7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-39982
MXsecurity Series Networking
7.5
HIGH
EPSS
0.2%
2023 CWE-321 1 PoC

A vulnerability has been identified in MXsecurity versions prior to v1.0.1. The vulnerability may put the confidentiality and integrity of SSH communications at risk on the affected device. This vulnerability is attributed to a hard-coded SSH host key, which might facilitate man-in-the-middle attacks and enable the decryption of SSH traffic.

CVE-2023-45233
edk2 General
7.5
HIGH
EPSS
0.5%
2023 CWE-835 1 PoC

EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.

CVE-2023-26152
static-server General
7.5
HIGH
EPSS
0.8%
2023 CWE-22 1 PoC

All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath function of server.js.

CVE-2023-40211
Post Grid Combo – 36+ Gutenberg Blocks General ⚡ nuclei
7.5
HIGH
EPSS
31.5%
2023 CWE-200 0 PoCs

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PickPlugins Post Grid Combo – 36+ Gutenberg Blocks.This issue affects Post Grid Combo – 36+ Gutenberg Blocks: from n/a through 2.2.50.

CVE-2023-24500
Electra Central AC unit General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW.

CVE-2023-4197
Dolibarr ERP CRM Web
7.5
HIGH
EPSS
51.1%
2023 CWE-20 2 PoCs

Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.

CVE-2023-24503
OSK201 General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW.

CVE-2023-21842
WebLogic Server DevOps Web Database
7.5
HIGH
EPSS
1.1%
2023 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2023-40278
Software Genérico General
7.5
HIGH
EPSS
11.3%
2023 3 PoCs

An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsp component of OpenClinic GA. By changing the AppointmentUid parameter, an attacker can determine whether a specific appointment exists based on the error message.

CVE-2023-31115
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. Incorrect resource transfer between spheres can cause changes to the activation mode of RCS via a crafted application.

CVE-2023-44836
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the SSID parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-21444
Samsung Flow for PC General
7.5
HIGH
EPSS
0.1%
2023 CWE-326 1 PoC

Improper cryptographic implementation in Samsung Flow for PC 4.9.14.0 allows adjacent attackers to decrypt encrypted messages or inject commands.

CVE-2023-37032
Software Genérico Networking
7.5
HIGH
EPSS
0.8%
2023 1 PoC

A Stack-based buffer overflow in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attackers to crash the MME with an unauthenticated cellphone by sending a NAS packet containing an oversized `Emergency Number List` Information Element.

CVE-2023-31893
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 2 PoCs

Telefnica Brasil Vivo Play (IPTV) Firmware: 2023.04.04.01.06.15 is vulnerable to Denial of Service (DoS) via DNS Recursion.

CVE-2023-29740
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 2 PoCs

An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause a denial of service attack by manipulating the database.

CVE-2023-5392
C300 General
7.5
HIGH
EPSS
0.1%
2023 CWE-1295 1 PoC

C300 information leak due to an analysis feature which allows extracting more memory over the network than required by the function. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-7239
WP Dashboard Notes Web Windows
7.5
HIGH
EPSS
0.7%
2023 1 PoC

The WP Dashboard Notes WordPress plugin before 1.0.11 does not validate that the user has access to the post_id parameter in its wpdn_update_note AJAX action. This allows users with a role of contributor and above to update notes created by other users.

CVE-2023-21516
Galaxy Store Web
7.5
HIGH
EPSS
0.5%
2023 CWE-20 1 PoC

XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.

CVE-2023-42560
Samsung Mobile Devices General
7.4
HIGH
EPSS
0.1%
2023 1 PoC

Heap out-of-bounds write vulnerability in dec_mono_audb of libsavsac.so prior to SMR Dec-2023 Release 1 allows an attacker to execute arbitrary code.