5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-22001
VM VirtualBox Database
4.6
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle VM VirtualBox a

CVE-2023-2943
openemr/openemr General
4.6
MEDIUM
EPSS
0.1%
2023 CWE-94 1 PoC

Code Injection in GitHub repository openemr/openemr prior to 7.0.1.

CVE-2023-30714
Samsung Mobile Devices DevOps
4.6
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper authorization vulnerability in FolderContainerDragDelegate in One UI Home prior to SMR Sep-2023 Release 1 allows physical attackers to change some settings of the folder lock.

CVE-2023-46668
Endpoint Web Database
4.6
MEDIUM
EPSS
0.3%
2023 CWE-532 1 PoC

If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the logging level is explicitly set to debug, and when Elastic Agent is simultaneously configured to collect and send those logs to Elasticsearch, then Elastic Agent API keys can be viewed in Elasticsearch in plaintext. These API keys could be used to write arbitrary data and read Elastic Endpoint user artifacts.

CVE-2023-3067
zadam/trilium Web
4.6
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.59.4.

CVE-2023-3620
amauric/tarteaucitron.js Web
4.6
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository amauric/tarteaucitron.js prior to v1.13.1.

CVE-2023-30676
Samsung Pass General
4.6
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass.

CVE-2023-3230
fossbilling/fossbilling General
4.6
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

Missing Authorization in GitHub repository fossbilling/fossbilling prior to 0.5.0.

CVE-2023-28345
Software Genérico Web Windows
4.6
MEDIUM
EPSS
0.0%
2023 2 PoCs

An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application exposes the teacher's Console password in cleartext via an API endpoint accessible from localhost. Attackers with physical access to the Teacher Console can open a web browser, navigate to the affected endpoint and obtain the teacher's password. This enables them to log into the Teacher Console and begin trivially attacking student machines.

CVE-2023-6927
Red Hat build of Keycloak 22 General
4.6
MEDIUM
EPSS
0.8%
2023 CWE-601 1 PoC

A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security patch implemented to address CVE-2023-6134.

CVE-2023-6900
DashMachine General
4.6
MEDIUM
EPSS
0.1%
2023 CWE-24 1 PoC

A vulnerability, which was classified as critical, has been found in rmountjoy92 DashMachine 0.5-4. Affected by this issue is some unknown functionality of the file /settings/delete_file. The manipulation of the argument file leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. VDB-248258 is the identifier assigned to this vulnerability.

CVE-2023-2978
Pydio Cells General
4.6
MEDIUM
EPSS
0.0%
2023 CWE-639 1 PoC

A vulnerability was found in Abstrium Pydio Cells 4.2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Change Subscription Handler. The manipulation leads to authorization bypass. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component. VDB-230210 is the identifier assigned to this vulnerability.

CVE-2023-30708
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.3%
2023 1 PoC

Improper authentication in SecSettings prior to SMR Sep-2023 Release 1 allows attacker to access Captive Portal Wi-Fi in Reactivation Lock status.

CVE-2023-0736
wallabag/wallabag Web
4.6
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository wallabag/wallabag prior to 2.5.4.

CVE-2023-22000
VM VirtualBox Database
4.6
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle VM VirtualBox a

CVE-2023-1316
osticket/osticket Web
4.5
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.

CVE-2023-23408
Azure HDInsight Web Cloud
4.5
MEDIUM
EPSS
7.6%
2023 CWE-79 1 PoC

Azure Apache Ambari Spoofing Vulnerability

CVE-2023-28096
opensips General
4.5
MEDIUM
EPSS
1.0%
2023 CWE-401 1 PoC

OpenSIPS, a Session Initiation Protocol (SIP) server implementation, has a memory leak starting in the 2.3 branch and priot to versions 3.1.8 and 3.2.5. The memory leak was detected in the function `parse_mi_request` while performing coverage-guided fuzzing. This issue can be reproduced by sending multiple requests of the form `{"jsonrpc": "2.0","method": "log_le`. This malformed message was tested against an instance of OpenSIPS via FIFO transport layer and was found to increase the memory consumption over time. To abuse this memory leak, attackers need to reach the management interface (MI)

CVE-2023-0023
Bank Account Management (Manage Banks) General
4.5
MEDIUM
EPSS
0.2%
2023 CWE-200 1 PoC

In SAP Bank Account Management (Manage Banks) application, when a user clicks a smart link to navigate to another app, personal data is shown directly in the URL. They might get captured in log files, bookmarks, and so on disclosing sensitive data of the application.

CVE-2023-33992
SAP Business Warehouse and SAP BW/4HANA General
4.5
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

The SAP BW BICS communication layer in SAP Business Warehouse and SAP BW/4HANA - version SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 730, SAP_BW 750, DW4CORE 100, DW4CORE 200, DW4CORE 300, may expose unauthorized cell values to the data response. To be able to exploit this, the user still needs authorizations on the query as well as on the keyfigure/measure level. The missing check only affects the data level.