5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-29185
NetWeaver AS for ABAP (Business Server Pages) General
5.3
MEDIUM
EPSS
0.5%
2023 CWE-400 1 PoC

SAP NetWeaver AS for ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an attacker authenticated as a non-administrative user to craft a request with certain parameters in certain circumstances which can consume the server's resources sufficiently to make it unavailable over the network without any user interaction.

CVE-2023-6401
NotePad++ General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-427 1 PoC

A vulnerability classified as problematic was found in NotePad++ up to 8.1. Affected by this vulnerability is an unknown functionality of the file dbghelp.exe. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The identifier VDB-246421 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-5612
GitLab DevOps
5.3
MEDIUM
EPSS
25.6%
2023 CWE-862 2 PoCs

An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.

CVE-2023-49927
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123, Exynos Modem 5300. The baseband software does not properly check format types specified by the RRC. This can lead to a lack of encryption.

CVE-2023-25848
ArcGIS Enterprise Server General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-319 1 PoC

ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a crafted query that may result in a low severity information disclosure issue. The information disclosed is limited to a single attribute in a database connection string. No business data is disclosed.

CVE-2023-4512
Wireshark General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-674 1 PoC

CBOR dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file

CVE-2023-6375
Court Case Management Plus General
5.3
MEDIUM
EPSS
0.8%
2023 CWE-552 1 PoC

Tyler Technologies Court Case Management Plus may store backups in a location that can be accessed by a remote, unauthenticated attacker. Backups may contain sensitive information such as database credentials.

CVE-2023-6353
Civil and Criminal Electronic Filing General
5.3
MEDIUM
EPSS
1.6%
2023 CWE-287 1 PoC

Tyler Technologies Civil and Criminal Electronic Filing allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the Upload.aspx 'enky' parameter.

CVE-2023-21825
iSupplier Portal Web Database
5.3
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Supplier Management). Supported versions that are affected are 12.2.6-12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupplier Portal. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle iSupplier Portal accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2023-21916
PeopleSoft Enterprise PT PeopleTools Web Database
5.3
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Web Server). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2023-0311
thorsten/phpmyfaq Web
5.3
MEDIUM
EPSS
1.4%
2023 CWE-287 1 PoC

Improper Authentication in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

CVE-2023-30458
Software Genérico General
5.3
MEDIUM
EPSS
0.5%
2023 3 PoCs

A username enumeration issue was discovered in Medicine Tracker System 1.0. The login functionality allows a malicious user to guess a valid username due to a different response time from invalid usernames. When one enters a valid username, the response time increases depending on the length of the supplied password.

CVE-2023-6001
YugabyteDB Anywhere DevOps
5.3
MEDIUM
EPSS
0.2%
2023 CWE-200 1 PoC

Prometheus metrics are available without authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment.

CVE-2023-20566
3rd Gen AMD EPYC™ Processors General
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.

CVE-2023-20532
2nd Gen EPYC General
5.3
MEDIUM
EPSS
0.4%
2023 1 PoC

Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.

CVE-2023-7199
Relevanssi Web Windows
5.3
MEDIUM
EPSS
0.4%
2023 1 PoC

The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and private posts via a crafted request

CVE-2023-7270
Office General
5.3
MEDIUM
EPSS
0.1%
2023 2 PoCs

An issue was discovered in SoftMaker Office 2024 / NX before revision 1214 and SoftMaker FreeOffice 2014 before revision 1215. FreeOffice 2021 is also affected, but won't be fixed. The SoftMaker Office and FreeOffice MSI installer files were found to produce a visible conhost.exe window running as the SYSTEM user when using the repair function of msiexec.exe. This allows a local, low-privileged attacker to use a chain of actions, to open a fully functional cmd.exe with the privileges of the SYSTEM user.

CVE-2023-5845
Simple Social Media Share Buttons Web Windows
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Simple Social Media Share Buttons WordPress plugin before 5.1.1 leaks password-protected post content to unauthenticated visitors in some meta tags

CVE-2023-26117
angular General
5.3
MEDIUM
EPSS
0.3%
2023 CWE-1333 4 PoCs

Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.

CVE-2023-31296
Software Genérico General
5.3
MEDIUM
EPSS
0.2%
2023 1 PoC

CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows attackers to obtain sensitive information via the User Name field.