7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-1115
pimcore/pimcore Web
7.6
HIGH
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.

CVE-2023-5808
System Management Unit (SMU) General
7.6
HIGH
EPSS
0.3%
2023 CWE-285 1 PoC

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be barred to that specific administrative role.

CVE-2023-3552
nilsteampassnet/teampass Web
7.6
HIGH
EPSS
0.3%
2023 CWE-116 1 PoC

Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

CVE-2023-2534
OTRS Web
7.6
HIGH
EPSS
0.4%
2023 CWE-285 1 PoC

Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticated attacker to track user behaviour and to gain live insight into overall system usage. User IDs can easily be correlated with real names e. g. via ticket histories by any user. (Fuzzing for garnering other adjacent user/sensitive data). Subscribing to all possible push events could also lead to performance implications on the server side, depending on the size of the installation and the number of active users. (Flooding)This issue affects OTRS: from 8.0.X before 8.0.32.

CVE-2023-0112
usememos/memos Web
7.6
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

CVE-2023-42571
Find My Mobile General
7.6
HIGH
EPSS
0.2%
2023 1 PoC

Abuse of remote unlock in Find My Mobile prior to version 7.3.13.4 allows physical attacker to unlock the device remotely by resetting the Samsung Account password with SMS verification when user lost the device.

CVE-2023-26439
OX App Suite Web Database
7.6
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

The cacheservice API could be abused to inject parameters with SQL syntax which was insufficiently sanitized before getting executed as SQL statement. Attackers with access to a local or restricted network were able to perform arbitrary SQL queries, discovering other users cached data. We have improved the input check for API calls and filter for potentially malicious content. No publicly available exploits are known.

CVE-2023-5865
thorsten/phpmyfaq Web
7.6
HIGH
EPSS
0.3%
2023 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository thorsten/phpmyfaq prior to 3.2.2.

CVE-2023-22060
Hyperion BI+ Web Database
7.6
HIGH
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle Hyperion Workspace product of Oracle Hyperion (component: UI and Visualization). The supported version that is affected is 11.2.13.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Workspace. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Workspace accessible data as well as unauthorized access to c

CVE-2023-26073
Software Genérico General
7.6
HIGH
EPSS
0.8%
2023 3 PoCs

An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient parameter validation when decoding the extended emergency number list.

CVE-2023-1238
answerdev/answer Web
7.6
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2023-5044
ingress-nginx DevOps Web
7.6
HIGH
EPSS
10.6%
2023 CWE-20 3 PoCs

Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.

CVE-2023-1536
answerdev/answer Web
7.6
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.7.

CVE-2023-26075
Software Genérico General
7.6
HIGH
EPSS
0.9%
2023 3 PoCs

An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. An intra-object overflow in the 5G MM message codec can occur due to insufficient parameter validation when decoding the Service Area List.

CVE-2023-3819
pimcore/pimcore General
7.6
HIGH
EPSS
0.0%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pimcore/pimcore prior to 10.6.4.

CVE-2023-4347
librenms/librenms Web
7.6
HIGH
EPSS
79.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.8.0.

CVE-2023-39214
Zoom SDK's General
7.6
HIGH
EPSS
0.4%
2023 CWE-749 1 PoC

Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.

CVE-2023-26076
Software Genérico General
7.6
HIGH
EPSS
0.7%
2023 2 PoCs

An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. An intra-object overflow in the 5G SM message codec can occur due to insufficient parameter validation when decoding reserved options.

CVE-2023-5043
ingress-nginx Web
7.6
HIGH
EPSS
4.9%
2023 CWE-20 1 PoC

Ingress nginx annotation injection causes arbitrary command execution.

CVE-2023-0289
craigk5n/webcalendar Web
7.6
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository craigk5n/webcalendar prior to master.