5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-46197
Popup by Supsystic General
5.3
MEDIUM
EPSS
17.3%
2023 CWE-22 1 PoC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by Supsystic allows Relative Path Traversal.This issue affects Popup by Supsystic: from n/a through 1.10.19.

CVE-2023-0848
WNDR3700v2 General
5.3
MEDIUM
EPSS
0.5%
2023 CWE-404 1 PoC

A vulnerability was found in Netgear WNDR3700v2 1.0.1.14. It has been rated as problematic. This issue affects some unknown processing of the component Web Management Interface. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221147.

CVE-2023-0901
pixelfed/pixelfed General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pixelfed/pixelfed prior to 0.11.4.

CVE-2023-44982
Perfect Images (Manage Image Sizes, Thumbnails, Replace, Retina) General ⚡ nuclei
5.3
MEDIUM
EPSS
12.9%
2023 CWE-200 0 PoCs

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Perfect Images (Manage Image Sizes, Thumbnails, Replace, Retina).This issue affects Perfect Images (Manage Image Sizes, Thumbnails, Replace, Retina): from n/a through 6.4.5.

CVE-2023-24473
OpenImageIO General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-125 1 PoC

An information disclosure vulnerability exists in the TGAInput::read_tga2_header functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted targa file can lead to a disclosure of sensitive information. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-0493
btcpayserver/btcpayserver General
5.3
MEDIUM
EPSS
10.0%
2023 CWE-76 2 PoCs

Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.

CVE-2023-25173
containerd DevOps
5.3
MEDIUM
EPSS
0.0%
2023 CWE-863 1 PoC

containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. Downstream applications that use the containerd client library may be affected as well. This bug has be

CVE-2023-24527
NetWeaver AS Java for Deploy Service Web
5.3
MEDIUM
EPSS
0.3%
2023 CWE-306 1 PoC

SAP NetWeaver AS Java for Deploy Service - version 7.5, does not perform any access control checks for functionalities that require user identity enabling an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to access but not modify server settings and data with no effect on availability and integrity.

CVE-2023-1538
answerdev/answer General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-208 1 PoC

Observable Timing Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2023-50436
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2023 2 PoCs

An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The earliest affected version is 7.1.5.

CVE-2023-4002
GitLab DevOps
5.3
MEDIUM
EPSS
0.1%
2023 CWE-201 2 PoCs

An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for EE-licensed users to link any security policy project by its ID to projects or groups the user has access to, potentially revealing the security projects's configured security policies.

CVE-2023-30802
Net-Gen Application Firewall Web Networking
5.3
MEDIUM
EPSS
0.1%
2023 CWE-540 1 PoC

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to a source code disclosure vulnerability. A remote and unauthenticated attacker can obtain PHP source code by sending an HTTP request with an invalid Content-Length field.

CVE-2023-52699
Linux General
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

In the Linux kernel, the following vulnerability has been resolved: sysv: don't call sb_bread() with pointers_lock held syzbot is reporting sleep in atomic context in SysV filesystem [1], for sb_bread() is called with rw_spinlock held. A "write_lock(&pointers_lock) => read_lock(&pointers_lock) deadlock" bug and a "sb_bread() with write_lock(&pointers_lock)" bug were introduced by "Replace BKL for chain locking with sysvfs-private rwlock" in Linux 2.5.12. Then, "[PATCH] err1-40: sysvfs locking fix" in Linux 2.6.8 fixed the former bug by moving pointers_lock lock to the callers, but instead

CVE-2023-31416
Elastic Cloud on Kubernetes DevOps Cloud
5.3
MEDIUM
EPSS
0.2%
2023 CWE-200 1 PoC

Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment.

CVE-2023-5390
ControlEdge UOC General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-36 2 PoCs

An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC. This exploit could be used to read files from the controller that may expose limited information from the device. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-24526
NetWeaver AS Java for Classload Service General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-306 1 PoC

SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks for functionalities that require user identity, resulting in escalation of privileges. This failure has a low impact on confidentiality of the data such that an unassigned user can read non-sensitive server data.

CVE-2023-50128
Software Genérico General
5.3
MEDIUM
EPSS
0.0%
2023 1 PoC

The remote keyless system of the Hozard alarm system (alarmsystemen) v1.0 sends an identical radio frequency signal for each request, which results in an attacker being able to conduct replay attacks to bring the alarm system to a disarmed state.

CVE-2023-29489
Software Genérico Web ⚡ nuclei
5.3
MEDIUM
EPSS
92.9%
2023 20 PoCs

An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31.

CVE-2023-1106
flatpressblog/flatpress Web
5.3
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2023-5690
modoboa/modoboa Web
5.3
MEDIUM
EPSS
0.4%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.2.2.