5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-2840
gpac/gpac General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2.

CVE-2023-6444
Seriously Simple Podcasting Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
61.4%
2023 2 PoCs

The Seriously Simple Podcasting WordPress plugin before 3.0.0 discloses the Podcast owner's email address (which by default is the admin email address) via an unauthenticated crafted request.

CVE-2023-3398
jgraph/drawio General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

Denial of Service in GitHub repository jgraph/drawio prior to 18.1.3.

CVE-2023-6376
court document management software General
5.3
MEDIUM
EPSS
1.0%
2023 CWE-330 1 PoC

Henschen & Associates court document management software does not sufficiently randomize file names of cached documents, allowing a remote, unauthenticated attacker to access restricted documents.

CVE-2023-3553
nilsteampassnet/teampass General
5.3
MEDIUM
EPSS
0.6%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

CVE-2023-36847
🔥 KEV Junos OS Web Networking
5.3
MEDIUM
EPSS
94.1%
2023 CWE-306 1 PoC

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities. This issue affects Juniper Networks Junos OS on EX Series: * All versions prior to 20.4R3-S8; * 21.1 versions

CVE-2023-29922
Software Genérico General ⚡ nuclei
5.3
MEDIUM
EPSS
91.2%
2023 1 PoC

PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create user/save interface.

CVE-2023-6759
IceCMS Web
5.3
MEDIUM
EPSS
0.2%
2023 CWE-837 1 PoC

A vulnerability classified as problematic has been found in Thecosy IceCMS 2.0.1. This affects an unknown part of the file /WebResource/resource of the component Love Handler. The manipulation leads to improper enforcement of a single, unique action. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-247887.

CVE-2023-0029
RE708 General
5.3
MEDIUM
EPSS
0.5%
2023 CWE-404 1 PoC

A vulnerability was found in Multilaser RE708 RE1200R4GC-2T2R-V3_v3411b_MUL029B. It has been rated as problematic. This issue affects some unknown processing of the component Telnet Service. The manipulation leads to denial of service. The attack may be initiated remotely. The identifier VDB-217169 was assigned to this vulnerability.

CVE-2023-26103
deno General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-1333 1 PoC

Versions of the package deno before 1.31.0 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the upgradeWebSocket function, which contains regexes in the form of /s*,s*/, used for splitting the Connection/Upgrade header. A specially crafted Connection/Upgrade header can be used to significantly slow down a web socket server.

CVE-2023-5969
Mattermost Web
5.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially crafted request to /api/v4/redirect_location, to fill up the memory due to caching large items.

CVE-2023-4631
DoLogin Security Web Windows
5.3
MEDIUM
EPSS
1.7%
2023 2 PoCs

The DoLogin Security WordPress plugin before 3.7 uses headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing.

CVE-2023-1646
Malware Fighter General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-121 1 PoC

A vulnerability was found in IObit Malware Fighter 9.4.0.776. It has been declared as critical. This vulnerability affects the function 0x8018E000/0x8018E004 in the library IMFCameraProtect.sys of the component IOCTL Handler. The manipulation leads to stack-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. VDB-224026 is the identifier assigned to this vulnerability.

CVE-2023-51062
Software Genérico Windows
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0 allows attackers to disclose the SMB Log contents via executing a crafted command.

CVE-2023-21939
Java SE JDK and JRE Web Database
5.3
MEDIUM
EPSS
2.1%
2023 2 PoCs

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition

CVE-2023-21486
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-926 1 PoC

Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.

CVE-2023-3817
OpenSSL General
5.3
MEDIUM
EPSS
0.3%
2023 CWE-606 1 PoC

Issue summary: Checking excessively long DH keys or parameters may be very slow. Impact summary: Applications that use the functions DH_check(), DH_check_ex() or EVP_PKEY_param_check() to check a DH key or DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial of Service. The function DH_check() performs various checks on DH parameters. After fixing CVE-2023-3446 it was discovered that a large q parameter value can also trigger an overly long computation during some of these checks. A

CVE-2023-22232
Connect General ⚡ nuclei
5.3
MEDIUM
EPSS
88.4%
2023 CWE-284 1 PoC

Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the integrity of a minor feature. Exploitation of this issue does not require user interaction.

CVE-2023-28968
Junos OS Networking
5.3
MEDIUM
EPSS
0.5%
2023 CWE-1325 1 PoC

An Improperly Controlled Sequential Memory Allocation vulnerability in the Juniper Networks Deep Packet Inspection-Decoder (JDPI-Decoder) Application Signature component of Junos OS's AppID service on SRX Series devices will stop the JDPI-Decoder from identifying dynamic application traffic, allowing an unauthenticated network-based attacker to send traffic to the target device using the JDPI-Decoder, designed to inspect dynamic application traffic and take action upon this traffic, to instead begin to not take action and to pass the traffic through. An example session can be seen by running t

CVE-2023-3431
plantuml/plantuml General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.