7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-5133
user-activity-log-pro Web Windows
7.5
HIGH
EPSS
0.1%
2023 1 PoC

This user-activity-log-pro WordPress plugin before 2.3.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to hide the source of malicious traffic.

CVE-2023-22435
Experion Server General
7.5
HIGH
EPSS
0.1%
2023 CWE-697 1 PoC

Experion server may experience a DoS due to a stack overflow when handling a specially crafted message.

CVE-2023-52285
Software Genérico Web Database
7.5
HIGH
EPSS
0.1%
2023 1 PoC

ExamSys 9150244 allows SQL Injection via the /Support/action/Pages.php s_score2 parameter.

CVE-2023-29723
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

The Glitter Unicorn Wallpaper app for Android 7.0 thru 8.0 allows unauthorized applications to actively request permission to insert data into the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the application is opened. By injecting data, the attacker can force the application to load malicious image URLs and display them in the UI. As the amount of data increases, it will eventually cause the application to trigger an OOM error and crash, resulting in a persistent denial of service attack.

CVE-2023-31726
Software Genérico General
7.5
HIGH
EPSS
2.1%
2023 2 PoCs

AList 3.15.1 is vulnerable to Incorrect Access Control, which can be exploited by attackers to obtain sensitive information.

CVE-2023-31595
Software Genérico General
7.5
HIGH
EPSS
0.5%
2023 1 PoC

IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via unauthenticated port access.

CVE-2023-29517
xwiki-platform Web
7.5
HIGH
EPSS
0.4%
2023 CWE-200 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The office document viewer macro was allowing anyone to see any file content from the hosting server, provided that the office server was connected and depending on the permissions of the user running the servlet engine (e.g. tomcat) running XWiki. The same vulnerability also allowed to perform internal requests to resources from the hosting server. The problem has been patched in XWiki 13.10.11, 14.10.1, 14.4.8, 15.0-rc-1. Users are advised to upgrade. It might be possible to workaround th

CVE-2023-26130
yhirose/cpp-httplib Web
7.5
HIGH
EPSS
0.2%
2023 CWE-93 2 PoCs

Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type header in the HTTP .Patch, .Post, .Put and .Delete requests. This can lead to logical errors and other misbehaviors. **Note:** This issue is present due to an incomplete fix for [CVE-2020-11709](https://security.snyk.io/vuln/SNYK-UNMANAGED-YHIROSECPPHTTPLIB-2366507).

CVE-2023-5245
Software Genérico General
7.5
HIGH
EPSS
0.4%
2023 CWE-22 1 PoC

FileUtil.extract() enumerates all zip file entries and extracts each file without validating whether file paths in the archive are outside the intended directory. When creating an instance of TensorflowModel using the saved_model format and an exported tensorflow model, the apply() function invokes the vulnerable implementation of FileUtil.extract(). Arbitrary file creation can directly lead to code execution

CVE-2023-20529
2nd Gen EPYC General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Insufficient bound checks in the SMU may allow an attacker to update the from/to address space to an invalid value potentially resulting in a denial of service.

CVE-2023-49338
Software Genérico General
7.5
HIGH
EPSS
0.4%
2023 2 PoCs

Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.

CVE-2023-1718
Bitrix24 Web
7.5
HIGH
EPSS
49.7%
2023 CWE-835 1 PoC

Improper file stream access in /desktop_app/file.ajax.php?action=uploadfile in Bitrix24 22.0.300 allows unauthenticated remote attackers to cause denial-of-service via a crafted "tmp_url".

CVE-2023-47117
label-studio General ⚡ nuclei
7.5
HIGH
EPSS
65.8%
2023 CWE-200 0 PoCs

Label Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. In addition, Label Studio had a hard coded secret key that an attacker can use to forge a session token

CVE-2023-50387
Software Genérico General
7.5
HIGH
EPSS
52.0%
2023 2 PoCs

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.

CVE-2023-3604
Change WP Admin Login Web Windows
7.5
HIGH
EPSS
0.2%
2023 1 PoC

The Change WP Admin Login WordPress plugin before 1.1.4 discloses the URL of the hidden login page when accessing a crafted URL, bypassing the protection offered.

CVE-2023-0678
phpipam/phpipam Web ⚡ nuclei
7.5
HIGH
EPSS
67.6%
2023 CWE-862 0 PoCs

Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.

CVE-2023-1874
WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards Web Windows
7.5
HIGH
EPSS
5.5%
2023 CWE-266 2 PoCs

The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.3.7. This is due to a lack of authorization checks on the multiple_roles_update function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wpda_role[]' parameter during a profile update. This requires the 'Enable role management' setting to be enabled for the site.

CVE-2023-25368
Software Genérico General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS is vulnerable to Incorrect Access Control. An unauthenticated attacker can overwrite firmnware.

CVE-2023-28432
🔥 KEV minio Cloud ⚡ nuclei
7.5
HIGH
EPSS
94.0%
2023 CWE-200 24 PoCs

Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY` and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z.

CVE-2023-30999
Security Verify Access Appliance DevOps
7.5
HIGH
EPSS
0.1%
2023 CWE-400 1 PoC

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 254651.