7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-4257
Zephyr General
7.6
HIGH
EPSS
0.4%
2023 CWE-120 1 PoC

Unchecked user input length in /subsys/net/l2/wifi/wifi_shell.c can cause buffer overflows.

CVE-2023-3294
saleor/react-storefront Web
7.6
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository saleor/react-storefront prior to c29aab226f07ca980cc19787dcef101e11b83ef7.

CVE-2023-1536
answerdev/answer Web
7.6
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.7.

CVE-2023-0112
usememos/memos Web
7.6
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

CVE-2023-0308
thorsten/phpmyfaq Web
7.6
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

CVE-2023-41789
Pandora FMS Web
7.6
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allows an attacker to perform cookie hijacking and log in as that user without the need for credentials. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-4818
A920 General
7.6
HIGH
EPSS
0.3%
2023 CWE-74 1 PoC

PAX A920 device allows to downgrade bootloader due to a bug in its version check. The signature is correctly checked and only bootloader signed by PAX can be used.  The attacker must have physical USB access to the device in order to exploit this vulnerability.

CVE-2023-6538
System Management Unit (SMU) General
7.6
HIGH
EPSS
5.3%
2023 CWE-285 1 PoC

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Server or combined Server+Storage administrative roles are able to access SMU configuration backup, that would normally be barred to those specific administrative roles.

CVE-2023-41790
Pandora FMS General
7.6
HIGH
EPSS
0.1%
2023 CWE-427 1 PoC

Uncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File Search Paths. This vulnerability allows to access the server configuration file and to compromise the database. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-2534
OTRS Web
7.6
HIGH
EPSS
0.4%
2023 CWE-285 1 PoC

Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and to gain live insight into overall system usage. User IDs can easily be correlated with real names e. g. via ticket histories by any user. (Fuzzing for garnering other adjacent user/sensitive data). Subscribing to all possible push events could also lead to performance implications on the server side, depending on the size of the installation and the number of active users. (Flooding)This issue affects OTRS: from 8.0.X before 8.0.32.

CVE-2023-3069
tsolucio/corebos General
7.6
HIGH
EPSS
0.1%
2023 CWE-620 1 PoC

Unverified Password Change in GitHub repository tsolucio/corebos prior to 8.

CVE-2023-41788
Pandora FMS Web
7.6
HIGH
EPSS
0.1%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Pandora FMS on all allows Accessing Functionality Not Properly Constrained by ACLs. This vulnerability allows attackers to execute code via PHP file uploads. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-5644
WP Mail Log Web Windows
7.6
HIGH
EPSS
0.1%
2023 1 PoC

The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with the Contributor role to view and delete data that should only be accessible to Admin users.

CVE-2023-26074
Software Genérico General
7.6
HIGH
EPSS
0.8%
2023 3 PoCs

An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123.. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient parameter validation when decoding operator-defined access category definitions.

CVE-2023-33248
Software Genérico General
7.6
HIGH
EPSS
0.7%
2023 2 PoCs

Amazon Alexa software version 8960323972 on Echo Dot 2nd generation and 3rd generation devices potentially allows attackers to deliver security-relevant commands via an audio signal between 16 and 22 kHz (often outside the range of human adult hearing). Commands at these frequencies are essentially never spoken by authorized actors, but a substantial fraction of the commands are successful.

CVE-2023-3552
nilsteampassnet/teampass Web
7.6
HIGH
EPSS
0.3%
2023 CWE-116 1 PoC

Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

CVE-2023-26439
OX App Suite Web Database
7.6
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

The cacheservice API could be abused to inject parameters with SQL syntax which was insufficiently sanitized before getting executed as SQL statement. Attackers with access to a local or restricted network were able to perform arbitrary SQL queries, discovering other users cached data. We have improved the input check for API calls and filter for potentially malicious content. No publicly available exploits are known.

CVE-2023-3725
Zephyr General
7.6
HIGH
EPSS
0.6%
2023 CWE-120 1 PoC

Potential buffer overflow vulnerability in the Zephyr CAN bus subsystem

CVE-2023-3070
tsolucio/corebos Web
7.6
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository tsolucio/corebos prior to 8.

CVE-2023-5865
thorsten/phpmyfaq Web
7.6
HIGH
EPSS
0.3%
2023 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository thorsten/phpmyfaq prior to 3.2.2.