7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-37026
Software Genérico Networking
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `E-RAB Release Response` packet missing an expected `MME_UE_S1AP_ID` field.

CVE-2023-22040
WebLogic Server Database
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Serv

CVE-2023-6002
YugabyteDB Web
6.5
MEDIUM
EPSS
0.2%
2023 CWE-117 1 PoC

YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated user input to log files can allow an unprivileged attacker to forge log entries or inject malicious content into the logs.

CVE-2023-24625
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Faveo 5.0.1 allows remote attackers to obtain sensitive information via a modified user ID in an Insecure Direct Object Reference (IDOR) attack.

CVE-2023-3423
cloudexplorer-dev/cloudexplorer-lite Cloud
6.5
MEDIUM
EPSS
0.1%
2023 CWE-521 1 PoC

Weak Password Requirements in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v 1.2.0.

CVE-2023-24121
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet.

CVE-2023-50129
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2023 1 PoC

Missing encryption in the NFC tags of the Flient Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original tags, which results in an attacker gaining access to the perimeter.

CVE-2023-1783
Orangescrum Cloud
6.5
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

OrangeScrum version 2.0.11 allows an external attacker to remotely obtain AWS instance credentials. This is possible because the application does not properly validate the HTML content to be converted to PDF.

CVE-2023-1147
flatpressblog/flatpress Web
6.5
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2023-2380
SRX5308 General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability, which was classified as problematic, was found in Netgear SRX5308 up to 4.3.5-3. Affected is an unknown function. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-227658 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-21946
MySQL Server Database
6.5
MEDIUM
EPSS
0.3%
2023 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVE-2023-1623
Custom Post Type UI Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The Custom Post Type UI WordPress plugin before 1.13.5 does not properly check for CSRF when sending the debug information to a user supplied email, which could allow attackers to make a logged in admin send such information to an arbitrary email address via a CSRF attack.

CVE-2023-47459
Software Genérico General
6.5
MEDIUM
EPSS
0.8%
2023 1 PoC

An issue in Knovos Discovery v.22.67.0 allows a remote attacker to obtain sensitive information via the /DiscoveryReview/Service/CaseManagement.svc/GetProductSiteName component.

CVE-2023-33754
Software Genérico Cloud
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The captive portal in Inpiazza Cloud WiFi versions prior to v4.2.17 does not enforce limits on the number of attempts for password recovery, allowing attackers to brute force valid user accounts to gain access to login credentials.

CVE-2023-5459
DVP32ES2 PLC General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability has been found in Delta Electronics DVP32ES2 PLC 1.48 and classified as critical. This vulnerability affects unknown code of the component Password Transmission Handler. The manipulation leads to denial of service. The exploit has been disclosed to the public and may be used. VDB-241582 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-5196
Mattermost General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-400 1 PoC

Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_prop resulting in the server consuming an abnormal quantity of computing resources and possibly becoming temporarily unavailable for its users.

CVE-2023-37035
Software Genérico Networking
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `S1Setup Request` packet missing an expected `Global eNB ID` field.

CVE-2023-27035
Software Genérico General
6.5
MEDIUM
EPSS
26.3%
2023 3 PoCs

An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page.

CVE-2023-37028
Software Genérico Networking
6.5
MEDIUM
EPSS
0.0%
2023 1 PoC

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `E-RAB Modification Indication` packet missing an expected `eNB_UE_S1AP_ID` field.

CVE-2023-2756
pimcore/customer-data-framework Database
6.5
MEDIUM
EPSS
7.0%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository pimcore/customer-data-framework prior to 3.3.10.