2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-0789
thorsten/phpmyfaq Web
8.1
HIGH
EPSS
7.8%
2023 CWE-77 1 PoC

Command Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

CVE-2023-4124
answerdev/answer General
8.1
HIGH
EPSS
0.2%
2023 CWE-862 1 PoC

Missing Authorization in GitHub repository answerdev/answer prior to v1.1.1.

CVE-2023-20894
VMware vCenter Server (vCenter Server) General
8.1
HIGH
EPSS
45.9%
2023 1 PoC

The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption.

CVE-2023-45842
Buildroot General
8.1
HIGH
EPSS
0.1%
2023 CWE-494 2 PoCs

Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `mxsldr` package.

CVE-2023-0994
francoisjacquet/rosariosis General
8.1
HIGH
EPSS
0.4%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository francoisjacquet/rosariosis prior to 10.8.2.

CVE-2023-5401
Experion Server General
8.1
HIGH
EPSS
1.6%
2023 CWE-121 1 PoC

Server receiving a malformed message based on a using the specified key values can cause a stack overflow vulnerability which could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-5098
Campaign Monitor Forms by Optin Cat Web Windows
8.1
HIGH
EPSS
0.2%
2023 1 PoC

The Campaign Monitor Forms by Optin Cat WordPress plugin before 2.5.6 does not prevent users with low privileges (like subscribers) from overwriting any options on a site with the string "true", which could lead to a variety of outcomes, including DoS.

CVE-2023-1757
thorsten/phpmyfaq Web
8.1
HIGH
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2023-1760
thorsten/phpmyfaq Web
8.1
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2023-3191
nilsteampassnet/teampass Web
8.1
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

CVE-2023-21828
Hospitality Reporting and Analytics Web Database
8.1
HIGH
EPSS
0.8%
2023 1 PoC

Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Reporting). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Hospitality Reporting and Analytics. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Reporting and Analytics accessible data as well as unauthorized access to critical data or complete acce

CVE-2023-4395
cockpit-hq/cockpit Web
8.1
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

CVE-2023-0441
Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery Web Windows
8.1
HIGH
EPSS
0.4%
2023 1 PoC

The Gallery Blocks with Lightbox WordPress plugin before 3.0.8 has an AJAX endpoint that can be accessed by any authenticated users, such as subscriber. The callback function allows numerous actions, the most serious one being reading and updating the WordPress options which could be used to enable registration with a default administrator user role.

CVE-2023-45839
Buildroot General
8.1
HIGH
EPSS
0.1%
2023 CWE-494 2 PoCs

Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `aufs-util` package.

CVE-2023-52043
Software Genérico General
8.1
HIGH
EPSS
0.1%
2023 1 PoC

An issue in D-Link COVR 1100, 1102, 1103 AC1200 Dual-Band Whole-Home Mesh Wi-Fi System (Hardware Rev B1) truncates Wireless Access Point Passwords (WPA-PSK) allowing an attacker to gain unauthorized network access via weak authentication controls.

CVE-2023-43608
Buildroot General
8.1
HIGH
EPSS
0.1%
2023 CWE-494 2 PoCs

A data integrity vulnerability exists in the BR_NO_CHECK_HASH_FOR functionality of Buildroot 2023.08.1 and dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.

CVE-2023-5355
Awesome Support Web Windows
8.1
HIGH
EPSS
0.2%
2023 1 PoC

The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server.

CVE-2023-40464
ALEOS General
8.1
HIGH
EPSS
0.0%
2023 CWE-321 1 PoC

Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An attacker with access to these items could potentially perform a man in the middle attack between the ACEManager client and ACEManager server.

CVE-2023-3615
Mattermost iOS app General
8.1
HIGH
EPSS
0.3%
2023 CWE-295 1 PoC

Mattermost iOS app fails to properly validate the server certificate while initializing the TLS connection allowing a network attacker to intercept the WebSockets connection.

CVE-2023-47257
Software Genérico General
8.1
HIGH
EPSS
6.4%
2023 1 PoC

ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.