9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-24059
Software Genérico General
7.3
HIGH
EPSS
9.3%
2023 1 PoC

Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January 2023.

CVE-2023-7261
Omaha General
7.3
HIGH
EPSS
0.0%
2023 2 PoCs

Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High)

CVE-2023-40109
Android General
7.3
HIGH
EPSS
0.0%
2023 1 PoC

In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVE-2023-0288
vim/vim General
7.3
HIGH
EPSS
0.0%
2023 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.

CVE-2023-34233
snowflake-connector-python General
7.3
HIGH
EPSS
0.5%
2023 CWE-77 1 PoC

The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Versions prior to 3.0.2 are vulnerable to command injection via single sign-on(SSO) browser URL authentication. In order to exploit the potential for command injection, an attacker would need to be successful in (1) establishing a malicious resource and (2) redirecting users to utilize the resource. The attacker could set up a malicious, publicly accessible server which responds to the SSO URL with an attack payload. If the attacker then

CVE-2023-1776
Mattermost General
7.3
HIGH
EPSS
0.7%
2023 CWE-79 1 PoC

Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a card and share it using a direct link to the file.

CVE-2023-0760
gpac/gpac General
7.3
HIGH
EPSS
0.0%
2023 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to V2.1.0-DEV.

CVE-2023-31349
μProf Tool General
7.3
HIGH
EPSS
0.2%
2023 CWE-276 1 PoC

Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

CVE-2023-32493
PowerScale OneFS General
7.3
HIGH
EPSS
0.4%
2023 CWE-693 1 PoC

Dell PowerScale OneFS, 9.5.0.x, contains a protection mechanism bypass vulnerability. An unprivileged, remote attacker could potentially exploit this vulnerability, leading to denial of service, information disclosure and remote execution.

CVE-2023-0817
gpac/gpac General
7.3
HIGH
EPSS
0.1%
2023 CWE-126 1 PoC

Buffer Over-read in GitHub repository gpac/gpac prior to v2.3.0-DEV.

CVE-2023-31348
μProf Tool General
7.3
HIGH
EPSS
0.2%
2023 1 PoC

A DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

CVE-2023-42567
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.1%
2023 1 PoC

Improper size check vulnerability in softsimd prior to SMR Dec-2023 Release 1 allows stack-based buffer overflow.

CVE-2023-2531
azuracast/azuracast General
7.3
HIGH
EPSS
0.1%
2023 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts in GitHub repository azuracast/azuracast prior to 0.18.3.

CVE-2023-1170
vim/vim General
7.3
HIGH
EPSS
0.1%
2023 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.

CVE-2023-38960
Software Genérico General
7.3
HIGH
EPSS
0.0%
2023 1 PoC

Insecure Permissions issue in Raiden Professional Server RaidenFTPD v.2.4 build 4005 allows a local attacker to gain privileges and execute arbitrary code via crafted executable running from the installation directory.

CVE-2023-0051
vim/vim General
7.3
HIGH
EPSS
0.0%
2023 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1144.

CVE-2023-26159
follow-redirects General
7.3
HIGH
EPSS
0.1%
2023 CWE-20 1 PoC

Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error, it can be manipulated to misinterpret the hostname. An attacker could exploit this weakness to redirect traffic to a malicious site, potentially leading to information disclosure, phishing attacks, or other security breaches.

CVE-2023-0049
vim/vim General
7.3
HIGH
EPSS
0.0%
2023 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.

CVE-2023-0512
vim/vim General
7.3
HIGH
EPSS
0.0%
2023 CWE-369 2 PoCs

Divide By Zero in GitHub repository vim/vim prior to 9.0.1247.

CVE-2023-6132
AVEVA Edge General
7.3
HIGH
EPSS
0.0%
2023 CWE-427 1 PoC

The vulnerability, if exploited, could allow a malicious entity with access to the file system to achieve arbitrary code execution and privilege escalation by tricking AVEVA Edge to load an unsafe DLL.