9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-42560
Samsung Mobile Devices General
7.4
HIGH
EPSS
0.1%
2023 1 PoC

Heap out-of-bounds write vulnerability in dec_mono_audb of libsavsac.so prior to SMR Dec-2023 Release 1 allows an attacker to execute arbitrary code.

CVE-2023-26459
NetWeaver AS for ABAP and ABAP Platform General
7.4
HIGH
EPSS
0.2%
2023 CWE-918 1 PoC

Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, an attacker authenticated as a non-administrative user can craft a request which will trigger the application server to send a request to an arbitrary URL which can reveal, modify or make unavailable non-sensitive information, leading to low impact on Confidentiality, Integrity and Availability.

CVE-2023-26219
TIBCO Hawk General
7.4
HIGH
EPSS
0.2%
2023 1 PoC

The Hawk Console and Hawk Agent components of TIBCO Software Inc.'s TIBCO Hawk, TIBCO Hawk Distribution for TIBCO Silver Fabric, TIBCO Operational Intelligence Hawk RedTail, and TIBCO Runtime Agent contain a vulnerability that theoretically allows an attacker with access to the Hawk Console’s and Agent’s log to obtain credentials used to access associated EMS servers. Affected releases are TIBCO Software Inc.'s TIBCO Hawk: versions 6.2.2 and below, TIBCO Hawk Distribution for TIBCO Silver Fabric: versions 6.2.2 and below, TIBCO Operational Intelligence Hawk RedTail: versions 7.2.1 and below, a

CVE-2023-34059
open-vm-tools General
7.4
HIGH
EPSS
0.1%
2023 3 PoCs

open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.

CVE-2023-45185
i Access Client Solutions General
7.4
HIGH
EPSS
1.5%
2023 CWE-863 1 PoC

IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code. Due to improper authority checks the attacker could perform operations on the PC under the user's authority. IBM X-Force ID: 268273.

CVE-2023-0509
pyload/pyload General
7.4
HIGH
EPSS
0.1%
2023 CWE-295 1 PoC

Improper Certificate Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev44.

CVE-2023-26145
pydash General
7.4
HIGH
EPSS
1.8%
2023 CWE-78 1 PoC

This affects versions of the package pydash before 6.0.0. A number of pydash methods such as pydash.objects.invoke() and pydash.collections.invoke_map() accept dotted paths (Deep Path Strings) to target a nested Python object, relative to the original source object. These paths can be used to target internal class attributes and dict items, to retrieve, modify or invoke nested Python objects. **Note:** The pydash.objects.invoke() method is vulnerable to Command Injection when the following prerequisites are satisfied: 1) The source object (argument 1) is not a built-in object such as list/d

CVE-2023-1514
RTU500 Scripting Interface General
7.4
HIGH
EPSS
0.1%
2023 CWE-295 1 PoC

A vulnerability exists in the component RTU500 Scripting interface. When a client connects to a server using TLS, the server presents a certificate. This certificate links a public key to the identity of the service and is signed by a Certification Authority (CA), allowing the client to validate that the remote service can be trusted and is not malicious. If the client does not validate the parameters of the certificate, then attackers could be able to spoof the identity of the service. An attacker could exploit the vulnerability by using faking the identity of a RTU500 device and intercepting

CVE-2023-5394
Experion Server General
7.4
HIGH
EPSS
0.9%
2023 CWE-119 1 PoC

Server receiving a malformed message that where the GCL message hostname may be too large which may cause a stack overflow; resulting in possible remote code execution. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-5396
Experion Server General
7.4
HIGH
EPSS
0.9%
2023 CWE-805 1 PoC

Server receiving a malformed message creates connection for a hostname that may cause a stack overflow resulting in possible remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-5393
Experion Server General
7.4
HIGH
EPSS
1.2%
2023 CWE-130 1 PoC

Server receiving a malformed message that causes a disconnect to a hostname may causing a stack overflow resulting in possible remote code execution. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-45182
i Access Client Solutions General
7.4
HIGH
EPSS
0.6%
2023 CWE-922 1 PoC

IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is vulnerable to having its key for an encrypted password decoded. By somehow gaining access to the encrypted password, a local attacker could exploit this vulnerability to obtain the password to other systems. IBM X-Force ID: 268265.

CVE-2024-27158
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.4
HIGH
EPSS
0.0%
2024 CWE-1392 1 PoC

All the Toshiba printers share the same hardcoded root password. As for the affected products/models/versions, see the reference URL.

CVE-2024-0023
Android General
7.4
HIGH
EPSS
3.7%
2024 3 PoCs

In ConvertRGBToPlanarYUV of Codec2BufferUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-27167
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.4
HIGH
EPSS
0.1%
2024 CWE-276 1 PoC

Toshiba printers use Sendmail to send emails to recipients. Sendmail is used with several insecure directories. A local attacker can inject a malicious Sendmail configuration file. As for the affected products/models/versions, see the reference URL.

CVE-2024-20767
🔥 KEV ColdFusion General ⚡ nuclei
7.4
HIGH
EPSS
94.0%
2024 CWE-284 6 PoCs

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet.

CVE-2024-27171
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.4
HIGH
EPSS
1.7%
2024 CWE-276 1 PoC

A remote attacker using the insecure upload functionality will be able to overwrite any Python file and get Remote Code Execution. As for the affected products/models/versions, see the reference URL.

CVE-2024-27149
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.4
HIGH
EPSS
0.1%
2024 CWE-276 1 PoC

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see the reference URL.

CVE-2024-27151
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.4
HIGH
EPSS
0.6%
2024 CWE-276 1 PoC

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. The programs can be replaced by malicious programs by any local or remote attacker. As for the affected products/models/versions, see the reference URL.

CVE-2024-27150
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.4
HIGH
EPSS
0.1%
2024 CWE-276 1 PoC

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see the reference URL.