7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-25927
Security Verify Access Web
6.5
MEDIUM
EPSS
0.3%
2023 CWE-20 1 PoC

IBM Security Verify Access 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, and 10.0.5 could allow an attacker to crash the webseald process using specially crafted HTTP requests resulting in loss of access to the system. IBM X-Force ID: 247635.

CVE-2023-37030
Software Genérico Networking
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Initial UE Message` packet missing an expected `eNB_UE_S1AP_ID` field.

CVE-2023-40745
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2023 CWE-190 1 PoC

LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.

CVE-2023-1783
Orangescrum Cloud
6.5
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

OrangeScrum version 2.0.11 allows an external attacker to remotely obtain AWS instance credentials. This is possible because the application does not properly validate the HTML content to be converted to PDF.

CVE-2023-47996
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

An integer overflow vulnerability in Exif.cpp::jpeg_read_exif_dir in FreeImage 3.18.0 allows attackers to obtain information and cause a denial of service.

CVE-2023-22040
WebLogic Server Database
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Serv

CVE-2023-25618
NetWeaver AS for ABAP and ABAP Platform General
6.5
MEDIUM
EPSS
0.5%
2023 CWE-400 1 PoC

SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in an unused class for error handling in which an attacker authenticated as a non-administrative user can craft a request with certain parameters which will consume the server's resources sufficiently to make it unavailable. There is no ability to view or modify any information.

CVE-2023-23458
DVR General
6.5
MEDIUM
EPSS
0.3%
2023 CWE-200 1 PoC

Sunell DVR, latest version, CWE-200: Exposure of Sensitive Information to an Unauthorized Actor through an unspecified request.

CVE-2023-2380
SRX5308 General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability, which was classified as problematic, was found in Netgear SRX5308 up to 4.3.5-3. Affected is an unknown function. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-227658 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-3026
jgraph/drawio Web
6.5
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 21.2.8.

CVE-2023-20891
VMware Tanzu Application Service for VMs Web
6.5
MEDIUM
EPSS
0.3%
2023 CWE-532 1 PoC

The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials in hex encoding in platform system audit logs. A malicious non-admin user who has access to the platform system audit logs can access hex encoded CF API admin credentials and can push new malicious versions of an application. In a default deployment non-admin users do not have access to the platform system audit logs.

CVE-2023-21984
Solaris Operating System Web Database
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Libraries). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVE-2023-23169
Software Genérico General
6.5
MEDIUM
EPSS
0.7%
2023 1 PoC

Synapsoft pdfocus 1.17 is vulnerable to local file inclusion and server-side request forgery Directory Traversal.

CVE-2023-24625
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Faveo 5.0.1 allows remote attackers to obtain sensitive information via a modified user ID in an Insecure Direct Object Reference (IDOR) attack.

CVE-2023-41707
OX App Suite General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-400 1 PoC

Processing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of mail search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. No publicly available exploits are known.

CVE-2023-0522
Enable/Disable Auto Login when Register Web Windows
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

The Enable/Disable Auto Login when Register WordPress plugin through 1.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2023-5459
DVP32ES2 PLC General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability has been found in Delta Electronics DVP32ES2 PLC 1.48 and classified as critical. This vulnerability affects unknown code of the component Password Transmission Handler. The manipulation leads to denial of service. The exploit has been disclosed to the public and may be used. VDB-241582 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-27270
NetWeaver Application Server for ABAP and ABAP Platform General
6.5
MEDIUM
EPSS
0.5%
2023 CWE-400 1 PoC

SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has multiple vulnerabilities in a class for test purposes in which an attacker authenticated as a non-administrative user can craft a request with certain parameters, which will consume the server's resources sufficiently to make it unavailable. There is no ability to view or modify any information.

CVE-2023-49112
SAST Web
6.5
MEDIUM
EPSS
0.1%
2023 3 PoCs

Kiuwan provides an API endpoint /saas/rest/v1/info/application to get information about any application, providing only its name via the "application" parameter. This endpoint lacks proper access control mechanisms, allowing other authenticated users to read information about applications, even though they have not been granted the necessary rights to do so. This issue affects Kiuwan SAST: <master.1808.p685.q13371

CVE-2023-2787
Mattermost Web
6.5
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary posts by using the message threads API.