Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In May 2023
Memory corruption due to improper validation of array index in computer vision while testing EVA kernel without sending any frames.
CVSS Score
6.7
EPSS Score
0.0
Published
2023-05-02
Memory corruption in Qualcomm IPC due to use after free while receiving the incoming packet and reposting it.
CVSS Score
7.8
EPSS Score
0.001
Published
2023-05-02
Transient DOS due to NULL pointer dereference in Modem while performing pullup for received TCP/UDP packet.
CVSS Score
7.5
EPSS Score
0.001
Published
2023-05-02
Transient DOS due to NULL pointer dereference in Modem while sending invalid messages in DCCH.
CVSS Score
7.5
EPSS Score
0.001
Published
2023-05-02
Memory corruption in Automotive due to Improper Restriction of Operations within the Bounds of a Memory Buffer while exporting a shared key.
CVSS Score
7.8
EPSS Score
0.001
Published
2023-05-02
3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote attackers to read %WINDIR%\system32 files via /Electron/download directory traversal in conjunction with a path component that has a drive letter and uses backslash characters. NOTE: this issue exists because of an incomplete fix for CVE-2022-28005.
CVSS Score
7.5
EPSS Score
0.003
Published
2023-05-02
In affected versions of Octopus Deploy it is possible to unmask variable secrets using the variable preview function
CVSS Score
5.3
EPSS Score
0.003
Published
2023-05-02
3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electron/download directory traversal. Files may have credentials, full backups, call recordings, and chat logs.
CVSS Score
7.5
EPSS Score
0.005
Published
2023-05-02
A vulnerability, which was classified as problematic, has been found in Mail Subscribe List Plugin up to 2.0.10 on WordPress. This issue affects some unknown processing of the file index.php. The manipulation of the argument sml_name/sml_email leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 2.1 is able to address this issue. The identifier of the patch is 484970ef8285cae51d2de3bd4e4684d33c956c28. It is recommended to upgrade the affected component. The identifier VDB-227765 was assigned to this vulnerability.
CVSS Score
3.5
EPSS Score
0.001
Published
2023-05-02
A vulnerability classified as problematic was found in BestWebSoft Job Board Plugin 1.0.0 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.0.1 is able to address this issue. The name of the patch is dbb71deee071422ce3e663fbcdce3ad24886f940. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-227764.
CVSS Score
3.5
EPSS Score
0.001
Published
2023-05-02


Contact Us

Shodan ® - All rights reserved