3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-3591
Mattermost General
4.8
MEDIUM
EPSS
0.2%
2023 CWE-287 1 PoC

Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created.

CVE-2023-53900
spip General
4.8
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded external links. Attackers can trick administrators into clicking a crafted SVG logo that redirects to a potentially dangerous URL through improper file upload filtering.

CVE-2023-1654
gpac/gpac General
4.8
MEDIUM
EPSS
0.0%
2023 CWE-400 1 PoC

Denial of Service in GitHub repository gpac/gpac prior to 2.4.0.

CVE-2023-4735
vim/vim General
4.8
MEDIUM
EPSS
0.0%
2023 CWE-787 1 PoC

Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847.

CVE-2023-30701
Samsung Mobile Devices General
4.7
MEDIUM
EPSS
0.1%
2023 1 PoC

PendingIntent hijacking in WifiGeofenceManager prior to SMR Aug-2023 Release 1 allows local attacker to arbitrary file access.

CVE-2023-34020
Uncanny Toolkit for LearnDash General ⚡ nuclei
4.7
MEDIUM
EPSS
4.7%
2023 CWE-601 0 PoCs

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash.This issue affects Uncanny Toolkit for LearnDash: from n/a through 3.6.4.3.

CVE-2023-30726
GameLauncher General
4.7
MEDIUM
EPSS
0.1%
2023 1 PoC

PendingIntent hijacking vulnerability in GameLauncher prior to version 4.2.59.5 allows local attackers to access data.

CVE-2023-41911
Software Genérico General
4.7
MEDIUM
EPSS
0.1%
2023 1 PoC

Samsung Mobile Processor Exynos 2200 allows a GPU Double Free (issue 1 of 2).

CVE-2023-25200
Software Genérico General
4.7
MEDIUM
EPSS
0.1%
2023 1 PoC

An HTML injection vulnerability exists in the MT Safeline X-Ray X3310 webserver version NXG 19.05 that enables a remote attacker to render malicious HTML and obtain sensitive information in a victim's browser.

CVE-2023-21490
Samsung Mobile Devices General
4.7
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control in GearManagerStub prior to SMR May-2023 Release 1 allows a local attacker to delete applications installed by watchmanager.

CVE-2023-0160
kernel General
4.7
MEDIUM
EPSS
0.0%
2023 CWE-833 1 PoC

A deadlock flaw was found in the Linux kernel’s BPF subsystem. This flaw allows a local user to potentially crash the system.

CVE-2023-34970
Valhall GPU Kernel Driver General
4.7
MEDIUM
EPSS
0.1%
2023 CWE-416 1 PoC

A local non-privileged user can make improper GPU processing operations to access a limited amount outside of buffer bounds or to exploit a software race condition. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory

CVE-2023-0045
Linux Kernel General
4.7
MEDIUM
EPSS
0.2%
2023 CWE-610 2 PoCs

The current implementation of the prctl syscall does not issue an IBPB immediately during the syscall. The ib_prctl_set  function updates the Thread Information Flags (TIFs) for the task and updates the SPEC_CTRL MSR on the function __speculation_ctrl_update, but the IBPB is only issued on the next schedule, when the TIF bits are checked. This leaves the victim vulnerable to values already injected on the BTB, prior to the prctl syscall.  The patch that added the support for the conditional mitigation via prctl (ib_prctl_set) dates back to the kernel 4.9.176. We recommend upgrading past commi

CVE-2023-2515
Mattermost General
4.7
MEDIUM
EPSS
0.1%
2023 CWE-863 1 PoC

Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to system admin

CVE-2023-42573
Search Widget General
4.7
MEDIUM
EPSS
0.1%
2023 1 PoC

PendingIntent hijacking vulnerability in Search Widget prior to version 3.4 in China models allows local attackers to access data.

CVE-2023-23694
Dell VxRail HCI General
4.7
MEDIUM
EPSS
0.2%
2023 CWE-78 1 PoC

Dell VxRail versions earlier than 7.0.450, contain(s) an OS command injection vulnerability in VxRail Manager. A local authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker.

CVE-2023-3380
WN579X3 General ⚡ nuclei
4.7
MEDIUM
EPSS
80.3%
2023 CWE-74 0 PoCs

A vulnerability classified as critical has been found in Wavlink WN579X3 up to 20230615. Affected is an unknown function of the file /cgi-bin/adm.cgi of the component Ping Test. The manipulation of the argument pingIp leads to injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-232236. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-3450
RG-BCR860 General
4.7
MEDIUM
EPSS
61.4%
2023 CWE-78 3 PoCs

A vulnerability was found in Ruijie RG-BCR860 2.5.13 and classified as critical. This issue affects some unknown processing of the component Network Diagnostic Page. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-232547. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-3439
Linux Kernel (mctp) General
4.7
MEDIUM
EPSS
0.0%
2023 CWE-416 1 PoC

A flaw was found in the MCTP protocol in the Linux kernel. The function mctp_unregister() reclaims the device's relevant resource when a netcard detaches. However, a running routine may be unaware of this and cause the use-after-free of the mdev->addrs object, potentially leading to a denial of service.

CVE-2023-30720
Samsung Mobile Devices General
4.7
MEDIUM
EPSS
0.1%
2023 1 PoC

PendingIntent hijacking in LmsAssemblyTrackerCTC prior to SMR Sep-2023 Release 1 allows local attacker to gain arbitrary file access.