7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-3782
Software Genérico Web
5.9
MEDIUM
EPSS
0.3%
2023 CWE-400 1 PoC

DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb into an HTTP response

CVE-2023-4722
gpac/gpac General
5.9
MEDIUM
EPSS
0.0%
2023 CWE-190 1 PoC

Integer Overflow or Wraparound in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-21468
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper access control vulnerability in Telephony prior to SMR Apr-2023 Release 1 allows attackers to access files with escalated permission.

CVE-2023-5407
C300 General
5.9
MEDIUM
EPSS
0.1%
2023 CWE-121 1 PoC

Controller denial of service due to improper handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-50125
Software Genérico General
5.9
MEDIUM
EPSS
0.2%
2023 1 PoC

A default engineer password set on the Hozard alarm system (Alarmsysteem) v1.0 allows an attacker to bring the alarm system to a disarmed state.

CVE-2023-5405
Experion Server General
5.9
MEDIUM
EPSS
0.1%
2023 CWE-787 1 PoC

Server information leak for the CDA Server process memory can occur when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-42570
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper access control vulnerability in KnoxCustomManagerService prior to SMR Dec-2023 Release 1 allows attacker to access device SIM PIN.

CVE-2023-27624
Redirect After Login Web ⚡ nuclei
5.9
MEDIUM
EPSS
0.7%
2023 CWE-79 0 PoCs

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marcelotorres Redirect After Login plugin <= 0.1.9 versions.

CVE-2023-21421
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2023 CWE-280 1 PoC

Improper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2023 Release 1 allows attacker to access device SIM PIN.

CVE-2023-0400
Data Loss Prevention (DLP) Windows
5.9
MEDIUM
EPSS
0.1%
2023 CWE-670 1 PoC

The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP controls when uploading sensitive data from a mapped drive into a web email client. Loading from a local driver was correctly prevented. Versions prior to 11.9 correctly detected and blocked the attempted upload of sensitive data.

CVE-2023-30446
DB2 for Linux, UNIX and Windows Windows
5.9
MEDIUM
EPSS
0.1%
2023 CWE-20 1 PoC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253361 .

CVE-2023-38371
Security Access Manager Docker DevOps
5.9
MEDIUM
EPSS
0.0%
2023 CWE-327 2 PoCs

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 261198.

CVE-2023-5406
Experion Server General
5.9
MEDIUM
EPSS
0.6%
2023 CWE-787 1 PoC

Server communication with a controller can lead to remote code execution using a specially crafted message from the controller. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-4721
gpac/gpac General
5.9
MEDIUM
EPSS
0.0%
2023 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-4756
gpac/gpac General
5.9
MEDIUM
EPSS
0.0%
2023 CWE-121 1 PoC

Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-32890
MT2731, MT6767, MT6768, MT6769, MT6769T, MT6769Z, MT8666, MT8667, MT8765, MT8766, MT8768, MT8786, MT8788 General
5.9
MEDIUM
EPSS
0.3%
2023 1 PoC

In modem EMM, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01183647; Issue ID: MOLY01183647 (MSV-963).

CVE-2023-21455
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.2%
2023 CWE-287 1 PoC

Improper authorization implementation in Exynos baseband prior to SMR Mar-2023 Release 1 allows incorrect handling of unencrypted message.

CVE-2023-44088
Pandora FMS Database
5.9
MEDIUM
EPSS
0.2%
2023 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitrary SQL queries were allowed to be executed using any account with low privileges. This issue affects Pandora FMS: from 700 through 774.

CVE-2023-42532
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.3%
2023 1 PoC

Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmware information.

CVE-2023-4985
InPlant SCADA General
5.9
MEDIUM
EPSS
0.1%
2023 CWE-287 1 PoC

A vulnerability classified as critical has been found in Supcon InPlant SCADA up to 20230901. Affected is an unknown function of the file Project.xml. The manipulation leads to improper authentication. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239796. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.