5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-21835
Java SE JDK and JRE Database
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.17, 17.0.5, 19.0.1; Oracle GraalVM Enterprise Edition: 20.3.8, 21.3.4 and 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via DTLS to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Editio

CVE-2023-3932
GitLab DevOps
5.3
MEDIUM
EPSS
0.1%
2023 CWE-286 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies.

CVE-2023-21942
Hyperion Essbase Web Database
5.3
MEDIUM
EPSS
0.5%
2023 1 PoC

Vulnerability in Oracle Essbase (component: Security and Provisioning). The supported version that is affected is 21.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Essbase. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Essbase accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).

CVE-2023-48957
Software Genérico Networking
5.3
MEDIUM
EPSS
0.0%
2023 2 PoCs

PureVPN Linux client 2.0.2-Productions fails to properly handle DNS queries, allowing them to bypass the VPN tunnel and be sent directly to the ISP or default DNS servers.

CVE-2023-34040
Spring For Apache Kafka DevOps Web
5.3
MEDIUM
EPSS
21.4%
2023 CWE-502 4 PoCs

In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Specifically, an application is vulnerable when all of the following are true: * The user does not configure an ErrorHandlingDeserializer for the key and/or value of the record * The user explicitly sets container properties checkDeserExWhenKeyNull and/or checkDeserExWhenValueNull container pro

CVE-2023-30858
emoji General
5.3
MEDIUM
EPSS
0.6%
2023 CWE-1333 1 PoC

The Denosaurs emoji package provides emojis for dinosaurs. Starting in version 0.1.0 and prior to version 0.3.0, the reTrimSpace regex has 2nd degree polynomial inefficiency, leading to a delayed response given a big payload. The issue has been patched in 0.3.0. As a workaround, avoid using the `replace`, `unemojify`, or `strip` functions.

CVE-2023-21485
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-926 1 PoC

Improper export of android application components vulnerability in VideoPreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.

CVE-2023-6343
Court Case Management Plus General
5.3
MEDIUM
EPSS
1.1%
2023 CWE-287 1 PoC

Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate and access sensitive files using the tiffserver/tssp.aspx 'FN' and 'PN' parameters. This behavior is related to the use of a deprecated version of Aquaforest TIFF Server, possibly 2.x. The vulnerable Aquaforest TIFF Server feature was removed on or around 2023-11-01. Insecure configuration issues in Aquaforest TIFF Server are identified separately as CVE-2023-6352. CVE-2023-6343 is similar to CVE-2020-9323. CVE-2023-6343 is related to or partially caused by CVE-2023-6352.

CVE-2023-1679
DriverGenius General
5.3
MEDIUM
EPSS
0.4%
2023 CWE-119 2 PoCs

A vulnerability classified as critical was found in DriverGenius 9.70.0.346. This vulnerability affects the function 0x9C406104/0x9C40A108 in the library mydrivers64.sys of the component IOCTL Handler. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224236.

CVE-2023-37008
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contain a buffer overflow in the ASN.1 deserialization function of the S1AP handler. This buffer overflow causes type confusion in decoded fields, leading to invalid parsing and freeing of memory. An attacker may use this to crash an MME or potentially execute code in certain circumstances.

CVE-2023-32492
PowerScale OneFS General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-276 1 PoC

Dell PowerScale OneFS 9.5.0.x contains an incorrect default permissions vulnerability. A low-privileged local attacker could potentially exploit this vulnerability, leading to information disclosure or allowing to modify files.

CVE-2023-27268
NetWeaver AS Java (Object Analyzing Service) Web
5.3
MEDIUM
EPSS
0.4%
2023 CWE-284 1 PoC

SAP NetWeaver AS Java (Object Analyzing Service) - version 7.50, does not perform necessary authorization checks, allowing an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to access but not modify server settings and data with no effect on availability., resulting in escalation of privileges.

CVE-2023-36539
Zoom clients General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-200 1 PoC

Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.

CVE-2023-5514
eSOMS General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-209 1 PoC

The response messages received from the eSOMS report generation using certain parameter queries with full file path can be abused for enumerating the local file system structure.

CVE-2023-5515
eSOMS General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-200 1 PoC

The responses for web queries with certain parameters disclose internal path of resources. This information can be used to learn internal structure of the application and to further plot attacks against web servers and deployed web applications.

CVE-2023-45209
Smart Reader Web
5.3
MEDIUM
EPSS
0.5%
2023 CWE-284 2 PoCs

An information disclosure vulnerability exists in the web interface /cgi-bin/download_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

CVE-2023-23545
T&D Corporation and ESPEC MIC CORP. data logger products General
5.3
MEDIUM
EPSS
0.4%
2023 1 PoC

Missing authentication for critical function exists in T&D Corporation and ESPEC MIC CORP. data logger products, which may allow a remote unauthenticated attacker to alter the product settings without authentication. Affected products and versions are as follows: T&D Corporation data logger products (TR-71W/72W all firmware versions, RTR-5W all firmware versions, WDR-7 all firmware versions, WDR-3 all firmware versions, and WS-2 all firmware versions), and ESPEC MIC CORP. data logger products (RT-12N/RS-12N all firmware versions, RT-22BN all firmware versions, and TEU-12N all firmware versions

CVE-2023-6592
FastDup Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
4.4%
2023 2 PoCs

The FastDup WordPress plugin before 2.2 does not prevent directory listing in sensitive directories containing export files.

CVE-2023-51393
Ember ZNet SDK General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-770 1 PoC

Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v7.4.0.0 (delivered as part of Silicon Labs Gecko SDK v4.4.0) which may enable attackers to trigger a bus fault and crash of the device, requiring a reboot in order to rejoin the network.