7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-5828
Longxing Industrial Development Zone Project Construction and Installation Management System Database
7.3
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability was found in Nanning Ontall Longxing Industrial Development Zone Project Construction and Installation Management System up to 20231026. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file login.aspx. The manipulation of the argument tbxUserName leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243727.

CVE-2023-49968
Software Genérico Web Database
7.3
HIGH
EPSS
0.1%
2023 2 PoCs

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/manage_department.php.

CVE-2023-26155
node-qpdf Web
7.3
HIGH
EPSS
0.2%
2023 CWE-78 1 PoC

All versions of the package node-qpdf are vulnerable to Command Injection such that the package-exported method encrypt() fails to sanitize its parameter input, which later flows into a sensitive command execution API. As a result, attackers may inject malicious commands once they can specify the input pdf file path.

CVE-2023-53878
Member Login Script Web
7.3
HIGH
EPSS
0.1%
2023 CWE-444 1 PoC

Member Login Script 3.3 contains a client-side desynchronization vulnerability that allows attackers to manipulate HTTP request handling by exploiting Content-Length header parsing. Attackers can send crafted POST requests with smuggled secondary requests to potentially bypass server-side request processing controls.

CVE-2023-22480
KubeOperator DevOps Web ⚡ nuclei
7.3
HIGH
EPSS
75.6%
2023 CWE-285 0 PoCs

KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In KubeOperator versions 3.16.3 and below, API interfaces with unauthorized entities and can leak sensitive information. This vulnerability could be used to take over the cluster under certain conditions. This issue has been patched in version 3.16.4.

CVE-2023-37013
Software Genérico General
7.3
HIGH
EPSS
0.2%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a sufficiently large ASN.1 packet over the S1AP interface. An attacker may repeatedly send such an oversized packet to cause the `ogs_sctp_recvmsg` routine to reach an unexpected network state and crash, leading to denial of service.

CVE-2023-3971
Red Hat Ansible Automation Platform 2.3 for RHEL 8 DevOps
7.3
HIGH
EPSS
0.4%
2023 CWE-80 1 PoC

An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.

CVE-2023-4322
radareorg/radare2 General
7.3
HIGH
EPSS
0.2%
2023 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.

CVE-2023-2904
SAFE Web
7.3
HIGH
EPSS
0.2%
2023 CWE-471 1 PoC

The External Visitor Manager portal of HID’s SAFE versions 5.8.0 through 5.11.3 are vulnerable to manipulation within web fields in the application programmable interface (API). An attacker could log in using account credentials available through a request generated by an internal user and then manipulate the visitor-id within the web API to access the personal data of other users. There is no limit on the number of requests that can be made to the HID SAFE Web Server, so an attacker could also exploit this vulnerability to create a denial-of-service condition.

CVE-2023-2641
Online Internship Management System Web Database
7.3
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability was found in SourceCodester Online Internship Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file admin/login.php of the component POST Parameter Handler. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-228770 is the identifier assigned to this vulnerability.

CVE-2023-0054
vim/vim General
7.3
HIGH
EPSS
0.0%
2023 CWE-787 1 PoC

Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145.

CVE-2023-26214
TIBCO BusinessConnect Web
7.3
HIGH
EPSS
0.7%
2023 1 PoC

The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker with network access to execute scripts targeting the affected system or the victim's local system. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect: versions 7.3.0 and below.

CVE-2023-41929
Software Genérico Windows
7.3
HIGH
EPSS
0.0%
2023 1 PoC

A DLL hijacking vulnerability in Samsung Memory Card & UFD Authentication Utility PC Software before 1.0.1 could allow a local attacker to escalate privileges. (An attacker must already have user privileges on Windows to exploit this vulnerability.)

CVE-2023-32493
PowerScale OneFS General
7.3
HIGH
EPSS
0.4%
2023 CWE-693 1 PoC

Dell PowerScale OneFS, 9.5.0.x, contains a protection mechanism bypass vulnerability. An unprivileged, remote attacker could potentially exploit this vulnerability, leading to denial of service, information disclosure and remote execution.

CVE-2023-0734
wallabag/wallabag General
7.3
HIGH
EPSS
0.3%
2023 CWE-285 1 PoC

Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4.

CVE-2023-3643
Boss Mini General ⚡ nuclei
7.3
HIGH
EPSS
40.7%
2023 CWE-73 1 PoC

A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233889 was assigned to this vulnerability.

CVE-2023-6651
Matrimonial Site Web Database
7.3
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability was found in code-projects Matrimonial Site 1.0. It has been classified as critical. Affected is an unknown function of the file /auth/auth.php?user=1. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247344.

CVE-2023-26110
node-bluetooth General
7.3
HIGH
EPSS
0.2%
2023 CWE-120 1 PoC

All versions of the package node-bluetooth are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation.

CVE-2023-2341
pimcore/pimcore Web
7.3
HIGH
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-24059
Software Genérico General
7.3
HIGH
EPSS
9.3%
2023 1 PoC

Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January 2023.