7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-34233
snowflake-connector-python General
7.3
HIGH
EPSS
0.5%
2023 CWE-77 1 PoC

The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Versions prior to 3.0.2 are vulnerable to command injection via single sign-on(SSO) browser URL authentication. In order to exploit the potential for command injection, an attacker would need to be successful in (1) establishing a malicious resource and (2) redirecting users to utilize the resource. The attacker could set up a malicious, publicly accessible server which responds to the SSO URL with an attack payload. If the attacker then

CVE-2023-38709
Apache HTTP Server Web
7.3
HIGH
EPSS
3.9%
2023 1 PoC

Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.

CVE-2023-22844
MilesightVPN Networking
7.3
HIGH
EPSS
0.0%
2023 CWE-321 1 PoC

An authentication bypass vulnerability exists in the requestHandlers.js verifyToken functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to authentication bypass. An attacker can send a network request to trigger this vulnerability.

CVE-2023-1776
Mattermost General
7.3
HIGH
EPSS
0.7%
2023 CWE-79 1 PoC

Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a card and share it using a direct link to the file.

CVE-2023-7156
Online College Library System Web Database
7.3
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability has been found in Campcodes Online College Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file index.php of the component Search. The manipulation of the argument category leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249178 is the identifier assigned to this vulnerability.

CVE-2023-46047
Software Genérico General
7.3
HIGH
EPSS
0.0%
2023 1 PoC

An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function. NOTE: this is disputed because there is no expectation that the product should be starting with an attacker-controlled configuration file.

CVE-2023-22319
MilesightVPN Networking Database
7.3
HIGH
EPSS
0.0%
2023 CWE-89 2 PoCs

A sql injection vulnerability exists in the requestHandlers.js LoginAuth functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to authentication bypass. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2023-1127
vim/vim General
7.3
HIGH
EPSS
0.0%
2023 CWE-369 1 PoC

Divide By Zero in GitHub repository vim/vim prior to 9.0.1367.

CVE-2023-7109
Library Management System Web Database
7.3
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability classified as critical was found in code-projects Library Management System 2.0. This vulnerability affects unknown code of the file /admin/login.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249004.

CVE-2023-42566
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.1%
2023 1 PoC

Out-of-bound write vulnerability in libsavsvc prior to SMR Dec-2023 Release 1 allows local attackers to execute arbitrary code.

CVE-2023-4182
Inventory Management System Web Database
7.3
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file edit_sell.php. The manipulation of the argument up_pid leads to sql injection. It is possible to initiate the attack remotely. The identifier VDB-236217 was assigned to this vulnerability.

CVE-2023-53878
Member Login Script Web
7.3
HIGH
EPSS
0.1%
2023 CWE-444 1 PoC

Member Login Script 3.3 contains a client-side desynchronization vulnerability that allows attackers to manipulate HTTP request handling by exploiting Content-Length header parsing. Attackers can send crafted POST requests with smuggled secondary requests to potentially bypass server-side request processing controls.

CVE-2023-6655
e-HR Database ⚡ nuclei
7.3
HIGH
EPSS
24.9%
2023 CWE-89 0 PoCs

A vulnerability, which was classified as critical, has been found in Hongjing e-HR 2020. Affected by this issue is some unknown functionality of the file /w_selfservice/oauthservlet/%2e./.%2e/general/inform/org/loadhistroyorgtree of the component Login Interface. The manipulation of the argument parentid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-247358 is the identifier assigned to this vulnerability.

CVE-2023-21894
Global Lifecycle Management NextGen OUI Framework Database
7.3
HIGH
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer issues). Supported versions that are affected are Prior to 13.9.4.2.11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Global Lifecycle Management NextGen OUI Framework executes to compromise Oracle Global Lifecycle Management NextGen OUI Framework. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in ta

CVE-2023-2904
SAFE Web
7.3
HIGH
EPSS
0.2%
2023 CWE-471 1 PoC

The External Visitor Manager portal of HID’s SAFE versions 5.8.0 through 5.11.3 are vulnerable to manipulation within web fields in the application programmable interface (API). An attacker could log in using account credentials available through a request generated by an internal user and then manipulate the visitor-id within the web API to access the personal data of other users. There is no limit on the number of requests that can be made to the HID SAFE Web Server, so an attacker could also exploit this vulnerability to create a denial-of-service condition.

CVE-2023-0784
Best Online News Portal Database
7.3
HIGH
EPSS
0.3%
2023 CWE-89 2 PoCs

A vulnerability classified as critical has been found in SourceCodester Best Online News Portal 1.0. Affected is an unknown function of the component Login Page. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220644.

CVE-2023-4415
RG-EW1200G Web ⚡ nuclei
7.3
HIGH
EPSS
90.0%
2023 CWE-287 2 PoCs

A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/sys/login. The manipulation leads to improper authentication. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-237518 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-42568
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.1%
2023 1 PoC

Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files with system privilege.

CVE-2023-36540
Zoom Desktop Client for Windows Windows
7.3
HIGH
EPSS
0.0%
2023 CWE-426 1 PoC

Untrusted search path in the installer for Zoom Desktop Client for Windows before 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.

CVE-2023-0049
vim/vim General
7.3
HIGH
EPSS
0.0%
2023 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.