5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-39217
Zoom SDK's General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-80 1 PoC

Improper input validation in Zoom SDK’s before 5.14.10 may allow an unauthenticated user to enable a denial of service via network access.

CVE-2023-2152
Student Study Center Desk Management System Web
5.3
MEDIUM
EPSS
0.5%
2023 CWE-73 1 PoC

A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument page leads to file inclusion. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-226273 was assigned to this vulnerability.

CVE-2023-1061
Doctors Appointment System Web Database
5.3
MEDIUM
EPSS
0.2%
2023 CWE-89 1 PoC

A vulnerability, which was classified as critical, has been found in SourceCodester Doctors Appointment System 1.0. This issue affects some unknown processing of the file /admin/edit-doc.php. The manipulation of the argument email/oldmail leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2023-21466
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.0%
2023 1 PoC

PendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023 Release 1 allows local attackers to access contentProvider without proper permission.

CVE-2023-1059
Doctors Appointment System Web Database
5.3
MEDIUM
EPSS
0.2%
2023 CWE-89 1 PoC

A vulnerability classified as critical was found in SourceCodester Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/doctors.php of the component Parameter Handler. The manipulation of the argument search/id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2023-1894
Puppet Enterprise General
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations.

CVE-2023-26147
ithewei/libhv Web
5.3
MEDIUM
EPSS
0.1%
2023 CWE-113 1 PoC

All versions of the package ithewei/libhv are vulnerable to HTTP Response Splitting when untrusted user input is used to build headers values. An attacker can add the \r\n (carriage return line feeds) characters to end the HTTP response headers and inject malicious content, like for example additional headers or new response body, leading to a potential XSS vulnerability.

CVE-2023-41811
Pandora FMS Web
5.3
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed Javascript code to be executed in the news section of the web console. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-28536
Branded Social Images General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

Missing Authorization vulnerability in Acato Branded Social Images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Branded Social Images: from n/a through 1.1.0.

CVE-2023-21971
MySQL Connectors Database
5.3
MEDIUM
EPSS
0.2%
2023 3 PoCs

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors as well as unauthorized update, insert or delete access to some of

CVE-2023-23463
DVR General
5.3
MEDIUM
EPSS
0.3%
2023 CWE-522 1 PoC

Sunell DVR, latest version, Insufficiently Protected Credentials (CWE-522) may be exposed through an unspecified request.

CVE-2023-37217
Telecom Aeonix General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-204 1 PoC

Tadiran Telecom Aeonix - CWE-204: Observable Response Discrepancy

CVE-2023-0443
AnyWhere Elementor Web Windows
5.3
MEDIUM
EPSS
0.2%
2023 1 PoC

The AnyWhere Elementor WordPress plugin before 1.2.8 discloses a Freemius Secret Key which could be used by an attacker to purchase the pro subscription using test credit card numbers without actually paying the amount. Such key has been revoked.

CVE-2023-6891
PeaZip General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-427 1 PoC

A vulnerability has been found in PeaZip 9.4.0 and classified as problematic. Affected by this vulnerability is an unknown functionality in the library dragdropfilesdll.dll of the component Library Handler. The manipulation leads to uncontrolled search path. An attack has to be approached locally. Upgrading to version 9.6.0 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-248251. NOTE: Vendor was contacted early, confirmed the existence of the flaw and immediately worked on a patched release.

CVE-2023-5678
OpenSSL General
5.3
MEDIUM
EPSS
0.5%
2023 CWE-606 2 PoCs

Issue summary: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow. Impact summary: Applications that use the functions DH_generate_key() to generate an X9.42 DH key may experience long delays. Likewise, applications that use DH_check_pub_key(), DH_check_pub_key_ex() or EVP_PKEY_public_check() to check an X9.42 DH key or X9.42 DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial of Service. While DH_check() performs all

CVE-2023-3469
thorsten/phpmyfaq Web
5.2
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.2.0-beta.2.

CVE-2023-1067
pimcore/pimcore Web
5.2
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.

CVE-2023-1789
firefly-iii/firefly-iii General
5.2
MEDIUM
EPSS
0.2%
2023 CWE-20 1 PoC

Improper Input Validation in GitHub repository firefly-iii/firefly-iii prior to 6.0.0.

CVE-2023-28600
Zoom for macOS Client General
5.2
MEDIUM
EPSS
0.1%
2023 CWE-378 1 PoC

Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to delete/replace Zoom Client files potentially causing a loss of integrity and availability to the Zoom Client.

CVE-2023-5564
froxlor/froxlor Web
5.2
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository froxlor/froxlor prior to 2.1.0-dev1.