7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-42494
v3.0.6433.1964 General
7.5
HIGH
EPSS
0.2%
2023 CWE-749 1 PoC

EisBaer Scada - CWE-749: Exposed Dangerous Method or Function

CVE-2023-46380
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2023 1 PoC

LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) send password-change requests via cleartext HTTP.

CVE-2023-27532
🔥 KEV Veeam Backup & Replication General
7.5
HIGH
EPSS
82.3%
2023 CWE-306 3 PoCs

Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.

CVE-2023-21964
WebLogic Server Database
7.5
HIGH
EPSS
0.9%
2023 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVE-2023-1809
Download Manager Web Windows
7.5
HIGH
EPSS
0.7%
2023 1 PoC

The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbitrary password-protected package files.

CVE-2023-28598
Zoom for Linux clients General
7.5
HIGH
EPSS
0.4%
2023 CWE-79 1 PoC

Zoom for Linux clients prior to 5.13.10 contain an HTML injection vulnerability. If a victim starts a chat with a malicious user it could result in a Zoom application crash.

CVE-2023-39611
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 2 PoCs

An issue in Software FX Chart FX 7 version 7.0.4962.20829 allows attackers to enumerate and read files from the local filesystem by sending crafted web requests.

CVE-2023-37216
SensMini M4 General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

AnaSystem SensMini M4 – Using the configuration tool, an authenticated user can cause Denial of Service for the device

CVE-2023-38370
Security Access Manager Docker DevOps
7.5
HIGH
EPSS
0.0%
2023 CWE-276 2 PoCs

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages. IBM X-Force ID: 261197.

CVE-2023-34614
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

An issue was discovered jmarsden/jsonij thru 0.5.2 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.

CVE-2023-6064
PayHere Payment Gateway Web Windows
7.5
HIGH
EPSS
0.5%
2023 1 PoC

The PayHere Payment Gateway WordPress plugin before 2.2.12 automatically creates publicly-accessible log files containing sensitive information when transactions occur.

CVE-2023-23132
Software Genérico Web
7.5
HIGH
EPSS
0.3%
2023 1 PoC

Selfwealth iOS mobile App 3.3.1 is vulnerable to Sensitive key disclosure. The application reveals hardcoded API keys.

CVE-2023-2916
InfiniteWP Client Web Windows
7.5
HIGH
EPSS
29.5%
2023 CWE-200 1 PoC

The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including configuration. It can only be exploited if the plugin has not been configured yet. If combined with another arbitrary plugin installation and activation vulnerability, it may be possible to connect a site to InfiniteWP which would make remote management possible and allow for elevation of privileges.

CVE-2023-22506
Bamboo Data Center General
7.5
HIGH
EPSS
3.7%
2023 3 PoCs

This High severity Injection and RCE (Remote Code Execution) vulnerability known as CVE-2023-22506 was introduced in version 8.0.0 of Bamboo Data Center.   This Injection and RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.5, allows an authenticated attacker to modify the actions taken by a system call and execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user interaction.     Atlassian recommends that you upgrade your instance to latest version. If you're unable to upgrade to latest, upgrade to one

CVE-2023-23330
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

amano Xparc parking solutions 7.1.3879 was discovered to be vulnerable to local file inclusion.

CVE-2023-52285
Software Genérico Web Database
7.5
HIGH
EPSS
0.1%
2023 1 PoC

ExamSys 9150244 allows SQL Injection via the /Support/action/Pages.php s_score2 parameter.

CVE-2023-24500
Electra Central AC unit General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW.

CVE-2023-25283
Software Genérico General
7.5
HIGH
EPSS
0.8%
2023 1 PoC

A stack overflow vulnerability in D-Link DIR820LA1_FW106B02 allows attackers to cause a denial of service via the reserveDHCP_HostName_1.1.1.0 parameter to lan.asp.

CVE-2023-49928
Software Genérico General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123, Exynos Modem 5300. The baseband software does not properly check states specified by the RRC. This can lead to disclosure of sensitive information.

CVE-2023-26106
dot-lens General
7.5
HIGH
EPSS
0.3%
2023 CWE-1321 1 PoC

All versions of the package dot-lens are vulnerable to Prototype Pollution via the set() function in index.js file.