7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-5846
TS-550 General
8.3
HIGH
EPSS
0.0%
2023 CWE-916 1 PoC

Franklin Fueling System TS-550 versions prior to 1.9.23.8960 are vulnerable to attackers decoding admin credentials, resulting in unauthenticated access to the device.

CVE-2023-1527
tsolucio/corebos Web
8.3
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository tsolucio/corebos prior to 8.0.

CVE-2023-0227
pyload/pyload General
8.3
HIGH
EPSS
0.1%
2023 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository pyload/pyload prior to 0.5.0b3.dev36.

CVE-2023-26153
geokit-rails Web
8.3
HIGH
EPSS
0.3%
2023 CWE-78 1 PoC

Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value. **Note:** An attacker can use this vulnerability to execute commands on the host system.

CVE-2023-45235
edk2 General
8.3
HIGH
EPSS
0.4%
2023 CWE-119 1 PoC

EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.

CVE-2023-4196
cockpit-hq/cockpit Web
8.3
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

CVE-2023-0954
Illustra Pro Gen 4 Dome General
8.3
HIGH
EPSS
0.1%
2023 CWE-489 1 PoC

A debug feature in Sensormatic Electronics Illustra Pro Gen 4 Dome and PTZ cameras allows a user to compromise credentials after a long period of sustained attack.

CVE-2023-45744
Smart Reader Web
8.3
HIGH
EPSS
0.7%
2023 CWE-284 2 PoCs

A data integrity vulnerability exists in the web interface /cgi-bin/upload_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to configuration modification. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

CVE-2023-40287
Software Genérico Web
8.3
HIGH
EPSS
0.7%
2023 1 PoC

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

CVE-2023-3188
owncast/owncast General ⚡ nuclei
8.3
HIGH
EPSS
48.7%
2023 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository owncast/owncast prior to 0.1.0.

CVE-2023-1880
thorsten/phpmyfaq Web ⚡ nuclei
8.3
HIGH
EPSS
14.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2023-40288
Software Genérico Web
8.3
HIGH
EPSS
0.7%
2023 1 PoC

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

CVE-2023-32220
NCR/camera General
8.2
HIGH
EPSS
0.0%
2023 1 PoC

Milesight NCR/camera version 71.8.0.6-r5 allows authentication bypass through an unspecified method.

CVE-2023-30845
esp-v2 Web
8.2
HIGH
EPSS
0.2%
2023 CWE-287 1 PoC

ESPv2 is a service proxy that provides API management capabilities using Google Service Infrastructure. ESPv2 2.20.0 through 2.42.0 contains an authentication bypass vulnerability. API clients can craft a malicious `X-HTTP-Method-Override` header value to bypass JWT authentication in specific cases. ESPv2 allows malicious requests to bypass authentication if both the conditions are true: The requested HTTP method is **not** in the API service definition (OpenAPI spec or gRPC `google.api.http` proto annotations, and the specified `X-HTTP-Method-Override` is a valid HTTP method in the API servi

CVE-2023-2186
SCADA Data Gateway General
8.2
HIGH
EPSS
0.4%
2023 CWE-134 1 PoC

On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send a specially crafted broadcast message including format string characters to the SCADA Data Gateway to perform unrestricted memory reads.An unauthenticated user can use this format string vulnerability to repeatedly crash the GTWWebMonitor.exe process to DoS the Web Monitor. Furthermore, an authenticated user can leverage this vulnerability to leak memory from the GTWWebMonitor.exe process. This

CVE-2023-33244
Software Genérico Web
8.2
HIGH
EPSS
0.1%
2023 1 PoC

Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an embedded web page.

CVE-2023-7009
Kontrol Lux General
8.2
HIGH
EPSS
0.0%
2023 1 PoC

Some Sciener-based locks support plaintext message processing over Bluetooth Low Energy, allowing unencrypted malicious commands to be passed to the lock. These malicious commands, less then 16 bytes in length, will be processed by the lock as if they were encrypted communications. This can be further exploited by an attacker to compromise the lock's integrity.

CVE-2023-6549
🔥 KEV NetScaler ADC General ⚡ nuclei
8.2
HIGH
EPSS
76.5%
2023 CWE-119 0 PoCs

Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read

CVE-2023-34116
Zoom Desktop Client for Windows Windows
8.2
HIGH
EPSS
0.4%
2023 CWE-78 1 PoC

Improper input validation in the Zoom Desktop Client for Windows before version 5.15.0 may allow an unauthorized user to enable an escalation of privilege via network access.

CVE-2023-30744
SAP AS NetWeaver JAVA Web
8.2
HIGH
EPSS
0.3%
2023 CWE-306 1 PoC

In SAP AS NetWeaver JAVA - versions SERVERCORE 7.50, J2EE-FRMW 7.50, CORE-TOOLS 7.50, an unauthenticated attacker can attach to an open interface and make use of an open naming and directory API to instantiate an object which has methods which can be called without further authorization and authentication.  A subsequent call to one of these methods can read or change the state of existing services without any effect on availability.