7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-2228
modoboa/modoboa Web
6.8
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.1.0.

CVE-2023-29087
Software Genérico General
6.8
MEDIUM
EPSS
0.6%
2023 2 PoCs

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficient parameter validation while decoding an SIP Retry-After header.

CVE-2023-4422
cockpit-hq/cockpit Web
6.8
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

CVE-2023-0061
Judge.me Product Reviews for WooCommerce Web Windows
6.8
MEDIUM
EPSS
0.5%
2023 1 PoC

The Judge.me Product Reviews for WooCommerce WordPress plugin before 1.3.21 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0800
libtiff General
6.8
MEDIUM
EPSS
0.0%
2023 1 PoC

LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3502, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.

CVE-2023-26461
NetWeaver (SAP Enterprise Portal) General
6.8
MEDIUM
EPSS
0.3%
2023 CWE-611 1 PoC

SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges to access the XML parser which can submit a crafted XML file which when parsed will enable them to access but not modify sensitive files and data. It allows the attacker to view sensitive data which is owned by certain privileges.

CVE-2023-30712
Samsung Mobile Devices General
6.8
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper input validation in Settings Suggestions prior to SMR Sep-2023 Release 1 allows attackers to launch arbitrary activity.

CVE-2023-21493
Samsung Mobile Devices General
6.8
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control vulnerability in SemShareFileProvider prior to SMR May-2023 Release 1 allows local attackers to access protected data.

CVE-2023-21472
Samsung Mobile Devices General
6.8
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader.

CVE-2023-49983
Software Genérico Web
6.8
MEDIUM
EPSS
0.4%
2023 2 PoCs

A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.

CVE-2023-7003
Kontrol Lux General
6.8
MEDIUM
EPSS
0.1%
2023 CWE-323 1 PoC

The AES key utilized in the pairing process between a lock using Sciener firmware and a wireless keypad is not unique, and can be reused to compromise other locks using the Sciener firmware.

CVE-2023-2615
pimcore/pimcore Web
6.8
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-33921
CP-8031 MASTER MODULE General
6.8
MEDIUM
EPSS
0.2%
2023 CWE-749 2 PoCs

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The affected devices contain an exposed UART console login interface. An attacker with direct physical access could try to bruteforce or crack the root password to login to the device.

CVE-2023-50124
Software Genérico General
6.8
MEDIUM
EPSS
0.1%
2023 1 PoC

Flient Smart Door Lock v1.0 is vulnerable to Use of Default Credentials. Due to default credentials on a debug interface, in combination with certain design choices, an attacker can unlock the Flient Smart Door Lock by replacing the fingerprint that is stored on the scanner.

CVE-2023-20116
Cisco Unified Communications Manager Web Networking
6.8
MEDIUM
EPSS
0.5%
2023 CWE-835 1 PoC

A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the web UI of the Self Care Portal. An attacker could exploit this vulnerability by sending crafted HTTP input to an affected device. A successful exploit could allow the attacker to cause a DoS conditi

CVE-2023-29085
Software Genérico General
6.8
MEDIUM
EPSS
0.9%
2023 2 PoCs

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficient parameter validation while decoding an SIP status line.

CVE-2023-29089
Software Genérico General
6.8
MEDIUM
EPSS
0.6%
2023 2 PoCs

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficient parameter validation while decoding SIP multipart messages.

CVE-2023-0804
libtiff General
6.8
MEDIUM
EPSS
0.0%
2023 1 PoC

LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3609, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.

CVE-2023-29088
Software Genérico General
6.8
MEDIUM
EPSS
0.6%
2023 2 PoCs

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficient parameter validation while decoding an SIP Session-Expires header.

CVE-2023-2323
pimcore/pimcore Web
6.8
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.