5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-6263
NxCloud Cloud
8.3
HIGH
EPSS
0.2%
2023 CWE-290 1 PoC

An issue was discovered by IPVM team in Network Optix NxCloud before 23.1.0.40440. It was possible to add a fake VMS server to NxCloud by using the exact identification of a legitimate VMS server. As result, it was possible to retrieve authorization headers from legitimate users when the legitimate client connects to the fake VMS server.

CVE-2023-40284
Software Genérico Web
8.3
HIGH
EPSS
0.7%
2023 1 PoC

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

CVE-2023-0794
thorsten/phpmyfaq Web
8.3
HIGH
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

CVE-2023-1887
thorsten/phpmyfaq Web
8.3
HIGH
EPSS
0.3%
2023 CWE-840 1 PoC

Business Logic Errors in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2023-4433
cockpit-hq/cockpit Web
8.3
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

CVE-2023-28601
Zoom for Windows Client Windows
8.3
HIGH
EPSS
0.3%
2023 CWE-358 1 PoC

Zoom for Windows clients prior to 5.14.0 contain an improper restriction of operations within the bounds of a memory buffer vulnerability. A malicious user may alter protected Zoom Client memory buffer potentially causing integrity issues within the Zoom Client.

CVE-2023-40286
Software Genérico Web
8.3
HIGH
EPSS
0.7%
2023 1 PoC

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

CVE-2023-5319
thorsten/phpmyfaq Web
8.3
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.18.

CVE-2023-1880
thorsten/phpmyfaq Web ⚡ nuclei
8.3
HIGH
EPSS
14.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2023-3243
BCM-WEB General
8.3
HIGH
EPSS
0.1%
2023 CWE-290 1 PoC

** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an authenticating hash and utilize it to create new sessions. The hash is also a poorly salted MD5 hash, which could result in a successful brute force password attack. Impacted product is BCM-WEB version 3.3.X. Recommended fix: Upgrade to a supported product such as Alerton ACM.] Out of an abundance of caution, this CVE ID is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded. 

CVE-2023-1892
sidekiq/sidekiq Web ⚡ nuclei
8.3
HIGH
EPSS
72.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.

CVE-2023-32226
Sysaid General
8.3
HIGH
EPSS
0.1%
2023 CWE-552 1 PoC

Sysaid - CWE-552: Files or Directories Accessible to External Parties -  Authenticated users may exfiltrate files from the server via an unspecified method.

CVE-2023-33244
Software Genérico Web
8.2
HIGH
EPSS
0.1%
2023 1 PoC

Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an embedded web page.

CVE-2023-30969
com.palantir.tiles:tiles Web
8.2
HIGH
EPSS
0.3%
2023 CWE-284 1 PoC

The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authentication/authorization on all the endpoints.

CVE-2023-21499
Samsung Mobile Devices General
8.2
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

Out-of-bounds write vulnerability in TA_Communication_mpos_encrypt_pin in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to execute arbitrary code.

CVE-2023-0975
Trellix Agent General
8.2
HIGH
EPSS
0.0%
2023 CWE-281 1 PoC

A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace one of the Agent’s executables before it can be executed. This allows the user to elevate their permissions.

CVE-2023-24000
GamiPress Database ⚡ nuclei
8.2
HIGH
EPSS
21.2%
2023 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GamiPress gamipress allows SQL Injection.This issue affects GamiPress: from n/a through 2.5.7.

CVE-2023-31414
Kibana Web
8.2
HIGH
EPSS
0.4%
2023 CWE-94 1 PoC

Kibana versions 8.0.0 through 8.7.0 contain an arbitrary code execution flaw. An attacker with write access to Kibana yaml or env configuration could add a specific payload that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process.

CVE-2023-41652
RSVPMaker Database
8.2
HIGH
EPSS
3.1%
2023 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker rsvpmaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 10.6.6.

CVE-2023-22098
VM VirtualBox Database
8.2
HIGH
EPSS
4.0%
2023 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: Only applicable to 7.0.x platform. CVSS 3.1 Base Score 8.2