2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-29051
OX App Suite Web
8.1
HIGH
EPSS
0.2%
2023 CWE-284 1 PoC

User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature by default was not effective in this case. Unauthorized users could discover and modify application state, including objects related to other users and contexts. We now make sure that the switch to disable user-generated templates by default works as intended and will remove the feature in future generations of the product. No publicly available exploits are known.

CVE-2023-3531
nilsteampassnet/teampass Web
8.1
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

CVE-2023-32284
ImageGear General
8.1
HIGH
EPSS
0.3%
2023 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the tiff_planar_adobe functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-4124
answerdev/answer General
8.1
HIGH
EPSS
0.2%
2023 CWE-862 1 PoC

Missing Authorization in GitHub repository answerdev/answer prior to v1.1.1.

CVE-2023-3314
Enterprise Security Manager General
8.1
HIGH
EPSS
0.6%
2023 CWE-78 1 PoC

A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands used to control the process execution of the .zip application allows an authorized user to obtain control of the .zip application to execute arbitrary commands or obtain elevation of system privileges.

CVE-2023-23567
ImageGear General
8.1
HIGH
EPSS
0.2%
2023 CWE-119 1 PoC

A heap-based buffer overflow vulnerability exists in the CreateDIBfromPict functionality of Accusoft ImageGear 20.1. A specially crafted file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-40463
ALEOS General
8.1
HIGH
EPSS
0.0%
2023 CWE-798 1 PoC

When configured in debugging mode by an authenticated user with administrative privileges, ALEOS 4.16 and earlier store the SHA512 hash of the common root password for that version in a directory accessible to a user with root privileges or equivalent access.

CVE-2023-5403
Experion Server General
8.1
HIGH
EPSS
1.0%
2023 CWE-121 1 PoC

Server hostname translation to IP address manipulation which could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-34998
OAS Platform General
8.1
HIGH
EPSS
0.0%
2023 CWE-319 1 PoC

An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary authentication. An attacker can sniff network traffic to trigger this vulnerability.

CVE-2023-46725
foodcoopshop Web
8.1
HIGH
EPSS
0.2%
2023 CWE-918 1 PoC

FoodCoopShop is open source software for food coops and local shops. Versions starting with 3.2.0 prior to 3.6.1 are vulnerable to server-side request forgery. In the Network module, a manufacturer account can use the `/api/updateProducts.json` endpoint to make the server send a request to an arbitrary host. This means that the server can be used as a proxy into the internal network where the server is. Furthermore, the checks on a valid image are not adequate, leading to a time of check time of use issue. For example, by using a custom server that returns 200 on HEAD requests, then return a v

CVE-2023-5395
Experion Server General
8.1
HIGH
EPSS
1.2%
2023 CWE-121 1 PoC

Server receiving a malformed message that uses the hostname in an internal table may cause a stack overflow resulting in possible remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-4899
mintplex-labs/anything-llm Database
8.1
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.

CVE-2023-4235
ofono General
8.1
HIGH
EPSS
0.1%
2023 CWE-119 1 PoC

A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it was forgotten in decode_deliver_report().

CVE-2023-20894
VMware vCenter Server (vCenter Server) General
8.1
HIGH
EPSS
45.9%
2023 1 PoC

The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption.

CVE-2023-31242
OAS Platform General
8.1
HIGH
EPSS
0.0%
2023 CWE-284 1 PoC

An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially-crafted series of network requests can lead to arbitrary authentication. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-45842
Buildroot General
8.1
HIGH
EPSS
0.1%
2023 CWE-494 2 PoCs

Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `mxsldr` package.

CVE-2023-0994
francoisjacquet/rosariosis General
8.1
HIGH
EPSS
0.4%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository francoisjacquet/rosariosis prior to 10.8.2.

CVE-2023-5355
Awesome Support Web Windows
8.1
HIGH
EPSS
0.2%
2023 1 PoC

The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server.

CVE-2023-5098
Campaign Monitor Forms by Optin Cat Web Windows
8.1
HIGH
EPSS
0.2%
2023 1 PoC

The Campaign Monitor Forms by Optin Cat WordPress plugin before 2.5.6 does not prevent users with low privileges (like subscribers) from overwriting any options on a site with the string "true", which could lead to a variety of outcomes, including DoS.

CVE-2023-1757
thorsten/phpmyfaq Web
8.1
HIGH
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.