7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-45209
Smart Reader Web
5.3
MEDIUM
EPSS
0.5%
2023 CWE-284 2 PoCs

An information disclosure vulnerability exists in the web interface /cgi-bin/download_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

CVE-2023-23545
T&D Corporation and ESPEC MIC CORP. data logger products General
5.3
MEDIUM
EPSS
0.4%
2023 1 PoC

Missing authentication for critical function exists in T&D Corporation and ESPEC MIC CORP. data logger products, which may allow a remote unauthenticated attacker to alter the product settings without authentication. Affected products and versions are as follows: T&D Corporation data logger products (TR-71W/72W all firmware versions, RTR-5W all firmware versions, WDR-7 all firmware versions, WDR-3 all firmware versions, and WS-2 all firmware versions), and ESPEC MIC CORP. data logger products (RT-12N/RS-12N all firmware versions, RT-22BN all firmware versions, and TEU-12N all firmware versions

CVE-2023-21904
Banking Virtual Account Management Web Database
5.3
MEDIUM
EPSS
0.6%
2023 1 PoC

Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Banking Virtual Acco

CVE-2023-4755
gpac/gpac General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-416 1 PoC

Use After Free in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-0330
Software Genérico General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-121 1 PoC

A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.

CVE-2023-6592
FastDup Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
4.4%
2023 2 PoCs

The FastDup WordPress plugin before 2.2 does not prevent directory listing in sensitive directories containing export files.

CVE-2023-6759
IceCMS Web
5.3
MEDIUM
EPSS
0.2%
2023 CWE-837 1 PoC

A vulnerability classified as problematic has been found in Thecosy IceCMS 2.0.1. This affects an unknown part of the file /WebResource/resource of the component Love Handler. The manipulation leads to improper enforcement of a single, unique action. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-247887.

CVE-2023-1176
mlflow/mlflow General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-36 1 PoC

Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.2.2.

CVE-2023-46666
Elastic Sharepoint Online Python Connector Database Windows
5.3
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that user would have read permissions to all content on the Sharepoint site through Elasticsearch.

CVE-2023-21971
MySQL Connectors Database
5.3
MEDIUM
EPSS
0.2%
2023 3 PoCs

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors as well as unauthorized update, insert or delete access to some of

CVE-2023-30666
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper input validation vulnerability in DoOemImeiSetPreconfig in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds write.

CVE-2023-2042
DataGear General
5.3
MEDIUM
EPSS
0.5%
2023 CWE-502 1 PoC

A vulnerability, which was classified as problematic, has been found in DataGear up to 4.7.0/5.1.0. Affected by this issue is some unknown functionality of the component JDBC Server Handler. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-21831
PeopleSoft Enterprise CS Academic Advisement Web Database
5.3
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the PeopleSoft Enterprise CS Academic Advisement product of Oracle PeopleSoft (component: Advising Notes). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Academic Advisement. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise CS Academic Advisement accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2023-0029
RE708 General
5.3
MEDIUM
EPSS
0.5%
2023 CWE-404 1 PoC

A vulnerability was found in Multilaser RE708 RE1200R4GC-2T2R-V3_v3411b_MUL029B. It has been rated as problematic. This issue affects some unknown processing of the component Telnet Service. The manipulation leads to denial of service. The attack may be initiated remotely. The identifier VDB-217169 was assigned to this vulnerability.

CVE-2023-26103
deno General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-1333 1 PoC

Versions of the package deno before 1.31.0 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the upgradeWebSocket function, which contains regexes in the form of /s*,s*/, used for splitting the Connection/Upgrade header. A specially crafted Connection/Upgrade header can be used to significantly slow down a web socket server.

CVE-2023-4683
gpac/gpac General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-476 2 PoCs

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-5969
Mattermost Web
5.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

Mattermost fails to properly sanitize the request to /api/v4/redirect_location allowing an attacker, sending a specially crafted request to /api/v4/redirect_location, to fill up the memory due to caching large items.

CVE-2023-51393
Ember ZNet SDK General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-770 1 PoC

Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v7.4.0.0 (delivered as part of Silicon Labs Gecko SDK v4.4.0) which may enable attackers to trigger a bus fault and crash of the device, requiring a reboot in order to rejoin the network.

CVE-2023-2766
OA General ⚡ nuclei
5.3
MEDIUM
EPSS
91.8%
2023 CWE-552 0 PoCs

A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini. The manipulation leads to files or directories accessible. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-229271. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-29185
NetWeaver AS for ABAP (Business Server Pages) General
5.3
MEDIUM
EPSS
0.5%
2023 CWE-400 1 PoC

SAP NetWeaver AS for ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an attacker authenticated as a non-administrative user to craft a request with certain parameters in certain circumstances which can consume the server's resources sufficiently to make it unavailable over the network without any user interaction.