5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-6780
glibc General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-131 4 PoCs

An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in undefined behavior. This issue affects glibc 2.37 and newer.

CVE-2023-2014
microweber/microweber Web
5.3
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository microweber/microweber prior to 1.3.3.

CVE-2023-0759
cockpit-hq/cockpit General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-268 1 PoC

Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8.

CVE-2023-26151
asyncua General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a result, the server will enter into an infinite loop and consume excessive memory.

CVE-2023-20052
Cisco Secure Endpoint Networking
5.3
MEDIUM
EPSS
4.6%
2023 CWE-611 2 PoCs

On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device. This vulnerability is due to enabling XML entity substitution that may result in XML external entity injection. An attacker could exploit this vulnerability by submitting a crafted DMG file to be scanned by ClamAV on an affected device. A successful exploit could allow the

CVE-2023-26116
angular General
5.3
MEDIUM
EPSS
0.3%
2023 CWE-1333 4 PoCs

Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.

CVE-2023-0651
FastCMS Web
5.3
MEDIUM
EPSS
0.6%
2023 CWE-434 1 PoC

A vulnerability was found in FastCMS 0.1.0. It has been classified as critical. Affected is an unknown function of the component Template Management. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2023-7252
Tickera Web Windows
5.3
MEDIUM
EPSS
0.3%
2023 1 PoC

The Tickera WordPress plugin before 3.5.2.5 does not prevent users from leaking other users' tickets.

CVE-2023-45503
Software Genérico Web Database Windows
5.3
MEDIUM
EPSS
1.8%
2023 1 PoC

SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via crafted payload to resetPassword, forgotPasswordProcess, saveUser, saveRole, deleteUser, deleteRole, deleteComment, deleteUser, allowComment, saveRole, forgotPasswordProcess, resetPassword, saveUser, addComment, saveRole, and saveUser endpoints.

CVE-2023-6341
CMS360 Web Cloud
5.3
MEDIUM
EPSS
0.9%
2023 CWE-639 1 PoC

Catalis (previously Icon Software) CMS360 allows a remote, unauthenticated attacker to view sensitive court documents by modifying document and other identifiers in URLs. The impact varies based on the intention and configuration of a specific CMS360 installation.

CVE-2023-2241
PoDoFo General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-122 1 PoC

A vulnerability, which was classified as critical, was found in PoDoFo 0.10.0. Affected is the function readXRefStreamEntry of the file PdfXRefStreamParserObject.cpp. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as 535a786f124b739e3c857529cecc29e4eeb79778. It is recommended to apply a patch to fix this issue. VDB-227226 is the identifier assigned to this vulnerability.

CVE-2023-6459
Mattermost General
5.3
MEDIUM
EPSS
0.5%
2023 CWE-200 1 PoC

Mattermost is grouping calls in the /metrics endpoint by id and reports that id in the response. Since this id is the channelID, the public /metrics endpoint is revealing channelIDs.

CVE-2023-26144
graphql General
5.3
MEDIUM
EPSS
2.1%
2023 CWE-400 1 PoC

Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the OverlappingFieldsCanBeMergedRule.ts file when parsing large queries. This vulnerability allows an attacker to degrade system performance. **Note:** It was not proven that this vulnerability can crash the process.

CVE-2023-47668
Membership Plugin – Restrict Content General
5.3
MEDIUM
EPSS
5.5%
2023 CWE-200 2 PoCs

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StellarWP Membership Plugin – Restrict Content plugin <= 3.2.7 versions.

CVE-2023-6447
EventPrime Web Windows
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id/event name.

CVE-2023-6354
Magistrate Court Case Management Plus General
5.3
MEDIUM
EPSS
1.0%
2023 CWE-287 1 PoC

Tyler Technologies Magistrate Court Case Management Plus allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the PDFViewer.aspx 'filename' parameter.

CVE-2023-37367
Software Genérico General
5.3
MEDIUM
EPSS
0.0%
2023 1 PoC

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem (Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. In the NAS Task, an improperly implemented security check for standard can disallow desired services for a while via consecutive NAS messages.

CVE-2023-2187
SCADA Data Gateway General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-306 1 PoC

On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can use this vulnerability to forcefully log out of any currently logged-in user by sending a "password change event". Furthermore, an attacker could use this vulnerability to spam the logged-in user with false events.

CVE-2023-37005
Software Genérico General
5.3
MEDIUM
EPSS
0.0%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial Context Setup Failure` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

CVE-2023-22622
Software Genérico Web Windows
5.3
MEDIUM
EPSS
8.4%
2023 3 PoCs

WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits.