7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-0440
healthchecks/healthchecks General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-203 1 PoC

Observable Discrepancy in GitHub repository healthchecks/healthchecks prior to v2.6.

CVE-2023-2766
OA General ⚡ nuclei
5.3
MEDIUM
EPSS
91.8%
2023 CWE-552 0 PoCs

A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini. The manipulation leads to files or directories accessible. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-229271. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-3817
OpenSSL General
5.3
MEDIUM
EPSS
0.3%
2023 CWE-606 1 PoC

Issue summary: Checking excessively long DH keys or parameters may be very slow. Impact summary: Applications that use the functions DH_check(), DH_check_ex() or EVP_PKEY_param_check() to check a DH key or DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial of Service. The function DH_check() performs various checks on DH parameters. After fixing CVE-2023-3446 it was discovered that a large q parameter value can also trigger an overly long computation during some of these checks. A

CVE-2023-1626
Antivirus General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-119 1 PoC

A vulnerability was found in Jianming Antivirus 16.2.2022.418. It has been declared as critical. This vulnerability affects unknown code in the library kvcore.sys of the component IoControlCode Handler. The manipulation leads to memory corruption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224008.

CVE-2023-22232
Connect General ⚡ nuclei
5.3
MEDIUM
EPSS
88.4%
2023 CWE-284 1 PoC

Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the integrity of a minor feature. Exploitation of this issue does not require user interaction.

CVE-2023-2417
Advanced Host Monitor General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-428 1 PoC

A vulnerability was found in ks-soft Advanced Host Monitor up to 12.56 and classified as problematic. Affected by this issue is some unknown functionality of the file C:\Program Files (x86)\HostMonitor\RMA-Win\rma_active.exe. The manipulation leads to unquoted search path. It is possible to launch the attack on the local host. Upgrading to version 12.60 is able to address this issue. It is recommended to upgrade the affected component. VDB-227714 is the identifier assigned to this vulnerability.

CVE-2023-28968
Junos OS Networking
5.3
MEDIUM
EPSS
0.5%
2023 CWE-1325 1 PoC

An Improperly Controlled Sequential Memory Allocation vulnerability in the Juniper Networks Deep Packet Inspection-Decoder (JDPI-Decoder) Application Signature component of Junos OS's AppID service on SRX Series devices will stop the JDPI-Decoder from identifying dynamic application traffic, allowing an unauthenticated network-based attacker to send traffic to the target device using the JDPI-Decoder, designed to inspect dynamic application traffic and take action upon this traffic, to instead begin to not take action and to pass the traffic through. An example session can be seen by running t

CVE-2023-25848
ArcGIS Enterprise Server General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-319 1 PoC

ArcGIS Enterprise Server versions 11.0 and below have an information disclosure vulnerability where a remote, unauthorized attacker may submit a crafted query that may result in a low severity information disclosure issue. The information disclosed is limited to a single attribute in a database connection string. No business data is disclosed.

CVE-2023-41763
🔥 KEV Skype for Business Server 2015 CU13 General ⚡ nuclei
5.3
MEDIUM
EPSS
16.5%
2023 CWE-918 0 PoCs

Skype for Business Elevation of Privilege Vulnerability

CVE-2023-26147
ithewei/libhv Web
5.3
MEDIUM
EPSS
0.1%
2023 CWE-113 1 PoC

All versions of the package ithewei/libhv are vulnerable to HTTP Response Splitting when untrusted user input is used to build headers values. An attacker can add the \r\n (carriage return line feeds) characters to end the HTTP response headers and inject malicious content, like for example additional headers or new response body, leading to a potential XSS vulnerability.

CVE-2023-3431
plantuml/plantuml General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.

CVE-2023-4512
Wireshark General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-674 1 PoC

CBOR dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file

CVE-2023-6780
glibc General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-131 4 PoCs

An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in undefined behavior. This issue affects glibc 2.37 and newer.

CVE-2023-2014
microweber/microweber Web
5.3
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository microweber/microweber prior to 1.3.3.

CVE-2023-0759
cockpit-hq/cockpit General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-268 1 PoC

Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8.

CVE-2023-26151
asyncua General
5.3
MEDIUM
EPSS
0.1%
2023 CWE-400 1 PoC

Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a result, the server will enter into an infinite loop and consume excessive memory.

CVE-2023-3012
gpac/gpac General
5.3
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2.

CVE-2023-46666
Elastic Sharepoint Online Python Connector Database Windows
5.3
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that user would have read permissions to all content on the Sharepoint site through Elasticsearch.

CVE-2023-1678
DriverGenius General
5.3
MEDIUM
EPSS
0.2%
2023 CWE-119 1 PoC

A vulnerability classified as critical has been found in DriverGenius 9.70.0.346. This affects the function 0x9C40A0D8/0x9C40A0DC/0x9C40A0E0 in the library mydrivers64.sys of the component IOCTL Handler. The manipulation leads to memory corruption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224235.

CVE-2023-1539
answerdev/answer General
5.3
MEDIUM
EPSS
0.4%
2023 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts in GitHub repository answerdev/answer prior to 1.0.6.