7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-21998
VM VirtualBox Database
4.6
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle VM VirtualBox a

CVE-2023-0736
wallabag/wallabag Web
4.6
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository wallabag/wallabag prior to 2.5.4.

CVE-2023-46668
Endpoint Web Database
4.6
MEDIUM
EPSS
0.3%
2023 CWE-532 1 PoC

If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the logging level is explicitly set to debug, and when Elastic Agent is simultaneously configured to collect and send those logs to Elasticsearch, then Elastic Agent API keys can be viewed in Elasticsearch in plaintext. These API keys could be used to write arbitrary data and read Elastic Endpoint user artifacts.

CVE-2023-30708
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.3%
2023 1 PoC

Improper authentication in SecSettings prior to SMR Sep-2023 Release 1 allows attacker to access Captive Portal Wi-Fi in Reactivation Lock status.

CVE-2023-22000
VM VirtualBox Database
4.6
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle VM VirtualBox a

CVE-2023-2943
openemr/openemr General
4.6
MEDIUM
EPSS
0.1%
2023 CWE-94 1 PoC

Code Injection in GitHub repository openemr/openemr prior to 7.0.1.

CVE-2023-5890
pkp/pkp-lib Web
4.6
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

CVE-2023-3067
zadam/trilium Web
4.6
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.59.4.

CVE-2023-3620
amauric/tarteaucitron.js Web
4.6
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository amauric/tarteaucitron.js prior to v1.13.1.

CVE-2023-21467
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.1%
2023 1 PoC

Error in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1 allows incorrect handling of unencrypted message.

CVE-2023-30676
Samsung Pass General
4.6
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass.

CVE-2023-0015
SAP BusinessObjects Business Intelligence Platform Web
4.6
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

In SAP BusinessObjects Business Intelligence Platform (Web Intelligence user interface) - version 420, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls directly the jsp of Web Intelligence DHTML may be vulnerable to XSS attacks. On successful exploitation an attacker can cause limited impact on confidentiality and integrity of the application.

CVE-2023-3230
fossbilling/fossbilling General
4.6
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

Missing Authorization in GitHub repository fossbilling/fossbilling prior to 0.5.0.

CVE-2023-30714
Samsung Mobile Devices DevOps
4.6
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper authorization vulnerability in FolderContainerDragDelegate in One UI Home prior to SMR Sep-2023 Release 1 allows physical attackers to change some settings of the folder lock.

CVE-2023-22001
VM VirtualBox Database
4.6
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle VM VirtualBox a

CVE-2023-1316
osticket/osticket Web
4.5
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.

CVE-2023-33992
SAP Business Warehouse and SAP BW/4HANA General
4.5
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

The SAP BW BICS communication layer in SAP Business Warehouse and SAP BW/4HANA - version SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 730, SAP_BW 750, DW4CORE 100, DW4CORE 200, DW4CORE 300, may expose unauthorized cell values to the data response. To be able to exploit this, the user still needs authorizations on the query as well as on the keyfigure/measure level. The missing check only affects the data level.

CVE-2023-23408
Azure HDInsight Web Cloud
4.5
MEDIUM
EPSS
7.6%
2023 CWE-79 1 PoC

Azure Apache Ambari Spoofing Vulnerability

CVE-2023-28096
opensips General
4.5
MEDIUM
EPSS
1.0%
2023 CWE-401 1 PoC

OpenSIPS, a Session Initiation Protocol (SIP) server implementation, has a memory leak starting in the 2.3 branch and priot to versions 3.1.8 and 3.2.5. The memory leak was detected in the function `parse_mi_request` while performing coverage-guided fuzzing. This issue can be reproduced by sending multiple requests of the form `{"jsonrpc": "2.0","method": "log_le`. This malformed message was tested against an instance of OpenSIPS via FIFO transport layer and was found to increase the memory consumption over time. To abuse this memory leak, attackers need to reach the management interface (MI)

CVE-2023-0023
Bank Account Management (Manage Banks) General
4.5
MEDIUM
EPSS
0.2%
2023 CWE-200 1 PoC

In SAP Bank Account Management (Manage Banks) application, when a user clicks a smart link to navigate to another app, personal data is shown directly in the URL. They might get captured in log files, bookmarks, and so on disclosing sensitive data of the application.