7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-49111
SAST Web
6.5
MEDIUM
EPSS
0.3%
2023 CWE-79 3 PoCs

For Kiuwan installations with SSO (single sign-on) enabled, an unauthenticated reflected cross-site scripting attack can be performed on the login page "login.html". This is possible due to the request parameter "message" values being directly included in a JavaScript block in the response. This is especially critical in business environments using AD SSO authentication, e.g. via ADFS, where attackers could potentially steal AD passwords. This issue affects Kiuwan SAST: <master.1808.p685.q13371

CVE-2023-31018
vGPU driver and Cloud gaming driver Cloud Windows
6.5
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

NVIDIA GPU Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a NULL-pointer dereference, which may lead to denial of service.

CVE-2023-22040
WebLogic Server Database
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Serv

CVE-2023-2380
SRX5308 General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability, which was classified as problematic, was found in Netgear SRX5308 up to 4.3.5-3. Affected is an unknown function. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-227658 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-31187
IX Workforce Engagement General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-522 1 PoC

Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials

CVE-2023-0936
Archer C50 General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-404 1 PoC

A vulnerability was found in TP-Link Archer C50 V2_160801. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Web Management Interface. The manipulation leads to denial of service. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-221552.

CVE-2023-3172
froxlor/froxlor General
6.5
MEDIUM
EPSS
0.3%
2023 CWE-22 1 PoC

Path Traversal in GitHub repository froxlor/froxlor prior to 2.0.20.

CVE-2023-27167
Software Genérico Database
6.5
MEDIUM
EPSS
0.6%
2023 2 PoCs

Suprema BioStar 2 v2.8.16 was discovered to contain a SQL injection vulnerability via the values parameter at /users/absence?search_month=1.

CVE-2023-6277
Red Hat Enterprise Linux 6 Web
6.5
MEDIUM
EPSS
3.8%
2023 CWE-400 5 PoCs

An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.

CVE-2023-24045
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2023 1 PoC

In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request.

CVE-2023-0952
Devolutions Server General
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an authenticated user to access sensitive data without proper authorization.

CVE-2023-30943
Software Genérico Web ⚡ nuclei
6.5
MEDIUM
EPSS
26.8%
2023 CWE-73 3 PoCs

The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.

CVE-2023-5459
DVP32ES2 PLC General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability has been found in Delta Electronics DVP32ES2 PLC 1.48 and classified as critical. This vulnerability affects unknown code of the component Password Transmission Handler. The manipulation leads to denial of service. The exploit has been disclosed to the public and may be used. VDB-241582 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-5214
Bolt General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-269 1 PoC

In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.

CVE-2023-6002
YugabyteDB Web
6.5
MEDIUM
EPSS
0.2%
2023 CWE-117 1 PoC

YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated user input to log files can allow an unprivileged attacker to forge log entries or inject malicious content into the logs.

CVE-2023-3423
cloudexplorer-dev/cloudexplorer-lite Cloud
6.5
MEDIUM
EPSS
0.1%
2023 CWE-521 1 PoC

Weak Password Requirements in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v 1.2.0.

CVE-2023-1009
Vigor 2960 General
6.5
MEDIUM
EPSS
3.5%
2023 CWE-22 1 PoC

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5. Affected is the function sub_1DF14 of the file /cgi-bin/mainfunction.cgi of the component Web Management Interface. The manipulation of the argument option with the input /../etc/passwd- leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-221742 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-0661
Devolutions Server General
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data.

CVE-2023-1147
flatpressblog/flatpress Web
6.5
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2023-3338
kernel General
6.5
MEDIUM
EPSS
7.7%
2023 CWE-476 2 PoCs

A null pointer dereference flaw was found in the Linux kernel's DECnet networking protocol. This issue could allow a remote user to crash the system.