7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-46446
Software Genérico Networking
6.8
MEDIUM
EPSS
0.4%
2023 1 PoC

An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulation, aka a "Rogue Session Attack."

CVE-2023-0801
libtiff General
6.8
MEDIUM
EPSS
0.0%
2023 1 PoC

LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tools/tiffcrop.c:6778, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.

CVE-2023-42134
POS terminals General
6.8
MEDIUM
EPSS
0.2%
2023 CWE-912 1 PoC

PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.45_20230314 or earlier can allow the signed partition overwrite and subsequently local code execution via hidden command. The attacker must have physical USB access to the device in order to exploit this vulnerability.

CVE-2023-2102
alextselegidis/easyappointments Web
6.8
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

CVE-2023-0802
libtiff General
6.8
MEDIUM
EPSS
0.0%
2023 1 PoC

LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3724, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.

CVE-2023-21918
Database - Enterprise Edition Database
6.8
MEDIUM
EPSS
0.5%
2023 1 PoC

Vulnerability in the Oracle Database Recovery Manager component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows high privileged attacker having Local SYSDBA privilege with network access via Oracle Net to compromise Oracle Database Recovery Manager. While the vulnerability is in Oracle Database Recovery Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of

CVE-2023-29086
Software Genérico General
6.8
MEDIUM
EPSS
0.6%
2023 2 PoCs

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficient parameter validation while decoding an SIP Min-SE header.

CVE-2023-2666
froxlor/froxlor General
6.8
MEDIUM
EPSS
0.1%
2023 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository froxlor/froxlor prior to 2.0.16.

CVE-2023-2426
vim/vim General
6.8
MEDIUM
EPSS
0.0%
2023 CWE-823 1 PoC

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499.

CVE-2023-0375
Easy Affiliate Links Web Windows
6.8
MEDIUM
EPSS
0.7%
2023 1 PoC

The Easy Affiliate Links WordPress plugin before 3.7.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-51820
Software Genérico General
6.8
MEDIUM
EPSS
0.2%
2023 2 PoCs

An issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate attackers to execute arbitrary code.

CVE-2023-0796
libtiff General
6.8
MEDIUM
EPSS
0.0%
2023 1 PoC

LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3592, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit afaabc3e.

CVE-2023-0574
YugabyteDB Anywhere General
6.8
MEDIUM
EPSS
0.3%
2023 CWE-918 1 PoC

Server-Side Request Forgery (SSRF), Improperly Controlled Modification of Dynamically-Determined Object Attributes, Improper Restriction of Excessive Authentication Attempts vulnerability in YugaByte, Inc. Yugabyte Managed allows Accessing Functionality Not Properly Constrained by ACLs, Communication Channel Manipulation, Authentication Abuse.This issue affects Yugabyte Managed: from 2.0.0.0 through 2.13.0.0

CVE-2023-44090
Pandora FMS DevOps Database
6.8
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows CVE-2008-5817. This vulnerability allowed SQL changes to be made to several files in the Grafana module. This issue affects Pandora FMS: from 700 through <776.

CVE-2023-21472
Samsung Mobile Devices General
6.8
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader.

CVE-2023-42577
Samsung Voice Recorder General
6.8
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper Access Control in Samsung Voice Recorder prior to versions 21.4.15.01 in Android 12 and Android 13, 21.4.50.17 in Android 14 allows physical attackers to access Voice Recorder information on the lock screen.

CVE-2023-0075
Amazon JS Web Windows
6.8
MEDIUM
EPSS
0.5%
2023 1 PoC

The Amazon JS WordPress plugin through 0.10 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-0799
libtiff General
6.8
MEDIUM
EPSS
0.0%
2023 1 PoC

LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3701, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit afaabc3e.

CVE-2023-42135
A920 Pro General
6.8
MEDIUM
EPSS
0.0%
2023 CWE-74 1 PoC

PAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter injection by bypassing the input validation when flashing a specific partition. The attacker must have physical USB access to the device in order to exploit this vulnerability.

CVE-2023-2614
pimcore/pimcore Web
6.8
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.21.