3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-37756
Software Genérico General
N/A
UNKNOWN
EPSS
6.6%
2023 2 PoCs

I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation. Attackers are able to easily guess users' passwords via a bruteforce attack.

CVE-2023-52654
Linux General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

In the Linux kernel, the following vulnerability has been resolved: io_uring/af_unix: disable sending io_uring over sockets File reference cycles have caused lots of problems for io_uring in the past, and it still doesn't work exactly right and races with unix_stream_read_generic(). The safest fix would be to completely disallow sending io_uring files via sockets via SCM_RIGHT, so there are no possible cycles invloving registered files and thus rendering SCM accounting on the io_uring side unnecessary.

CVE-2023-21284
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In multiple functions of DevicePolicyManager.java, there is a possible way to prevent enabling the Find my Device feature due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-33383
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2023 2 PoCs

Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition that results in a device reload.

CVE-2023-42335
Software Genérico General
N/A
UNKNOWN
EPSS
1.9%
2023 1 PoC

Unrestricted File Upload vulnerability in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to execute arbitrary code via the add attachment function in the New Expense component.

CVE-2023-39003
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /tmp.

CVE-2023-33802
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A buffer overflow in SumatraPDF Reader v3.4.6 allows attackers to cause a Denial of Service (DoS) via a crafted text file.

CVE-2023-6207
Firefox General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

CVE-2023-48161
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

Buffer Overflow vulnerability in GifLib Project GifLib v.5.2.1 allows a local attacker to obtain sensitive information via the DumpSCreen2RGB function in gif2rgb.c

CVE-2023-36184
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

CMysten Labs Sui blockchain v1.2.0 was discovered to contain a stack overflow via the component /spec/openrpc.json.

CVE-2023-28869
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents of arbitrary files on the operating system by creating a symbolic link.

CVE-2023-36623
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

The root password of the Loxone Miniserver Go Gen.2 before 14.2 is calculated using hard-coded secrets and the MAC address. This allows a local user to calculate the root password and escalate privileges.

CVE-2023-44061
Software Genérico General
N/A
UNKNOWN
EPSS
5.0%
2023 2 PoCs

File Upload vulnerability in Simple and Nice Shopping Cart Script v.1.0 allows a remote attacker to execute arbitrary code via the upload function in the edit profile component.

CVE-2023-32804
Midgard GPU Userspace Driver General
N/A
UNKNOWN
EPSS
0.1%
2023 CWE-787 1 PoC

Out-of-bounds Write vulnerability in Arm Ltd Midgard GPU Userspace Driver, Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a local non-privileged user to write a constant pattern to a limited amount of memory not allocated by the user space driver.This issue affects Midgard GPU Userspace Driver: from r0p0 through r32p0; Bifrost GPU Userspace Driver: from r0p0 through r44p0; Valhall GPU Userspace Driver: from r19p0 through r44p0; Arm 5th Gen GPU Architecture Userspace Driver: from r41p0 through r44p0.

CVE-2023-33468
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection confirmation code remotely, bypassing the need to obtain it directly from the physical screen.

CVE-2023-42361
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Local File Inclusion vulnerability in Midori-global Better PDF Exporter for Jira Server and Jira Data Center v.10.3.0 and before allows an attacker to view arbitrary files and cause other impacts via use of crafted image during PDF export.

CVE-2023-47251
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2023 3 PoCs

In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, a Directory Traversal in the print function of the VNC service allows authenticated attackers (with access to a VNC session) to automatically transfer malicious PDF documents by moving them into the .spool directory, and then sending a signal to the VNC service, which automatically transfers them to the connected VNC client's filesystem.

CVE-2023-32211
Firefox General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

CVE-2023-41638
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

An arbitrary file upload vulnerability in the Gestione Documentale module of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2023-51022
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langFlag’ parameter of the setLanguageCfg interface of the cstecgi .cgi.