7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-49799
nuxt-api-party Web
7.5
HIGH
EPSS
1.4%
2023 CWE-918 1 PoC

`nuxt-api-party` is an open source module to proxy API requests. nuxt-api-party attempts to check if the user has passed an absolute URL to prevent the aforementioned attack. This has been recently changed to use the regular expression `^https?://`, however this regular expression can be bypassed by an absolute URL with leading whitespace. For example `\nhttps://whatever.com` which has a leading newline. According to the fetch specification, before a fetch is made the URL is normalized. "To normalize a byte sequence potentialValue, remove any leading and trailing HTTP whitespace bytes from pot

CVE-2023-44837
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Password parameter in the SetWanSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-43862
Software Genérico General
7.5
HIGH
EPSS
1.0%
2023 1 PoC

D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formLanguageChange function.

CVE-2023-26774
Software Genérico Web
7.5
HIGH
EPSS
0.6%
2023 3 PoCs

An issue found in Sales Tracker Management System v.1.0 allows a remote attacker to access sensitive information via sales.php component of the admin/reports endpoint.

CVE-2023-35843
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
92.0%
2023 4 PoCs

NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files on the server by manipulating the path parameter of the /download route. This vulnerability could allow an attacker to access sensitive files and data on the server, including configuration files, source code, and other sensitive information.

CVE-2023-31726
Software Genérico General
7.5
HIGH
EPSS
2.1%
2023 2 PoCs

AList 3.15.1 is vulnerable to Incorrect Access Control, which can be exploited by attackers to obtain sensitive information.

CVE-2023-29517
xwiki-platform Web
7.5
HIGH
EPSS
0.4%
2023 CWE-200 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The office document viewer macro was allowing anyone to see any file content from the hosting server, provided that the office server was connected and depending on the permissions of the user running the servlet engine (e.g. tomcat) running XWiki. The same vulnerability also allowed to perform internal requests to resources from the hosting server. The problem has been patched in XWiki 13.10.11, 14.10.1, 14.4.8, 15.0-rc-1. Users are advised to upgrade. It might be possible to workaround th

CVE-2023-1105
flatpressblog/flatpress General
7.5
HIGH
EPSS
0.3%
2023 CWE-73 1 PoC

External Control of File Name or Path in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2023-22308
SoftEther VPN Networking
7.5
HIGH
EPSS
0.1%
2023 CWE-191 1 PoC

An integer underflow vulnerability exists in the vpnserver OvsProcessData functionality of SoftEther VPN 5.01.9674 and 5.02. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2023-48834
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion.

CVE-2023-21854
Sales Offline Web Database
7.5
HIGH
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Core Components). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Sales Offline. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Sales Offline accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).

CVE-2023-42580
Galaxy Store Web
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Improper URL validation from MCSLaunch deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to install APK from Galaxy Store.

CVE-2023-6929
ETL3100 General
7.5
HIGH
EPSS
0.0%
2023 CWE-639 1 PoC

EuroTel ETL3100 versions v01c01 and v01x37 are vulnerable to insecure direct object references that occur when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability, attackers can bypass authorization, access the hidden resources on the system, and execute privileged functionalities.

CVE-2023-31315
3rd Gen AMD EPYC™ Processors General
7.5
HIGH
EPSS
0.0%
2023 1 PoC

Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.

CVE-2023-31595
Software Genérico General
7.5
HIGH
EPSS
0.5%
2023 1 PoC

IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via unauthenticated port access.

CVE-2023-46346
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 4.1.1 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a path traversal to view all files on the information system.

CVE-2023-29748
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 2 PoCs

Story Saver for Instragram - Video Downloader 1.0.6 for Android has an exposed component that provides a method to modify the SharedPreference file. An attacker can leverage this method to inject a large amount of data into any SharedPreference file, which will be loaded into memory when the application is opened. When an attacker injects too much data, the application will trigger an OOM error and crash at startup, resulting in a persistent denial of service.

CVE-2023-31594
Software Genérico Web
7.5
HIGH
EPSS
0.4%
2023 1 PoC

IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control via an exposed HTTP channel using VLC network.

CVE-2023-22960
Software Genérico General
7.5
HIGH
EPSS
42.8%
2023 3 PoCs

Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.

CVE-2023-50387
Software Genérico General
7.5
HIGH
EPSS
52.0%
2023 2 PoCs

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.