5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-26067
Software Genérico General ⚡ nuclei
8.1
HIGH
EPSS
93.0%
2023 2 PoCs

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).

CVE-2023-0994
francoisjacquet/rosariosis General
8.1
HIGH
EPSS
0.4%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository francoisjacquet/rosariosis prior to 10.8.2.

CVE-2023-23567
ImageGear General
8.1
HIGH
EPSS
0.2%
2023 CWE-119 1 PoC

A heap-based buffer overflow vulnerability exists in the CreateDIBfromPict functionality of Accusoft ImageGear 20.1. A specially crafted file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-45838
Buildroot General
8.1
HIGH
EPSS
0.1%
2023 CWE-494 2 PoCs

Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `aufs` package.

CVE-2023-3084
nilsteampassnet/teampass Web
8.1
HIGH
EPSS
0.5%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

CVE-2023-23467
Media Control Panel Web
8.1
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Media CP Media Control Panel latest version. Reflected XSS possible through unspecified endpoint.

CVE-2023-37910
xwiki-platform General
8.1
HIGH
EPSS
0.6%
2023 CWE-862 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with the introduction of attachment move support in version 14.0-rc-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, an attacker with edit access on any document (can be the user profile which is editable by default) can move any attachment of any other document to this attacker-controlled document. This allows the attacker to access and possibly publish any attachment of which the name is known, regardless if the attacker has view or edit rights on the source document of th

CVE-2023-5397
Experion Server General
8.1
HIGH
EPSS
0.3%
2023 CWE-20 1 PoC

Server receiving a malformed message to create a new connection could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-0441
Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery Web Windows
8.1
HIGH
EPSS
0.4%
2023 1 PoC

The Gallery Blocks with Lightbox WordPress plugin before 3.0.8 has an AJAX endpoint that can be accessed by any authenticated users, such as subscriber. The callback function allows numerous actions, the most serious one being reading and updating the WordPress options which could be used to enable registration with a default administrator user role.

CVE-2023-25734
Firefox Windows
8.1
HIGH
EPSS
0.2%
2023 2 PoCs

After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVE-2023-26984
Software Genérico General
8.1
HIGH
EPSS
0.8%
2023 1 PoC

An issue in the password reset function of Peppermint v0.2.4 allows attackers to access the emails and passwords of the Tickets page via a crafted request.

CVE-2023-31242
OAS Platform General
8.1
HIGH
EPSS
0.0%
2023 CWE-284 1 PoC

An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially-crafted series of network requests can lead to arbitrary authentication. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-22018
VM VirtualBox Database Windows
8.1
HIGH
EPSS
0.8%
2023 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.46 and Prior to 7.0.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via RDP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2023-29325
Windows 10 Version 1809 Windows
8.1
HIGH
EPSS
22.1%
2023 CWE-416 2 PoCs

Windows OLE Remote Code Execution Vulnerability

CVE-2023-1104
flatpressblog/flatpress Web
8.1
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2023-50807
Software Genérico General
8.1
HIGH
EPSS
0.3%
2023 2 PoCs

A vulnerability was discovered in Samsung Wearable Processor and Modems with versions Exynos 9110, Exynos Modem 5123, Exynos Modem 5300 that allows an out-of-bounds write in the heap in 2G (no auth).

CVE-2023-23464
Media Control Panel General
8.1
HIGH
EPSS
0.2%
2023 1 PoC

Media CP Media Control Panel latest version. A Permissive Flash Cross-domain Policy may allow information disclosure.

CVE-2023-30729
Samsung Email General
8.1
HIGH
EPSS
0.3%
2023 1 PoC

Improper Certificate Validation in Samsung Email prior to version 6.1.82.0 allows remote attacker to intercept the network traffic including sensitive information.

CVE-2023-34217
TN-5900 Series General
8.1
HIGH
EPSS
0.2%
2023 CWE-22 1 PoC

TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability stems from insufficient input validation in the certificate-delete function, which could potentially allow malicious users to delete arbitrary files.

CVE-2023-40463
ALEOS General
8.1
HIGH
EPSS
0.0%
2023 CWE-798 1 PoC

When configured in debugging mode by an authenticated user with administrative privileges, ALEOS 4.16 and earlier store the SHA512 hash of the common root password for that version in a directory accessible to a user with root privileges or equivalent access.