3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-21145
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In updatePictureInPictureMode of ActivityRecord.java, there is a possible bypass of background launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-36255
Software Genérico General
N/A
UNKNOWN
EPSS
89.5%
2023 2 PoCs

An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path parameter in the URL.

CVE-2023-6860
Firefox ESR General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.

CVE-2023-41508
Software Genérico General
N/A
UNKNOWN
EPSS
7.2%
2023 2 PoCs

A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel.

CVE-2023-48840
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.

CVE-2023-20802
MT6879, MT6895, MT6983, MT8188, MT8195, MT8395, MT8781 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In imgsys, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07420968; Issue ID: ALPS07420976.

CVE-2023-21286
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In visitUris of RemoteViews.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-32781
Software Genérico General
N/A
UNKNOWN
EPSS
47.2%
2023 1 PoC

A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed by the EXE/Script sensor. The severity of this vulnerability is high and received a score of 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CVE-2023-48205
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Jorani Leave Management System 1.0.2 allows a remote attacker to spoof a Host header associated with password reset emails.

CVE-2023-35800
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, which could allow access to information reserved to administrators.

CVE-2023-44216
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2023 5 PoCs

PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text contained on a web page from one origin if they control a resource from a different origin.

CVE-2023-36144
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
85.5%
2023 1 PoC

An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the device, exposing critical information about the device configuration.

CVE-2023-27132
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

TSplus Remote Work 16.0.0.0 places a cleartext password on the "var pass" line of the HTML source code for the secure single sign-on web portal. NOTE: CVE-2023-31069 is only about the TSplus Remote Access product, not the TSplus Remote Work product.

CVE-2023-40924
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
61.1%
2023 1 PoC

SolarView Compact < 6.00 is vulnerable to Directory Traversal.

CVE-2023-48830
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export.

CVE-2023-51200
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

Sin descripción disponible.

CVE-2023-6870
Firefox General
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox. *This issue only affects Android versions of Firefox and Firefox Focus.* This vulnerability affects Firefox < 121.

CVE-2023-49052
Software Genérico General
N/A
UNKNOWN
EPSS
26.3%
2023 1 PoC

File Upload vulnerability in Microweber v.2.0.4 allows a remote attacker to execute arbitrary code via a crafted script to the file upload function in the created forms component.

CVE-2023-38355
Software Genérico General
N/A
UNKNOWN
EPSS
6.0%
2023 1 PoC

MiniTool Movie Maker 7.0 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

CVE-2023-21274
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In convertSubgraphFromHAL of ShimConverter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.