9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-26114
code-server General
8.2
HIGH
EPSS
0.2%
2023 CWE-1385 1 PoC

Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.

CVE-2023-21501
Samsung Mobile Devices General
8.2
HIGH
EPSS
0.1%
2023 CWE-20 1 PoC

Improper input validation vulnerability in mPOS fiserve trustlet prior to SMR May-2023 Release 1 allows local attackers to execute arbitrary code.

CVE-2023-41806
Pandora FMS General
8.2
HIGH
EPSS
0.1%
2023 CWE-269 1 PoC

Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability causes that a bad privilege assignment could cause a DOS attack that affects the availability of the Pandora FMS server. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-27351
🔥 KEV NG General ⚡ nuclei
8.2
HIGH
EPSS
87.0%
2023 CWE-287 0 PoCs

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19226.

CVE-2023-3486
PaperCut NG General
8.2
HIGH
EPSS
2.3%
2023 CWE-434 1 PoC

An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s file storage. This could exhaust system resources and prevent the service from operating as expected.

CVE-2023-7007
Gateway G2 General
8.2
HIGH
EPSS
0.1%
2023 1 PoC

Sciener server does not validate connection requests from the GatewayG2, allowing an impersonation attack that provides the attacker the unlockKey field.

CVE-2023-28324
Ivanti Endpoint Manager General
8.2
HIGH
EPSS
79.9%
2023 1 PoC

A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.

CVE-2023-52169
Software Genérico General
8.2
HIGH
EPSS
0.2%
2023 1 PoC

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.

CVE-2023-4898
mintplex-labs/anything-llm General
8.2
HIGH
EPSS
0.1%
2023 CWE-305 1 PoC

Authentication Bypass by Primary Weakness in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.

CVE-2023-26158
mockjs General
8.2
HIGH
EPSS
0.1%
2023 CWE-1321 1 PoC

All versions of the package mockjs are vulnerable to Prototype Pollution via the Util.extend function due to missing check if the attribute resolves to the object prototype. By adding or modifying attributes of an object prototype, it is possible to create attributes that exist on every object, or replace critical attributes with malicious ones. This can be problematic if the software depends on existence or non-existence of certain attributes, or uses pre-defined attributes of object prototype (such as hasOwnProperty, toString or valueOf). User controlled inputs inside the extend() method of

CVE-2023-27326
Desktop General
8.2
HIGH
EPSS
2.8%
2023 CWE-22 2 PoCs

Parallels Desktop Toolgate Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate component. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to escalate privileges and execute arbitr

CVE-2023-43017
Security Verify Access Appliance General
8.2
HIGH
EPSS
0.0%
2023 CWE-295 1 PoC

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. IBM X-Force ID: 266155.

CVE-2023-26573
IDWeb General
8.2
HIGH
EPSS
0.2%
2023 CWE-306 1 PoC

Missing authentication in the SetDB method in IDAttend’s IDWeb application 3.1.052 and earlier allows denial of service or theft of database login credentials.

CVE-2023-21499
Samsung Mobile Devices General
8.2
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

Out-of-bounds write vulnerability in TA_Communication_mpos_encrypt_pin in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to execute arbitrary code.

CVE-2023-46805
🔥 KEV ICS General ⚡ nuclei
8.2
HIGH
EPSS
94.4%
2023 8 PoCs

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

CVE-2023-5760
Avast/Avg Antivirus General
8.2
HIGH
EPSS
0.1%
2023 CWE-367 1 PoC

A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be further exploited, allowing an attacker to gain full local privilege escalation on the system.This issue affects Avast/Avg Antivirus: 23.8.

CVE-2023-45539
Software Genérico General
8.2
HIGH
EPSS
0.0%
2023 1 PoC

HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unspecified other impact upon misinterpretation of a path_end rule, such as routing index.html#.png to a static server.

CVE-2023-0975
Trellix Agent General
8.2
HIGH
EPSS
0.0%
2023 CWE-281 1 PoC

A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/upgrade workflow, to replace one of the Agent’s executables before it can be executed. This allows the user to elevate their permissions.

CVE-2023-6779
glibc General
8.2
HIGH
EPSS
0.7%
2023 CWE-122 4 PoCs

An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a message bigger than INT_MAX bytes, leading to an incorrect calculation of the buffer size to store the message, resulting in an application crash. This issue affects glibc 2.37 and newer.

CVE-2023-26133
progressbar.js General
8.2
HIGH
EPSS
0.1%
2023 CWE-1321 1 PoC

All versions of the package progressbar.js are vulnerable to Prototype Pollution via the function extend() in the file utils.js.