7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-1587
Avast Antivirus Windows
5.8
MEDIUM
EPSS
0.1%
2023 CWE-476 1 PoC

Avast and AVG Antivirus for Windows were susceptible to a NULL pointer dereference issue via RPC-interface. The issue was fixed with Avast and AVG Antivirus version 22.11

CVE-2023-5318
microweber/microweber General
5.8
MEDIUM
EPSS
0.3%
2023 CWE-798 1 PoC

Use of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0.

CVE-2023-47218
QTS Cloud ⚡ nuclei
5.8
MEDIUM
EPSS
93.2%
2023 CWE-77 2 PoCs

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.5.2645 build 20240116 and later QuTS hero h5.1.5.2647 build 20240118 and later QuTScloud c5.1.5.2651 and later

CVE-2023-50358
QTS Cloud
5.8
MEDIUM
EPSS
1.8%
2023 CWE-78 3 PoCs

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.5.2645 build 20240116 and later QTS 4.5.4.2627 build 20231225 and later QTS 4.3.6.2665 build 20240131 and later QTS 4.3.4.2675 build 20240131 and later QTS 4.3.3.2644 build 20240131 and later QTS 4.2.6 build 20240131 and later QuTS hero h5.1.5.2647 build 20240118 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5

CVE-2023-2021
nilsteampassnet/teampass Web
5.8
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.3.

CVE-2023-4914
cecilapp/cecil General
5.8
MEDIUM
EPSS
0.2%
2023 CWE-23 1 PoC

Relative Path Traversal in GitHub repository cecilapp/cecil prior to 7.47.1.

CVE-2023-53886
Xlight FTP Server General
5.7
MEDIUM
EPSS
0.1%
2023 CWE-121 1 PoC

Xlight FTP Server 3.9.3.6 contains a stack buffer overflow vulnerability in the 'Execute Program' configuration that allows attackers to crash the application. Attackers can trigger the vulnerability by inserting 294 characters into the program execution configuration, causing a denial of service condition.

CVE-2023-1149
btcpayserver/btcpayserver General
5.7
MEDIUM
EPSS
0.4%
2023 CWE-76 1 PoC

Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.8.0.

CVE-2023-21448
Samsung Cloud Cloud
5.7
MEDIUM
EPSS
0.1%
2023 CWE-22 1 PoC

Path traversal vulnerability in Samsung Cloud prior to version 5.3.0.32 allows attacker to access specific png file.

CVE-2023-6051
GitLab DevOps
5.7
MEDIUM
EPSS
0.2%
2023 CWE-94 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when source code or installation packages are pulled from a specific tag.

CVE-2023-29681
Software Genérico Networking
5.7
MEDIUM
EPSS
0.1%
2023 3 PoCs

Cleartext Transmission in cookie:ecos_pw: in Tenda N301 v6.0, firmware v12.03.01.06_pt allows an authenticated attacker on the LAN or WLAN to intercept communications with the router and obtain the password.

CVE-2023-21965
Business Intelligence Enterprise Edition Web Database
5.7
MEDIUM
EPSS
0.5%
2023 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessibl

CVE-2023-30731
Samsung Mobile Devices General
5.7
MEDIUM
EPSS
0.1%
2023 1 PoC

Logic error in package installation via debugger command prior to SMR Oct-2023 Release 1 allows physical attacker to install an application that has different build type.

CVE-2023-21422
Samsung Mobile Devices General
5.7
MEDIUM
EPSS
0.1%
2023 CWE-285 1 PoC

Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server without permission via binding WifiService.

CVE-2023-1708
GitLab DevOps
5.7
MEDIUM
EPSS
5.2%
2023 1 PoC

An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-printable characters gets copied from clipboard, allowing unexpected commands to be executed on victim machine.

CVE-2023-27370
RAX30 Networking
5.7
MEDIUM
EPSS
0.0%
2023 CWE-312 1 PoC

NETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of device configuration. The issue results from the storage of configuration secrets in plaintext. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromi

CVE-2023-21986
GraalVM Enterprise Edition Database
5.7
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Native Image). Supported versions that are affected are Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle GraalVM Enterprise Edition executes to compromise Oracle GraalVM Enterprise Edition. While the vulnerability is in Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in

CVE-2023-1178
GitLab DevOps
5.7
MEDIUM
EPSS
2.5%
2023 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source code or installation packages are pulled from a tag or from a release containing a ref to another commit.

CVE-2023-37027
Software Genérico Networking
5.7
MEDIUM
EPSS
0.1%
2023 1 PoC

Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `E-RAB Modification Indication` packet missing an expected `eNB_UE_S1AP_ID` field.

CVE-2023-5104
nocodb/nocodb General
5.7
MEDIUM
EPSS
0.8%
2023 CWE-20 1 PoC

Improper Input Validation in GitHub repository nocodb/nocodb prior to 0.96.0.