of integrity or denial of service.

CVE-2023-0307
thorsten/phpmyfaq Web
5.7
MEDIUM
EPSS
0.8%
2023 CWE-521 1 PoC

Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

CVE-2023-21952
Business Intelligence Enterprise Edition Web Database
5.7
MEDIUM
EPSS
0.5%
2023 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessibl

CVE-2023-30731
Samsung Mobile Devices General
5.7
MEDIUM
EPSS
0.1%
2023 1 PoC

Logic error in package installation via debugger command prior to SMR Oct-2023 Release 1 allows physical attacker to install an application that has different build type.

CVE-2023-21965
Business Intelligence Enterprise Edition Web Database
5.7
MEDIUM
EPSS
0.5%
2023 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessibl

CVE-2023-7211
Router Networking
5.6
MEDIUM
EPSS
0.1%
2023 CWE-291 2 PoCs

A vulnerability was found in Uniway Router 2.0. It has been declared as critical. This vulnerability affects unknown code of the component Administrative Web Interface. The manipulation leads to reliance on ip address for authentication. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. VDB-249766 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-21983
Application Express (APEX) Web Database
5.6
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the Application Express Administration product of Oracle Application Express (component: None). Supported versions that are affected are Application Express Administration: 18.2-22.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Application Express Administration. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Application Express Administration accessible data as well as unauthorized read access to a subset of Application Express Administration a