7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-20566
3rd Gen AMD EPYC™ Processors General
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.

CVE-2023-36919
SAP Enable Now General
5.3
MEDIUM
EPSS
0.5%
2023 CWE-213 1 PoC

In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the Referrer-Policy response header is not implemented, allowing an unauthenticated attacker to obtain referrer details, resulting in information disclosure.

CVE-2023-28470
Software Genérico General
5.3
MEDIUM
EPSS
0.4%
2023 2 PoCs

In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.

CVE-2023-1538
answerdev/answer General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-208 1 PoC

Observable Timing Discrepancy in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2023-20532
2nd Gen EPYC General
5.3
MEDIUM
EPSS
0.4%
2023 1 PoC

Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.

CVE-2023-3529
Rotem CRM Web
5.3
MEDIUM
EPSS
0.1%
2023 CWE-203 1 PoC

A vulnerability classified as problematic has been found in Rotem Dynamics Rotem CRM up to 20230729. This affects an unknown part of the file /LandingPages/api/otp/send?id=[ID][ampersand]method=sms of the component OTP URI Interface. The manipulation leads to information exposure through discrepancy. It is possible to initiate the attack remotely. The identifier VDB-233253 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-31186
IX Workforce Engagement General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-204 1 PoC

Avaya IX Workforce Engagement v15.2.7.1195 - User Enumeration - Observable Response Discrepancy

CVE-2023-7199
Relevanssi Web Windows
5.3
MEDIUM
EPSS
0.4%
2023 1 PoC

The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and private posts via a crafted request

CVE-2023-50436
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2023 2 PoCs

An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The earliest affected version is 7.1.5.

CVE-2023-0113
Netcore Router Networking
5.3
MEDIUM
EPSS
0.3%
2023 CWE-200 1 PoC

A vulnerability was found in Netis Netcore Router up to 2.2.6. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file param.file.tgz of the component Backup Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-217591.

CVE-2023-4002
GitLab DevOps
5.3
MEDIUM
EPSS
0.1%
2023 CWE-201 2 PoCs

An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for EE-licensed users to link any security policy project by its ID to projects or groups the user has access to, potentially revealing the security projects's configured security policies.

CVE-2023-21466
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.0%
2023 1 PoC

PendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023 Release 1 allows local attackers to access contentProvider without proper permission.

CVE-2023-7270
Office General
5.3
MEDIUM
EPSS
0.1%
2023 2 PoCs

An issue was discovered in SoftMaker Office 2024 / NX before revision 1214 and SoftMaker FreeOffice 2014 before revision 1215. FreeOffice 2021 is also affected, but won't be fixed. The SoftMaker Office and FreeOffice MSI installer files were found to produce a visible conhost.exe window running as the SYSTEM user when using the repair function of msiexec.exe. This allows a local, low-privileged attacker to use a chain of actions, to open a fully functional cmd.exe with the privileges of the SYSTEM user.

CVE-2023-30802
Net-Gen Application Firewall Web Networking
5.3
MEDIUM
EPSS
0.1%
2023 CWE-540 1 PoC

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to a source code disclosure vulnerability. A remote and unauthenticated attacker can obtain PHP source code by sending an HTTP request with an invalid Content-Length field.

CVE-2023-21835
Java SE JDK and JRE Database
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.17, 17.0.5, 19.0.1; Oracle GraalVM Enterprise Edition: 20.3.8, 21.3.4 and 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via DTLS to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Editio

CVE-2023-5845
Simple Social Media Share Buttons Web Windows
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

The Simple Social Media Share Buttons WordPress plugin before 5.1.1 leaks password-protected post content to unauthenticated visitors in some meta tags

CVE-2023-26117
angular General
5.3
MEDIUM
EPSS
0.3%
2023 CWE-1333 4 PoCs

Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.

CVE-2023-1059
Doctors Appointment System Web Database
5.3
MEDIUM
EPSS
0.2%
2023 CWE-89 1 PoC

A vulnerability classified as critical was found in SourceCodester Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/doctors.php of the component Parameter Handler. The manipulation of the argument search/id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2023-2152
Student Study Center Desk Management System Web
5.3
MEDIUM
EPSS
0.5%
2023 CWE-73 1 PoC

A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument page leads to file inclusion. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-226273 was assigned to this vulnerability.

CVE-2023-39217
Zoom SDK's General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-80 1 PoC

Improper input validation in Zoom SDK’s before 5.14.10 may allow an unauthenticated user to enable a denial of service via network access.