2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-5644
WP Mail Log Web Windows
7.6
HIGH
EPSS
0.1%
2023 1 PoC

The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with the Contributor role to view and delete data that should only be accessible to Admin users.

CVE-2023-33248
Software Genérico General
7.6
HIGH
EPSS
0.7%
2023 2 PoCs

Amazon Alexa software version 8960323972 on Echo Dot 2nd generation and 3rd generation devices potentially allows attackers to deliver security-relevant commands via an audio signal between 16 and 22 kHz (often outside the range of human adult hearing). Commands at these frequencies are essentially never spoken by authorized actors, but a substantial fraction of the commands are successful.

CVE-2023-44092
Pandora FMS General
7.6
HIGH
EPSS
0.1%
2023 CWE-78 1 PoC

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Pandora FMS on all allows OS Command Injection. This vulnerability allowed to create a reverse shell and execute commands in the OS. This issue affects Pandora FMS: from 700 through <776.

CVE-2023-3552
nilsteampassnet/teampass Web
7.6
HIGH
EPSS
0.3%
2023 CWE-116 1 PoC

Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

CVE-2023-26074
Software Genérico General
7.6
HIGH
EPSS
0.8%
2023 3 PoCs

An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123.. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient parameter validation when decoding operator-defined access category definitions.

CVE-2023-0308
thorsten/phpmyfaq Web
7.6
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

CVE-2023-4003
One General
7.6
HIGH
EPSS
0.1%
2023 CWE-250 1 PoC

One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method. CWE-250: Execution with Unnecessary Privileges.

CVE-2023-3725
Zephyr General
7.6
HIGH
EPSS
0.6%
2023 CWE-120 1 PoC

Potential buffer overflow vulnerability in the Zephyr CAN bus subsystem

CVE-2023-6538
System Management Unit (SMU) General
7.6
HIGH
EPSS
5.3%
2023 CWE-285 1 PoC

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Server or combined Server+Storage administrative roles are able to access SMU configuration backup, that would normally be barred to those specific administrative roles.

CVE-2023-1238
answerdev/answer Web
7.6
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2023-4257
Zephyr General
7.6
HIGH
EPSS
0.4%
2023 CWE-120 1 PoC

Unchecked user input length in /subsys/net/l2/wifi/wifi_shell.c can cause buffer overflows.

CVE-2023-1115
pimcore/pimcore Web
7.6
HIGH
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.

CVE-2023-41788
Pandora FMS Web
7.6
HIGH
EPSS
0.1%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Pandora FMS on all allows Accessing Functionality Not Properly Constrained by ACLs. This vulnerability allows attackers to execute code via PHP file uploads. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-42571
Find My Mobile General
7.6
HIGH
EPSS
0.2%
2023 1 PoC

Abuse of remote unlock in Find My Mobile prior to version 7.3.13.4 allows physical attacker to unlock the device remotely by resetting the Samsung Account password with SMS verification when user lost the device.

CVE-2023-2534
OTRS Web
7.6
HIGH
EPSS
0.4%
2023 CWE-285 1 PoC

Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and to gain live insight into overall system usage. User IDs can easily be correlated with real names e. g. via ticket histories by any user. (Fuzzing for garnering other adjacent user/sensitive data). Subscribing to all possible push events could also lead to performance implications on the server side, depending on the size of the installation and the number of active users. (Flooding)This issue affects OTRS: from 8.0.X before 8.0.32.

CVE-2023-32741
Contact Form to Any API Web Database
7.6
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in IT Path Solutions PVT LTD Contact Form to Any API allows SQL Injection.This issue affects Contact Form to Any API: from n/a through 1.1.2.

CVE-2023-26073
Software Genérico General
7.6
HIGH
EPSS
0.8%
2023 3 PoCs

An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient parameter validation when decoding the extended emergency number list.

CVE-2023-21826
Hospitality Reporting and Analytics Web Database
7.6
HIGH
EPSS
0.6%
2023 1 PoC

Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Reporting). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Hospitality Reporting and Analytics. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality Reporting and Analytics accessible da

CVE-2023-22833
com.palantir.lime:lime2 General
7.6
HIGH
EPSS
0.1%
2023 CWE-304 1 PoC

Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that allowed authenticated users within a Foundry organization to bypass discretionary or mandatory access controls under certain circumstances.

CVE-2023-3070
tsolucio/corebos Web
7.6
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.