2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-53873
SyncBreeze DevOps
8.7
HIGH
EPSS
0.3%
2023 CWE-400 1 PoC

SyncBreeze 15.2.24 contains a denial of service vulnerability in the login authentication mechanism that allows attackers to crash the service. Attackers can send an oversized password parameter with repeated 'password=' values to overwhelm the login endpoint and potentially disrupt service availability.

CVE-2023-53971
WebTareas Web
8.7
HIGH
EPSS
0.1%
2023 CWE-434 1 PoC

WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functionality. Attackers can upload a PHP file with arbitrary code to the /files/Messages/ directory and execute it directly through the generated file path.

CVE-2023-20158
Cisco Small Business Smart and Managed Switches Networking
8.6
HIGH
EPSS
0.5%
2023 CWE-120 1 PoC

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2023-20024
Cisco Small Business Smart and Managed Switches Networking
8.6
HIGH
EPSS
1.0%
2023 CWE-120 1 PoC

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2023-26498
Software Genérico General
8.6
HIGH
EPSS
5.2%
2023 1 PoC

An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos Auto T5126. Memory corruption can occur due to improper checking of the number of properties while parsing the chatroom attribute in the SDP (Session Description Protocol) module.

CVE-2023-43662
ShokoServer Web Windows ⚡ nuclei
8.6
HIGH
EPSS
91.9%
2023 CWE-22 0 PoCs

ShokoServer is a media server which specializes in organizing anime. In affected versions the `/api/Image/WithPath` endpoint is accessible without authentication and is supposed to return default server images. The endpoint accepts the parameter `serverImagePath`, which is not sanitized in any way before being passed to `System.IO.File.OpenRead`, which results in an arbitrary file read. This issue may lead to an arbitrary file read which is exacerbated in the windows installer which installs the ShokoServer as administrator. Any unauthenticated attacker may be able to access sensitive informat

CVE-2023-39423
IRM Next Generation Web Database Windows
8.6
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs,  among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the currently valid sessions and impersonate a currently logged-in user.

CVE-2023-37023
Software Genérico General
8.6
HIGH
EPSS
0.3%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `Uplink NAS Transport` packet handler. A packet missing its `MME_UE_S1AP_ID` field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of service.

CVE-2023-37017
Software Genérico General
8.6
HIGH
EPSS
0.3%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `S1Setup Request` message missing a required `Global eNB ID` field to repeatedly crash the MME, resulting in denial of service.

CVE-2023-6461
viliusle/minipaint Web
8.6
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository viliusle/minipaint prior to 4.14.0.

CVE-2023-37018
Software Genérico General
8.6
HIGH
EPSS
0.3%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Capability Info Indication` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

CVE-2023-0777
modoboa/modoboa General ⚡ nuclei
8.6
HIGH
EPSS
76.2%
2023 CWE-305 2 PoCs

Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4.

CVE-2023-47105
Software Genérico General ⚡ nuclei
8.6
HIGH
EPSS
26.5%
2023 0 PoCs

exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd parameter without authentication.

CVE-2023-3722
Aura Device Services General ⚡ nuclei
8.6
HIGH
EPSS
54.6%
2023 CWE-434 1 PoC

An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.

CVE-2023-28206
🔥 KEV iOS and iPadOS General
8.6
HIGH
EPSS
24.1%
2023 1 PoC

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1, iOS 15.7.5 and iPadOS 15.7.5, macOS Big Sur 11.7.6. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.

CVE-2023-20157
Cisco Small Business Smart and Managed Switches Networking
8.6
HIGH
EPSS
0.5%
2023 CWE-120 1 PoC

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2023-45612
Ktor General
8.6
HIGH
EPSS
0.0%
2023 CWE-611 1 PoC

In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE

CVE-2023-37019
Software Genérico General
8.6
HIGH
EPSS
0.3%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `S1Setup Request` message missing a required `Supported TAs` field to repeatedly crash the MME, resulting in denial of service.

CVE-2023-20161
Cisco Small Business Smart and Managed Switches Networking
8.6
HIGH
EPSS
4.3%
2023 CWE-120 1 PoC

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2023-26496
Software Genérico General
8.6
HIGH
EPSS
5.2%
2023 1 PoC

An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T5124. Memory corruption can occur due to improper checking of the parameter length while parsing the fmtp attribute in the SDP (Session Description Protocol) module.