3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-7181
DedeBIZ General
4.7
MEDIUM
EPSS
0.1%
2023 CWE-434 1 PoC

A vulnerability was found in Muyun DedeBIZ up to 6.2.12 and classified as critical. Affected by this issue is some unknown functionality of the component Add Attachment Handler. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249368. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-3450
RG-BCR860 General
4.7
MEDIUM
EPSS
61.4%
2023 CWE-78 3 PoCs

A vulnerability was found in Ruijie RG-BCR860 2.5.13 and classified as critical. This issue affects some unknown processing of the component Network Diagnostic Page. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-232547. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-42482
Software Genérico General
4.7
MEDIUM
EPSS
0.1%
2023 1 PoC

Samsung Mobile Processor Exynos 2200 allows a GPU Use After Free.

CVE-2023-33200
Bifrost GPU Kernel Driver General
4.7
MEDIUM
EPSS
0.1%
2023 CWE-416 1 PoC

A local non-privileged user can make improper GPU processing operations to exploit a software race condition. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory.

CVE-2023-42539
Samsung Health General
4.7
MEDIUM
EPSS
0.1%
2023 1 PoC

PendingIntent hijacking vulnerability in ChallengeNotificationManager in Samsung Health prior to version 6.25 allows local attackers to access data.

CVE-2023-25586
binutils General
4.7
MEDIUM
EPSS
0.0%
2023 CWE-457 1 PoC

A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that can cause a crash and local denial of service.

CVE-2023-1032
linux General
4.7
MEDIUM
EPSS
0.0%
2023 CWE-415 2 PoCs

The Linux kernel io_uring IORING_OP_SOCKET operation contained a double free in function __sys_socket_file() in file net/socket.c. This issue was introduced in da214a475f8bd1d3e9e7a19ddfeb4d1617551bab and fixed in 649c15c7691e9b13cbe9bf6c65c365350e056067.

CVE-2023-33288
Software Genérico General
4.7
MEDIUM
EPSS
0.0%
2023 1 PoC

An issue was discovered in the Linux kernel before 6.2.9. A use-after-free was found in bq24190_remove in drivers/power/supply/bq24190_charger.c. It could allow a local attacker to crash the system due to a race condition.

CVE-2023-25588
binutils General
4.7
MEDIUM
EPSS
0.0%
2023 CWE-457 1 PoC

A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitialized in the `bfd_mach_o_get_synthetic_symtab` function, which may lead to an application crash and local denial of service.

CVE-2023-25585
binutils General
4.7
MEDIUM
EPSS
0.0%
2023 CWE-457 1 PoC

A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.

CVE-2023-2979
Pydio Cells General
4.7
MEDIUM
EPSS
0.0%
2023 CWE-284 1 PoC

A vulnerability classified as critical has been found in Abstrium Pydio Cells 4.2.0. This affects an unknown part of the component User Creation Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-230211.

CVE-2023-5339
Mattermost General
4.7
MEDIUM
EPSS
0.1%
2023 CWE-200 1 PoC

Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged. 

CVE-2023-6900
DashMachine General
4.6
MEDIUM
EPSS
0.1%
2023 CWE-24 1 PoC

A vulnerability, which was classified as critical, has been found in rmountjoy92 DashMachine 0.5-4. Affected by this issue is some unknown functionality of the file /settings/delete_file. The manipulation of the argument file leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. VDB-248258 is the identifier assigned to this vulnerability.

CVE-2023-2978
Pydio Cells General
4.6
MEDIUM
EPSS
0.0%
2023 CWE-639 1 PoC

A vulnerability was found in Abstrium Pydio Cells 4.2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Change Subscription Handler. The manipulation leads to authorization bypass. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component. VDB-230210 is the identifier assigned to this vulnerability.

CVE-2023-30708
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.3%
2023 1 PoC

Improper authentication in SecSettings prior to SMR Sep-2023 Release 1 allows attacker to access Captive Portal Wi-Fi in Reactivation Lock status.

CVE-2023-2943
openemr/openemr General
4.6
MEDIUM
EPSS
0.1%
2023 CWE-94 1 PoC

Code Injection in GitHub repository openemr/openemr prior to 7.0.1.

CVE-2023-21467
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.1%
2023 1 PoC

Error in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1 allows incorrect handling of unencrypted message.

CVE-2023-30676
Samsung Pass General
4.6
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass.

CVE-2023-3230
fossbilling/fossbilling General
4.6
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

Missing Authorization in GitHub repository fossbilling/fossbilling prior to 0.5.0.

CVE-2023-6927
Red Hat build of Keycloak 22 General
4.6
MEDIUM
EPSS
0.8%
2023 CWE-601 1 PoC

A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security patch implemented to address CVE-2023-6134.