7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-22048
MySQL Server Database
3.1
LOW
EPSS
0.1%
2023 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are 8.0.33 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVE-2023-0057
pyload/pyload General
3.1
LOW
EPSS
0.9%
2023 CWE-1021 1 PoC

Improper Restriction of Rendered UI Layers or Frames in GitHub repository pyload/pyload prior to 0.5.0b3.dev33.

CVE-2023-0055
pyload/pyload Web
3.1
LOW
EPSS
0.1%
2023 CWE-614 1 PoC

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository pyload/pyload prior to 0.5.0b3.dev32.

CVE-2023-6599
microweber/microweber General
3.1
LOW
EPSS
0.3%
2023 CWE-544 1 PoC

Missing Standardized Error Handling Mechanism in GitHub repository microweber/microweber prior to 2.0.

CVE-2023-2281
Mattermost General
3.1
LOW
EPSS
0.3%
2023 CWE-200 1 PoC

When archiving a team, Mattermost fails to sanitize the related Websocket event sent to currently connected clients. This allows the clients to see the name, display name, description, and other data about the archived team.

CVE-2023-47643
SuiteCRM-Core Web ⚡ nuclei
3.1
LOW
EPSS
49.6%
2023 CWE-200 0 PoCs

SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.4.2, Graphql Introspection is enabled without authentication, exposing the scheme defining all object types, arguments, and functions. An attacker can obtain the GraphQL schema and understand the entire attack surface of the API, including sensitive fields such as UserHash. This issue is patched in version 8.4.2. There are no known workarounds.

CVE-2023-6727
Mattermost General
3.1
LOW
EPSS
0.3%
2023 CWE-200 1 PoC

Mattermost fails to perform correct authorization checks when creating a playbook action, allowing users without access to the playbook to create playbook actions. If the playbook action created is to post a message in a channel based on specific keywords in a post, some playbook information, like the name, can be leaked. 

CVE-2023-3584
Mattermost Web
3.1
LOW
EPSS
0.1%
2023 CWE-863 1 PoC

Mattermost fails to properly check the authorization of POST /api/v4/teams when passing a team override scheme ID in the request, allowing an authenticated attacker with knowledge of a Team Override Scheme ID to create a new team with said team override scheme.

CVE-2023-35124
OAS Platform General
3.1
LOW
EPSS
0.1%
2023 CWE-209 1 PoC

An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to a disclosure of sensitive information. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-3515
go-gitea/gitea General
3.0
LOW
EPSS
0.1%
2023 CWE-601 1 PoC

Open Redirect in GitHub repository go-gitea/gitea prior to 1.19.4.

CVE-2023-41813
Pandora FMS Web
3.0
LOW
EPSS
0.5%
2023 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). Allows you to edit the Web Console user notification options. This issue affects Pandora FMS: from 700 through 774.

CVE-2023-2664
Xpdf General
2.9
LOW
EPSS
0.1%
2023 CWE-674 1 PoC

 In Xpdf 4.04 (and earlier), a PDF object loop in the embedded file tree leads to infinite recursion and a stack overflow.

CVE-2023-2662
Xpdf General
2.9
LOW
EPSS
0.0%
2023 CWE-369 1 PoC

In Xpdf 4.04 (and earlier), a bad color space object in the input PDF file can cause a divide-by-zero.

CVE-2023-2663
Xpdf General
2.9
LOW
EPSS
0.1%
2023 CWE-674 1 PoC

 In Xpdf 4.04 (and earlier), a PDF object loop in the page label tree leads to infinite recursion and a stack overflow.

CVE-2023-5920
Mattermost Desktop General
2.9
LOW
EPSS
0.1%
2023 CWE-200 1 PoC

Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input.

CVE-2023-32112
Vendor Master Hierarchy General
2.8
LOW
EPSS
0.1%
2023 CWE-862 1 PoC

Vendor Master Hierarchy - versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, SAP_APPL 606, SAP_APPL 616, SAP_APPL 617, SAP_APPL 618, S4CORE 100, does not perform necessary authorization checks for an authenticated user to access some of its function. This could lead to modification of data impacting the integrity of the system.

CVE-2023-1560
TinyTIFF General
2.8
LOW
EPSS
0.1%
2023 CWE-120 1 PoC

A vulnerability, which was classified as problematic, has been found in TinyTIFF 3.0.0.0. This issue affects some unknown processing of the file tinytiffreader.c of the component File Handler. The manipulation leads to buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The identifier VDB-223553 was assigned to this vulnerability.

CVE-2023-31028
nvJPEG2000 Library Windows
2.8
LOW
EPSS
0.0%
2023 CWE-20 1 PoC

NVIDIA nvJPEG2000 Library for Windows and Linux contains a vulnerability where improper input validation might enable an attacker to use a specially crafted input file. A successful exploit of this vulnerability might lead to a partial denial of service.

CVE-2023-28602
Zoom for Windows Client Windows
2.8
LOW
EPSS
0.1%
2023 CWE-347 1 PoC

Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially downgrade Zoom Client components to previous versions.

CVE-2023-4216
Orders Tracking for WooCommerce Web Windows
2.7
LOW
EPSS
0.1%
2023 1 PoC

The Orders Tracking for WooCommerce WordPress plugin before 1.2.6 doesn't validate the file_url parameter when importing a CSV file, allowing high privilege users with the manage_woocommerce capability to access any file on the web server via a Traversal attack. The content retrieved is however limited to the first line of the file.