3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-0221
Application and Change Control General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-269 1 PoC

Product security bypass vulnerability in ACC prior to version 8.3.4 allows a locally logged-in attacker with administrator privileges to bypass the execution controls provided by ACC using the utilman program.

CVE-2023-30665
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper input validation vulnerability in OnOemServiceMode in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds read.

CVE-2023-43574
Desktop BIOS General
4.4
MEDIUM
EPSS
0.0%
2023 CWE-126 1 PoC

A buffer over-read was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.

CVE-2023-1158
Pentaho Business Analytics Server General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-863 1 PoC

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x expose dashboard prompts to users who are not part of the authorization list. 

CVE-2023-28810
DS-K1T804AXX General
4.3
MEDIUM
EPSS
0.5%
2023 CWE-284 1 PoC

Some access control/intercom products have unauthorized modification of device network configuration vulnerabilities. Attackers can modify device network configuration by sending specific data packets to the vulnerable interface within the same local network.

CVE-2023-28599
Zoom for Android General
4.3
MEDIUM
EPSS
0.5%
2023 CWE-79 1 PoC

Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victim to a malicious website during meeting creation.

CVE-2023-45223
Mattermost General
4.3
MEDIUM
EPSS
0.4%
2023 CWE-200 1 PoC

Mattermost fails to properly validate the "Show Full Name" option in a few endpoints in Mattermost Boards, allowing a member to get the full name of another user even if the Show Full Name option was disabled. 

CVE-2023-26438
OX App Suite General
4.3
MEDIUM
EPSS
0.0%
2023 CWE-918 1 PoC

External service lookups for a number of protocols were vulnerable to a time-of-check/time-of-use (TOCTOU) weakness, involving the JDK DNS cache. Attackers that were timing DNS cache expiry correctly were able to inject configuration that would bypass existing network deny-lists. Attackers could exploit this weakness to discover the existence of restricted network infrastructure and service availability. Improvements were made to include deny-lists not only during the check of the provided connection data, but also during use. No publicly available exploits are known.

CVE-2023-2395
SRX5308 General
4.3
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

A vulnerability classified as problematic has been found in Netgear SRX5308 up to 4.3.5-3. This affects an unknown part of the component Web Management Interface. The manipulation of the argument Login.userAgent leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227673 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-1903
HCM Fiori App My Forms (Fiori 2.0) General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-862 1 PoC

SAP HCM Fiori App My Forms (Fiori 2.0) - version 605, does not perform necessary authorization checks for an authenticated user exposing the restricted header data.

CVE-2023-2822
Ethos Identity General ⚡ nuclei
4.3
MEDIUM
EPSS
83.7%
2023 CWE-79 3 PoCs

A vulnerability was found in Ellucian Ethos Identity up to 5.10.5. It has been classified as problematic. Affected is an unknown function of the file /cas/logout. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 5.10.6 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-229596.

CVE-2023-4168
Adlisting General ⚡ nuclei
4.3
MEDIUM
EPSS
74.7%
2023 CWE-200 2 PoCs

A vulnerability was found in Templatecookie Adlisting 2.14.0. It has been classified as problematic. Affected is an unknown function of the file /ad-list of the component Redirect Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-236184. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-45038
Music Station General ⚡ nuclei
4.3
MEDIUM
EPSS
6.9%
2023 CWE-287 0 PoCs

An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following version: Music Station 5.4.0 and later

CVE-2023-46442
Software Genérico General
4.3
MEDIUM
EPSS
2.9%
2023 2 PoCs

An infinite loop in the retrieveActiveBody function of Soot before v4.4.1 under Java 8 allows attackers to cause a Denial of Service (DoS).

CVE-2023-40362
Software Genérico General
4.3
MEDIUM
EPSS
6.1%
2023 1 PoC

An issue was discovered in CentralSquare Click2Gov Building Permit before October 2023. Lack of access control protections allows remote attackers to arbitrarily delete the contractors from any user's account when the user ID and contractor information is known.

CVE-2023-39205
Zoom Clients General
4.3
MEDIUM
EPSS
0.3%
2023 CWE-754 1 PoC

Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-4478
Mattermost General
4.3
MEDIUM
EPSS
0.3%
2023 CWE-74 1 PoC

Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thus blocking them from later accessing Mattermost without the system admin activating their accounts.

CVE-2023-47168
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-601 1 PoC

Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked "Back to Mattermost" after providing a invalid custom url scheme in /oauth/{service}/mobile_login?redirect_to=

CVE-2023-21425
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.0%
2023 CWE-287 1 PoC

Improper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to get sensitive information.

CVE-2023-0914
pixelfed/pixelfed General
4.3
MEDIUM
EPSS
0.2%
2023 CWE-285 1 PoC

Improper Authorization in GitHub repository pixelfed/pixelfed prior to 0.11.4.