7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-31004
Security Verify Access Appliance DevOps
8.3
HIGH
EPSS
0.1%
2023 CWE-300 1 PoC

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a remote attacker to gain access to the underlying system using man in the middle techniques. IBM X-Force ID: 254765.

CVE-2023-1878
thorsten/phpmyfaq Web
8.3
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2023-40284
Software Genérico Web
8.3
HIGH
EPSS
0.7%
2023 1 PoC

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

CVE-2023-6263
NxCloud Cloud
8.3
HIGH
EPSS
0.2%
2023 CWE-290 1 PoC

An issue was discovered by IPVM team in Network Optix NxCloud before 23.1.0.40440. It was possible to add a fake VMS server to NxCloud by using the exact identification of a legitimate VMS server. As result, it was possible to retrieve authorization headers from legitimate users when the legitimate client connects to the fake VMS server.

CVE-2023-2948
openemr/openemr Web ⚡ nuclei
8.3
HIGH
EPSS
84.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.1.

CVE-2023-1535
answerdev/answer Web
8.3
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.7.

CVE-2023-42931
macOS General
8.3
HIGH
EPSS
2.8%
2023 2 PoCs

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. A process may gain admin privileges without proper authentication.

CVE-2023-0880
thorsten/phpmyfaq Web
8.3
HIGH
EPSS
0.4%
2023 CWE-115 1 PoC

Misinterpretation of Input in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

CVE-2023-21923
Health Sciences InForm Web Database
8.3
HIGH
EPSS
1.1%
2023 1 PoC

Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Health Sciences InForm accessible data as well as unauthorized access to critical data or complete access to all Oracle

CVE-2023-32226
Sysaid General
8.3
HIGH
EPSS
0.1%
2023 CWE-552 1 PoC

Sysaid - CWE-552: Files or Directories Accessible to External Parties -  Authenticated users may exfiltrate files from the server via an unspecified method.

CVE-2023-1887
thorsten/phpmyfaq Web
8.3
HIGH
EPSS
0.3%
2023 CWE-840 1 PoC

Business Logic Errors in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2023-40290
Software Genérico Web Windows
8.3
HIGH
EPSS
0.7%
2023 1 PoC

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue that affects Internet Explorer 11 on Windows.

CVE-2023-40000
LiteSpeed Cache Web ⚡ nuclei
8.3
HIGH
EPSS
82.0%
2023 CWE-79 2 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through 5.7.

CVE-2023-2949
openemr/openemr Web ⚡ nuclei
8.3
HIGH
EPSS
71.8%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.1.

CVE-2023-40465
ALEOS General
8.3
HIGH
EPSS
0.0%
2023 CWE-121 1 PoC

Several versions of ALEOS, including ALEOS 4.16.0, include an opensource third-party component which can be exploited from the local area network, resulting in a Denial of Service condition for the captive portal.

CVE-2023-3243
BCM-WEB General
8.3
HIGH
EPSS
0.1%
2023 CWE-290 1 PoC

** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an authenticating hash and utilize it to create new sessions. The hash is also a poorly salted MD5 hash, which could result in a successful brute force password attack. Impacted product is BCM-WEB version 3.3.X. Recommended fix: Upgrade to a supported product such as Alerton ACM.] Out of an abundance of caution, this CVE ID is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded. 

CVE-2023-5319
thorsten/phpmyfaq Web
8.3
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.18.

CVE-2023-0794
thorsten/phpmyfaq Web
8.3
HIGH
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

CVE-2023-3548
IQ Wifi 6 General
8.3
HIGH
EPSS
0.2%
2023 CWE-307 1 PoC

An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack.

CVE-2023-4815
answerdev/answer General
8.3
HIGH
EPSS
0.1%
2023 CWE-306 1 PoC

Missing Authentication for Critical Function in GitHub repository answerdev/answer prior to v1.1.3.