9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-3891
Lapce General
7.3
HIGH
EPSS
0.1%
2023 CWE-367 1 PoC

Race condition in Lapce v0.2.8 allows an attacker to elevate privileges on the system

CVE-2023-42566
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.1%
2023 1 PoC

Out-of-bound write vulnerability in libsavsvc prior to SMR Dec-2023 Release 1 allows local attackers to execute arbitrary code.

CVE-2023-26110
node-bluetooth General
7.3
HIGH
EPSS
0.2%
2023 CWE-120 1 PoC

All versions of the package node-bluetooth are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation.

CVE-2023-51751
Software Genérico General
7.3
HIGH
EPSS
0.2%
2023 2 PoCs

ScaleFusion 10.5.2 does not properly limit users to the Edge application because Alt-F4 can be used. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode.

CVE-2023-42568
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.1%
2023 1 PoC

Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files with system privilege.

CVE-2023-4977
librenms/librenms General
7.3
HIGH
EPSS
0.1%
2023 CWE-94 1 PoC

Code Injection in GitHub repository librenms/librenms prior to 23.9.0.

CVE-2023-4733
vim/vim General
7.3
HIGH
EPSS
0.0%
2023 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.1840.

CVE-2023-26135
flatnest General
7.3
HIGH
EPSS
0.1%
2023 CWE-1321 1 PoC

All versions of the package flatnest are vulnerable to Prototype Pollution via the nest() function in the flatnest/nest.js file.

CVE-2023-42565
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.1%
2023 1 PoC

Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local attackers with shell privilege to execute arbitrary code.

CVE-2023-0734
wallabag/wallabag General
7.3
HIGH
EPSS
0.3%
2023 CWE-285 1 PoC

Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4.

CVE-2023-26109
node-bluetooth-serial-port General
7.3
HIGH
EPSS
0.4%
2023 CWE-120 1 PoC

All versions of the package node-bluetooth-serial-port are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation.

CVE-2023-21420
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.1%
2023 CWE-134 1 PoC

Use of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release 1 allows arbitrary code execution.

CVE-2023-37219
Telecom Composit General
7.3
HIGH
EPSS
0.1%
2023 CWE-1236 1 PoC

Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV File

CVE-2023-5521
tiann/kernelsu General
7.3
HIGH
EPSS
0.5%
2023 CWE-863 2 PoCs

Incorrect Authorization in GitHub repository tiann/kernelsu prior to v0.6.9.

CVE-2023-3643
Boss Mini General ⚡ nuclei
7.3
HIGH
EPSS
40.7%
2023 CWE-73 1 PoC

A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233889 was assigned to this vulnerability.

CVE-2023-0054
vim/vim General
7.3
HIGH
EPSS
0.0%
2023 CWE-787 1 PoC

Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145.

CVE-2023-4590
Frhed General
7.3
HIGH
EPSS
0.4%
2023 CWE-120 1 PoC

Buffer overflow vulnerability in Frhed hex editor, affecting version 1.6.0. This vulnerability could allow an attacker to execute arbitrary code via a long filename argument through the Structured Exception Handler (SEH) registers.

CVE-2023-1175
vim/vim General
7.3
HIGH
EPSS
0.0%
2023 CWE-131 1 PoC

Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.

CVE-2023-1127
vim/vim General
7.3
HIGH
EPSS
0.0%
2023 CWE-369 1 PoC

Divide By Zero in GitHub repository vim/vim prior to 9.0.1367.

CVE-2023-46047
Software Genérico General
7.3
HIGH
EPSS
0.0%
2023 1 PoC

An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function. NOTE: this is disputed because there is no expectation that the product should be starting with an attacker-controlled configuration file.