Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In December 2023
Traefik is an open source HTTP reverse proxy and load balancer. When Traefik is configured to use the `HTTPChallenge` to generate and renew the Let's Encrypt TLS certificates, the delay authorized to solve the challenge (50 seconds) can be exploited by attackers to achieve a `slowloris attack`. This vulnerability has been patch in version 2.10.6 and 3.0.0-beta5. Users are advised to upgrade. Users unable to upgrade should replace the `HTTPChallenge` with the `TLSChallenge` or the `DNSChallenge`.
CVSS Score
5.9
EPSS Score
0.008
Published
2023-12-04
Microcks up to 1.17.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.
CVSS Score
9.8
EPSS Score
0.01
Published
2023-12-04
Ssolon <= 2.6.0 and <=2.5.12 is vulnerable to Deserialization of Untrusted Data.
CVSS Score
9.8
EPSS Score
0.009
Published
2023-12-04
An issue in the component /admin/api.plugs/script of ThinkAdmin v6.1.53 allows attackers to getshell via providing a crafted URL to download a malicious PHP file.
CVSS Score
8.8
EPSS Score
0.009
Published
2023-12-04
An arbitrary file upload vulnerability in the component /admin/api.upload/file of ThinkAdmin v6.1.53 allows attackers to execute arbitrary code via a crafted Zip file.
CVSS Score
8.8
EPSS Score
0.011
Published
2023-12-04
kkFileView v4.3.0 is vulnerable to Incorrect Access Control.
CVSS Score
6.1
EPSS Score
0.005
Published
2023-12-04
A Cross-Site Scripting (XSS) vulnerability in the recipe preparation component within /api/objects/recipes and note component within /api/objects/shopping_lists/ of Grocy <= 4.0.3 allows attackers to obtain the victim's cookies.
CVSS Score
5.4
EPSS Score
0.007
Published
2023-12-04
A vulnerability exists in the webserver that affects the RTU500 series product versions listed below. A malicious actor could perform cross-site scripting on the webserver due to an RDT language file being improperly sanitized.
CVSS Score
6.0
EPSS Score
0.004
Published
2023-12-04
A vulnerability exists in the HCI IEC 60870-5-104 that affects the RTU500 series product versions listed below. Incomplete or wrong received APDU frame layout may cause blocking on link layer. Error reason was an endless blocking when reading incoming frames on link layer with wrong length information of APDU or delayed reception of data octets. Only communication link of affected HCI IEC 60870-5-104 is blocked. If attack sequence stops the communication to the previously attacked link gets normal again.
CVSS Score
5.9
EPSS Score
0.004
Published
2023-12-04
EzViz Studio v2.2.0 is vulnerable to DLL hijacking.
CVSS Score
7.8
EPSS Score
0.005
Published
2023-12-04


Contact Us

Shodan ® - All rights reserved