5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-26222
TIBCO EBX Web
8.7
HIGH
EPSS
0.4%
2023 1 PoC

The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.22 and below, versions 6.0.13 and below and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 5.0.0 and below.

CVE-2023-53971
WebTareas Web
8.7
HIGH
EPSS
0.1%
2023 CWE-434 1 PoC

WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functionality. Attackers can upload a PHP file with arbitrary code to the /files/Messages/ directory and execute it directly through the generated file path.

CVE-2023-26498
Software Genérico General
8.6
HIGH
EPSS
5.2%
2023 1 PoC

An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos Auto T5126. Memory corruption can occur due to improper checking of the number of properties while parsing the chatroom attribute in the SDP (Session Description Protocol) module.

CVE-2023-0309
thorsten/phpmyfaq Web
8.6
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

CVE-2023-20158
Cisco Small Business Smart and Managed Switches Networking
8.6
HIGH
EPSS
0.5%
2023 CWE-120 1 PoC

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2023-20024
Cisco Small Business Smart and Managed Switches Networking
8.6
HIGH
EPSS
1.0%
2023 CWE-120 1 PoC

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2023-26496
Software Genérico General
8.6
HIGH
EPSS
5.2%
2023 1 PoC

An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T5124. Memory corruption can occur due to improper checking of the parameter length while parsing the fmtp attribute in the SDP (Session Description Protocol) module.

CVE-2023-43646
get-func-name General
8.6
HIGH
EPSS
1.4%
2023 CWE-400 1 PoC

get-func-name is a module to retrieve a function's name securely and consistently both in NodeJS and the browser. Versions prior to 2.0.1 are subject to a regular expression denial of service (redos) vulnerability which may lead to a denial of service when parsing malicious input. This vulnerability can be exploited when there is an imbalance in parentheses, which results in excessive backtracking and subsequently increases the CPU load and processing time significantly. This vulnerability can be triggered using the following input: '\t'.repeat(54773) + '\t/function/i'. This issue has been add

CVE-2023-37017
Software Genérico General
8.6
HIGH
EPSS
0.3%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `S1Setup Request` message missing a required `Global eNB ID` field to repeatedly crash the MME, resulting in denial of service.

CVE-2023-37021
Software Genérico General
8.6
HIGH
EPSS
0.3%
2023 1 PoC

Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Modification Failure` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

CVE-2023-6461
viliusle/minipaint Web
8.6
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository viliusle/minipaint prior to 4.14.0.

CVE-2023-37019
Software Genérico General
8.6
HIGH
EPSS
0.3%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `S1Setup Request` message missing a required `Supported TAs` field to repeatedly crash the MME, resulting in denial of service.

CVE-2023-0777
modoboa/modoboa General ⚡ nuclei
8.6
HIGH
EPSS
76.2%
2023 CWE-305 2 PoCs

Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4.

CVE-2023-3722
Aura Device Services General ⚡ nuclei
8.6
HIGH
EPSS
54.6%
2023 CWE-434 1 PoC

An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.

CVE-2023-20161
Cisco Small Business Smart and Managed Switches Networking
8.6
HIGH
EPSS
4.3%
2023 CWE-120 1 PoC

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2023-37023
Software Genérico General
8.6
HIGH
EPSS
0.3%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `Uplink NAS Transport` packet handler. A packet missing its `MME_UE_S1AP_ID` field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of service.

CVE-2023-45612
Ktor General
8.6
HIGH
EPSS
0.0%
2023 CWE-611 1 PoC

In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE

CVE-2023-28206
🔥 KEV iOS and iPadOS General
8.6
HIGH
EPSS
24.1%
2023 1 PoC

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1, iOS 15.7.5 and iPadOS 15.7.5, macOS Big Sur 11.7.6. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.

CVE-2023-6023
vertaai/modeldb General ⚡ nuclei
8.6
HIGH
EPSS
47.9%
2023 CWE-29 1 PoC

An attacker can read any file on the filesystem on the server hosting ModelDB through an LFI in the artifact_path URL parameter.

CVE-2023-20157
Cisco Small Business Smart and Managed Switches Networking
8.6
HIGH
EPSS
0.5%
2023 CWE-120 1 PoC

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory.