7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-26987
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2023 2 PoCs

An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST request.

CVE-2023-1125
Ruby Help Desk Web Windows
6.5
MEDIUM
EPSS
0.3%
2023 1 PoC

The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an attacker to close and/or add files and replies to tickets other than their own.

CVE-2023-27896
BusinessObjects Business Intelligence Platform (Web Services) Web
6.5
MEDIUM
EPSS
0.3%
2023 CWE-918 1 PoC

In SAP BusinessObjects Business Intelligence Platform - version 420, 430, an attacker can control a malicious BOE server, forcing the application server to connect to its own CMS, leading to a high impact on availability.

CVE-2023-50129
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2023 1 PoC

Missing encryption in the NFC tags of the Flient Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original tags, which results in an attacker gaining access to the perimeter.

CVE-2023-1163
Vigor 2960 General
6.5
MEDIUM
EPSS
0.9%
2023 CWE-22 1 PoC

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5 and classified as critical. Affected by this vulnerability is the function getSyslogFile of the file mainfunction.cgi of the component Web Management Interface. The manipulation of the argument option leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-222259. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-0019
SAP GRC (Process Control) General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

In SAP GRC (Process Control) - versions GRCFND_A V1200, GRCFND_A V8100, GRCPINW V1100_700, GRCPINW V1100_731, GRCPINW V1200_750, remote-enabled function module in the proprietary SAP solution enables an authenticated attacker with minimal privileges to access all the confidential data stored in the database. Successful exploitation of this vulnerability can expose user credentials from client-specific tables of the database, leading to high impact on confidentiality.

CVE-2023-24121
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet.

CVE-2023-37034
Software Genérico Networking
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Initial UE Message` packet missing an expected `TAI` field.

CVE-2023-45826
leantime Web Database ⚡ nuclei
6.5
MEDIUM
EPSS
34.4%
2023 CWE-89 0 PoCs

Leantime is an open source project management system. A 'userId' variable in `app/domain/files/repositories/class.files.php` is not parameterized. An authenticated attacker can send a carefully crafted POST request to `/api/jsonrpc` to exploit an SQL injection vulnerability. Confidentiality is impacted as it allows for dumping information from the database. This issue has been addressed in version 2.4-beta-4. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2023-50126
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2023 1 PoC

Missing encryption in the RFID tags of the Hozard alarm system (Alarmsysteem) v1.0 allow attackers to create a cloned tag via brief physical proximity to one of the original tags, which results in an attacker being able to bring the alarm system to a disarmed state.

CVE-2023-3981
omeka/omeka-s General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository omeka/omeka-s prior to 4.0.2.

CVE-2023-20527
1st Gen EPYC General
6.5
MEDIUM
EPSS
0.3%
2023 1 PoC

Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial-of-service.

CVE-2023-4800
DoLogin Security Web Windows
6.5
MEDIUM
EPSS
8.9%
2023 2 PoCs

The DoLogin Security WordPress plugin before 3.7.1 does not restrict the access of a widget that shows the IPs of failed logins to low privileged users.

CVE-2023-31018
vGPU driver and Cloud gaming driver Cloud Windows
6.5
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

NVIDIA GPU Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a NULL-pointer dereference, which may lead to denial of service.

CVE-2023-47993
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

A Buffer out-of-bound read vulnerability in Exif.cpp::ReadInt32 in FreeImage 3.18.0 allows attackers to cause a denial-of-service.

CVE-2023-4969
OpenCL General
6.5
MEDIUM
EPSS
2.1%
2023 3 PoCs

A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures.

CVE-2023-0668
Wireshark General
6.5
MEDIUM
EPSS
1.9%
2023 CWE-125 2 PoCs

Due to failure in validating the length provided by an attacker-crafted IEEE-C37.118 packet, Wireshark version 4.0.5 and prior, by default, is susceptible to a heap-based buffer overflow, and possibly code execution in the context of the process running Wireshark.

CVE-2023-21993
Clinical Remote Data Capture Option Web Database
6.5
MEDIUM
EPSS
0.5%
2023 1 PoC

Vulnerability in the Oracle Clinical Remote Data Capture product of Oracle Health Sciences Applications (component: Forms). The supported version that is affected is 5.4.0.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Clinical Remote Data Capture. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Clinical Remote Data Capture accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N

CVE-2023-0952
Devolutions Server General
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an authenticated user to access sensitive data without proper authorization.

CVE-2023-49111
SAST Web
6.5
MEDIUM
EPSS
0.3%
2023 CWE-79 3 PoCs

For Kiuwan installations with SSO (single sign-on) enabled, an unauthenticated reflected cross-site scripting attack can be performed on the login page "login.html". This is possible due to the request parameter "message" values being directly included in a JavaScript block in the response. This is especially critical in business environments using AD SSO authentication, e.g. via ADFS, where attackers could potentially steal AD passwords. This issue affects Kiuwan SAST: <master.1808.p685.q13371