2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-26597
C300 General
7.5
HIGH
EPSS
0.1%
2023 CWE-400 1 PoC

Controller DoS due to buffer overflow in the handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-26925
Software Genérico General
7.5
HIGH
EPSS
0.9%
2023 2 PoCs

An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-882 1.30. A specially crafted network request can lead to the disclosure of sensitive information.

CVE-2023-42490
v3.0.6433.1964 General
7.5
HIGH
EPSS
0.2%
2023 CWE-200 1 PoC

EisBaer Scada - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CVE-2023-47108
opentelemetry-go-contrib General
7.5
HIGH
EPSS
4.3%
2023 CWE-770 1 PoC

OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. Starting in version 0.37.0 and prior to version 0.46.0, the grpc Unary Server Interceptor out of the box adds labels `net.peer.sock.addr` and `net.peer.sock.port` that have unbound cardinality. It leads to the server's potential memory exhaustion when many malicious requests are sent. An attacker can easily flood the peer address and port for requests. Version 0.46.0 contains a fix for this issue. As a workaround to stop being affected, a view removing the attributes can be used. The other possibility is to

CVE-2023-22960
Software Genérico General
7.5
HIGH
EPSS
42.8%
2023 3 PoCs

Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.

CVE-2023-45854
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

A Business Logic vulnerability in Shopkit 1.0 allows an attacker to add products with negative quantities to the shopping cart via the qtd parameter in the add-to-cart function.

CVE-2023-7204
WP STAGING WordPress Backup Plugin Web Windows
7.5
HIGH
EPSS
0.2%
2023 1 PoC

The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the cloning process which provides

CVE-2023-49356
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

A stack buffer overflow vulnerability in MP3Gain v1.6.2 allows an attacker to cause a denial of service via the WriteMP3GainAPETag function at apetag.c:592.

CVE-2023-26139
underscore-keypath General
7.5
HIGH
EPSS
0.1%
2023 CWE-1321 1 PoC

Versions of the package underscore-keypath from 0.0.11 are vulnerable to Prototype Pollution via the name argument of the setProperty() function. Exploiting this vulnerability is possible due to improper input sanitization which allows the usage of arguments like “__proto__”.

CVE-2023-7269
ArtPlacer Widget Web Windows
7.5
HIGH
EPSS
0.1%
2023 1 PoC

The ArtPlacer Widget WordPress plugin before 2.21.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2023-21893
Data Provider for .NET Database Windows
7.5
HIGH
EPSS
1.1%
2023 1 PoC

Vulnerability in the Oracle Data Provider for .NET component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCPS to compromise Oracle Data Provider for .NET. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Data Provider for .NET. Note: Applies also to Database client-only on Windows platform. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability

CVE-2023-29726
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

The Call Blocker application 6.6.3 for Android incorrectly opens a key component that an attacker can use to inject large amounts of dirty data into the application's database. When the application starts, it loads the data from the database into memory. Once the attacker injects too much data, the application triggers an OOM error and crashes, resulting in a persistent denial of service.

CVE-2023-45893
Software Genérico General
7.5
HIGH
EPSS
1.0%
2023 1 PoC

An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.

CVE-2023-0215
OpenSSL Web
7.5
HIGH
EPSS
0.4%
2023 2 PoCs

The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the SMIME, CMS and PKCS7 streaming capabilities, but may also be called directly by end user applications. The function receives a BIO from the caller, prepends a new BIO_f_asn1 filter BIO onto the front of it to form a BIO chain, and then returns the new head of the BIO chain to the caller. Under certain conditions, for example if a CMS recipient public key is invalid, the new filter BIO is freed and the function returns a NULL result indica

CVE-2023-45232
edk2 General
7.5
HIGH
EPSS
0.5%
2023 CWE-835 1 PoC

EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.

CVE-2023-25264
Software Genérico General
7.5
HIGH
EPSS
0.6%
2023 1 PoC

An issue was discovered in Docmosis Tornado prior to version 2.9.5. An unauthenticated attacker can bypass the authentication check filter completely by introducing a specially crafted request with relative path segments.

CVE-2023-6383
Debug Log Manager Web Windows
7.5
HIGH
EPSS
0.6%
2023 1 PoC

The Debug Log Manager WordPress plugin before 2.3.0 contains a Directory listing vulnerability was discovered, which allows you to download the debug log without authorization and gain access to sensitive data

CVE-2023-7012
Chrome General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convinced a user to install a malicious app to potentially perform a sandbox escape via a malicious file. (Chromium security severity: Medium)

CVE-2023-26126
m.static General
7.5
HIGH
EPSS
0.3%
2023 CWE-22 1 PoC

All versions of the package m.static are vulnerable to Directory Traversal due to improper input sanitization of the path being requested via the requestFile function.

CVE-2023-20531
2nd Gen EPYC General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a denial of service.