Skip to content

Commit

Permalink
Commit from GitHub Actions (Update Notebook)
Browse files Browse the repository at this point in the history
  • Loading branch information
github-actions[bot] committed Nov 14, 2023
1 parent 3599033 commit 187f1d8
Show file tree
Hide file tree
Showing 3 changed files with 35 additions and 29 deletions.
58 changes: 29 additions & 29 deletions KEV-EPSS.ipynb

Large diffs are not rendered by default.

6 changes: 6 additions & 0 deletions epss_kev_nvd.csv
Original file line number Diff line number Diff line change
Expand Up @@ -1027,3 +1027,9 @@ CVE-2023-46747,9.8,0.96984,0.99668,F5 BIG-IP Configuration utility contains an a
CVE-2023-46604,9.8,0.96733,0.99562,Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.
CVE-2023-22518,9.8,0.96763,0.99575,Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.
CVE-2023-29552,7.5,0.16321,0.95457,"The Service Location Protocol (SLP) contains a denial-of-service (DoS) vulnerability that could allow an unauthenticated, remote attacker to register services and use spoofed UDP traffic to conduct a denial-of-service (DoS) attack with a significant amplification factor."
CVE-2023-47246,,0.00046,0.14381,SysAid Server (on-premises version) contains a path traversal vulnerability that leads to code execution.
CVE-2023-36844,5.3,0.02557,0.89058,"Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify certain PHP environment variables, leading to partial loss of integrity, which may allow chaining to other vulnerabilities."
CVE-2023-36845,9.8,0.37937,0.96839,"Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment variable. Using a crafted request, which sets the variable PHPRC, an attacker is able to modify the PHP execution environment allowing the injection und execution of code."
CVE-2023-36846,5.3,0.00043,0.07354,"Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities."
CVE-2023-36847,5.3,0.00043,0.07354,"Juniper Junos OS on EX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities."
CVE-2023-36851,5.3,0.00046,0.14366,"Juniper Junos OS on SRX Series contains a missing authentication for critical function vulnerability that allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.php that doesn't require authentication, an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities."
Binary file modified epss_kev_nvd.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.

0 comments on commit 187f1d8

Please sign in to comment.