#ExploitObserverAlert
CVE-2023-43885
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-43885. Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attackers to arbitrarily lock the device.
FIRST-EPSS: 0.000450000
NVD-IS: 5.2
NVD-ES: 2.8
CVE-2023-43885
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-43885. Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attackers to arbitrarily lock the device.
FIRST-EPSS: 0.000450000
NVD-IS: 5.2
NVD-ES: 2.8
#ExploitObserverAlert
CVE-2023-24588
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-24588. Exposure of sensitive information to an unauthorized actor in firmware for some Intel(R) Optane(TM) SSD products may allow an unauthenticated user to potentially enable information disclosure via physical access.
FIRST-EPSS: 0.000540000
NVD-IS: 3.6
NVD-ES: 0.9
CVE-2023-24588
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-24588. Exposure of sensitive information to an unauthorized actor in firmware for some Intel(R) Optane(TM) SSD products may allow an unauthenticated user to potentially enable information disclosure via physical access.
FIRST-EPSS: 0.000540000
NVD-IS: 3.6
NVD-ES: 0.9
#ExploitObserverAlert
CVE-2023-6792
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-6792. An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated API user to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.
FIRST-EPSS: 0.000420000
NVD-IS: 3.4
NVD-ES: 2.8
CVE-2023-6792
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-6792. An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated API user to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall.
FIRST-EPSS: 0.000420000
NVD-IS: 3.4
NVD-ES: 2.8
#ExploitObserverAlert
CVE-2023-3740
DESCRIPTION: Exploit Observer has 3 entries related to CVE-2023-3740. Insufficient validation of untrusted input in Themes in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially serve malicious content to a user via a crafted background URL. (Chromium security severity: Low)
FIRST-EPSS: 0.000880000
NVD-IS: 1.4
NVD-ES: 2.8
CVE-2023-3740
DESCRIPTION: Exploit Observer has 3 entries related to CVE-2023-3740. Insufficient validation of untrusted input in Themes in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially serve malicious content to a user via a crafted background URL. (Chromium security severity: Low)
FIRST-EPSS: 0.000880000
NVD-IS: 1.4
NVD-ES: 2.8
#ExploitObserverAlert
CVE-2023-36881
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-36881. Azure Apache Ambari Spoofing Vulnerability
FIRST-EPSS: 0.000510000
NVD-IS: 3.6
NVD-ES: 0.9
CVE-2023-36881
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-36881. Azure Apache Ambari Spoofing Vulnerability
FIRST-EPSS: 0.000510000
NVD-IS: 3.6
NVD-ES: 0.9
#ExploitObserverAlert
CVE-2023-23552
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-23552. On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.0 before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP Advanced WAF or BIG-IP ASM security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
FIRST-EPSS: 0.000460000
NVD-IS: 3.6
NVD-ES: 3.9
CVE-2023-23552
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-23552. On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.0 before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP Advanced WAF or BIG-IP ASM security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
FIRST-EPSS: 0.000460000
NVD-IS: 3.6
NVD-ES: 3.9
#ExploitObserverAlert
CVE-2023-48312
DESCRIPTION: Exploit Observer has 2 entries related to CVE-2023-48312. capsule-proxy is a reverse proxy for the capsule operator project. Affected versions are subject to a privilege escalation vulnerability which is based on a missing check if the user is authenticated based on the `TokenReview` result. All the clusters running with the `anonymous-auth` Kubernetes API Server setting disable (set to `false`) are affected since it would be possible to bypass the token review mechanism, interacting with the upper Kubernetes API Server. This privilege escalation cannot be exploited if you're relying only on client certificates (SSL/TLS). This vulnerability has been addressed in version 0.4.6. Users are advised to upgrade.
FIRST-EPSS: 0.000610000
NVD-IS: 5.9
NVD-ES: 3.9
CVE-2023-48312
DESCRIPTION: Exploit Observer has 2 entries related to CVE-2023-48312. capsule-proxy is a reverse proxy for the capsule operator project. Affected versions are subject to a privilege escalation vulnerability which is based on a missing check if the user is authenticated based on the `TokenReview` result. All the clusters running with the `anonymous-auth` Kubernetes API Server setting disable (set to `false`) are affected since it would be possible to bypass the token review mechanism, interacting with the upper Kubernetes API Server. This privilege escalation cannot be exploited if you're relying only on client certificates (SSL/TLS). This vulnerability has been addressed in version 0.4.6. Users are advised to upgrade.
FIRST-EPSS: 0.000610000
NVD-IS: 5.9
NVD-ES: 3.9
#ExploitObserverAlert
CVE-2023-27915
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-27915. A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
FIRST-EPSS: 0.000550000
NVD-IS: 5.9
NVD-ES: 1.8
CVE-2023-27915
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-27915. A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
FIRST-EPSS: 0.000550000
NVD-IS: 5.9
NVD-ES: 1.8
#ExploitObserverAlert
GHSA-gc57-xhh5-m94r
DESCRIPTION: Exploit Observer has 3 entries related to GHSA-GC57-XHH5-M94R. The endpoint /api/collaboration/{id}/task is used to collect all tasks from a certain collaboration. To get such tasks, a user should have permission to view the collaboration and to view the tasks in it. However, currently it is only checked if the user has permission to view the collaboration.
GHSS: 5.4
GHSA-gc57-xhh5-m94r
DESCRIPTION: Exploit Observer has 3 entries related to GHSA-GC57-XHH5-M94R. The endpoint /api/collaboration/{id}/task is used to collect all tasks from a certain collaboration. To get such tasks, a user should have permission to view the collaboration and to view the tasks in it. However, currently it is only checked if the user has permission to view the collaboration.
GHSS: 5.4
#ExploitObserverAlert
CVE-2023-30517
DESCRIPTION: Exploit Observer has 2 entries related to CVE-2023-30517. Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting to a configured NeuVector Vulnerability Scanner server.
FIRST-EPSS: 0.000460000
NVD-IS: 1.4
NVD-ES: 3.9
CVE-2023-30517
DESCRIPTION: Exploit Observer has 2 entries related to CVE-2023-30517. Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting to a configured NeuVector Vulnerability Scanner server.
FIRST-EPSS: 0.000460000
NVD-IS: 1.4
NVD-ES: 3.9
#ExploitObserverAlert
CVE-2023-6105
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-6105. An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.
FIRST-EPSS: 0.000420000
NVD-IS: 3.6
NVD-ES: 1.8
CVE-2023-6105
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-6105. An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.
FIRST-EPSS: 0.000420000
NVD-IS: 3.6
NVD-ES: 1.8
#ExploitObserverAlert
GHSA-whj9-m24x-qhhp
DESCRIPTION: Exploit Observer has 4 entries related to GHSA-WHJ9-M24X-QHHP. Before 2.6.3
GHSS: 6.2
GHSA-whj9-m24x-qhhp
DESCRIPTION: Exploit Observer has 4 entries related to GHSA-WHJ9-M24X-QHHP. Before 2.6.3
GHSS: 6.2
#ExploitObserverAlert
CVE-2023-49447
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-49447. JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/update.
FIRST-EPSS: 0.000580000
NVD-IS: 5.9
NVD-ES: 2.8
CVE-2023-49447
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-49447. JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/update.
FIRST-EPSS: 0.000580000
NVD-IS: 5.9
NVD-ES: 2.8
#ExploitObserverAlert
CVE-2023-21993
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-21993. Vulnerability in the Oracle Clinical Remote Data Capture product of Oracle Health Sciences Applications (component: Forms). The supported version that is affected is 5.4.0.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Clinical Remote Data Capture. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Clinical Remote Data Capture accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
FIRST-EPSS: 0.000470000
NVD-IS: 3.6
NVD-ES: 2.8
CVE-2023-21993
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-21993. Vulnerability in the Oracle Clinical Remote Data Capture product of Oracle Health Sciences Applications (component: Forms). The supported version that is affected is 5.4.0.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Clinical Remote Data Capture. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Clinical Remote Data Capture accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
FIRST-EPSS: 0.000470000
NVD-IS: 3.6
NVD-ES: 2.8
#ExploitObserverAlert
CVE-2023-36720
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-36720. Windows Mixed Reality Developer Tools Denial of Service Vulnerability
FIRST-EPSS: 0.000990000
NVD-IS: 3.6
NVD-ES: 3.9
CVE-2023-36720
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-36720. Windows Mixed Reality Developer Tools Denial of Service Vulnerability
FIRST-EPSS: 0.000990000
NVD-IS: 3.6
NVD-ES: 3.9
#ExploitObserverAlert
CVE-2023-49819
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-49819. Deserialization of Untrusted Data vulnerability in Gordon Böhme, Antonio Leutsch Structured Content (JSON-LD) #wpsc.This issue affects Structured Content (JSON-LD) #wpsc: from n/a through 1.5.3.
NVD-IS: 5.9
NVD-ES: 3.9
CVE-2023-49819
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-49819. Deserialization of Untrusted Data vulnerability in Gordon Böhme, Antonio Leutsch Structured Content (JSON-LD) #wpsc.This issue affects Structured Content (JSON-LD) #wpsc: from n/a through 1.5.3.
NVD-IS: 5.9
NVD-ES: 3.9
#ExploitObserverAlert
CVE-2023-43645
DESCRIPTION: Exploit Observer has 2 entries related to CVE-2023-43645. OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA is vulnerable to a denial of service attack when certain Check calls are executed against authorization models that contain circular relationship definitions. When the call is made, it's possible for the server to exhaust resources and die. Users are advised to upgrade to v1.3.2 and update any offending models. There are no known workarounds for this vulnerability. Note that for models which contained cycles or a relation definition that has the relation itself in its evaluation path, checks and queries that require evaluation will no longer be evaluated on v1.3.2+ and will return errors instead. Users who do not have cyclic models are unaffected.
FIRST-EPSS: 0.000460000
NVD-IS: 3.6
NVD-ES: 2.2
CVE-2023-43645
DESCRIPTION: Exploit Observer has 2 entries related to CVE-2023-43645. OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA is vulnerable to a denial of service attack when certain Check calls are executed against authorization models that contain circular relationship definitions. When the call is made, it's possible for the server to exhaust resources and die. Users are advised to upgrade to v1.3.2 and update any offending models. There are no known workarounds for this vulnerability. Note that for models which contained cycles or a relation definition that has the relation itself in its evaluation path, checks and queries that require evaluation will no longer be evaluated on v1.3.2+ and will return errors instead. Users who do not have cyclic models are unaffected.
FIRST-EPSS: 0.000460000
NVD-IS: 3.6
NVD-ES: 2.2
#ExploitObserverAlert
CVE-2023-1690
DESCRIPTION: Exploit Observer has 2 entries related to CVE-2023-1690. A vulnerability, which was classified as problematic, has been found in SourceCodester Earnings and Expense Tracker App 1.0. This issue affects some unknown processing of the file LoginRegistration.php?a=register_user. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-224309 was assigned to this vulnerability.
FIRST-EPSS: 0.000460000
NVD-IS: 2.7
NVD-ES: 2.8
CVE-2023-1690
DESCRIPTION: Exploit Observer has 2 entries related to CVE-2023-1690. A vulnerability, which was classified as problematic, has been found in SourceCodester Earnings and Expense Tracker App 1.0. This issue affects some unknown processing of the file LoginRegistration.php?a=register_user. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-224309 was assigned to this vulnerability.
FIRST-EPSS: 0.000460000
NVD-IS: 2.7
NVD-ES: 2.8
#ExploitObserverAlert
CVE-2023-41367
DESCRIPTION: Exploit Observer has 2 entries related to CVE-2023-41367. Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain access to admin view of specific function anonymously. On successful exploitation of vulnerability under specific circumstances, attacker can view user’s email address. There is no integrity/availability impact.
FIRST-EPSS: 0.000460000
NVD-IS: 1.4
NVD-ES: 3.9
CVE-2023-41367
DESCRIPTION: Exploit Observer has 2 entries related to CVE-2023-41367. Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain access to admin view of specific function anonymously. On successful exploitation of vulnerability under specific circumstances, attacker can view user’s email address. There is no integrity/availability impact.
FIRST-EPSS: 0.000460000
NVD-IS: 1.4
NVD-ES: 3.9
#ExploitObserverAlert
CVE-2023-4373
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-4373. Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature.
FIRST-EPSS: 0.001340000
NVD-IS: 5.9
NVD-ES: 3.9
CVE-2023-4373
DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-4373. Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature.
FIRST-EPSS: 0.001340000
NVD-IS: 5.9
NVD-ES: 3.9
#ExploitObserverAlert
CVE-2023-22046
DESCRIPTION: Exploit Observer has 5 entries related to CVE-2023-22046. Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
FIRST-EPSS: 0.000830000
NVD-IS: 3.6
NVD-ES: 1.2
CVE-2023-22046
DESCRIPTION: Exploit Observer has 5 entries related to CVE-2023-22046. Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
FIRST-EPSS: 0.000830000
NVD-IS: 3.6
NVD-ES: 1.2