3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-6348
Chrome General
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-43838
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar.

CVE-2023-30146
Software Genérico General
N/A
UNKNOWN
EPSS
1.9%
2023 1 PoC

Assmann Digitus Plug&View IP Camera HT-IP211HDP, version 2.000.022 allows unauthenticated attackers to download a copy of the camera's settings and the administrator credentials.

CVE-2023-29733
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

The Lock Master app 2.2.4 for Android allows unauthorized apps to modify the values in its SharedPreference files. These files hold data that affects many app functions. Malicious modifications by unauthorized apps can cause security issues, such as functionality manipulation, resulting in a severe escalation of privilege attack.

CVE-2023-20793
MT6853, MT6853T, MT6873, MT6875, MT6877, MT6883, MT6885, MT6889, MT6891, MT6893, MT8183, MT8188, MT8195 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In apu, there is a possible memory corruption due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767818; Issue ID: ALPS07767818.

CVE-2023-30222
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password hashes for all users via eavesdropping.

CVE-2023-32209
Firefox General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A maliciously crafted favicon could have led to an out of memory crash. This vulnerability affects Firefox < 113.

CVE-2023-31294
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via the Delivery Name field.

CVE-2023-34724
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

An issue was discovered in TECHView LA5570 Wireless Gateway 1.0.19_T53, allows physical attackers to gain escalated privileges via the UART interface.

CVE-2023-37151
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Sin descripción disponible.

CVE-2023-26759
Software Genérico General
N/A
UNKNOWN
EPSS
11.9%
2023 1 PoC

Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an OS command injection vulnerability via calls made to the XMService component.

CVE-2023-48124
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2023 2 PoCs

Cross Site Scripting in SUP Online Shopping v.1.0 allows a remote attacker to execute arbitrary code via the Name, Email and Address parameters in the Register New Account component.

CVE-2023-20592
1st Gen AMD EPYC™ Processors General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.

CVE-2023-29737
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause a denial of service via the database files.

CVE-2023-1380
Kernel General
N/A
UNKNOWN
EPSS
0.0%
2023 CWE-125 2 PoCs

A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service.

CVE-2023-33281
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

The remote keyfob system on Nissan Sylphy Classic 2021 sends the same RF signal for each door-open request, which allows for a replay attack. NOTE: the vendor's position is that this cannot be reproduced with genuine Nissan parts: for example, the combination of keyfob and door handle shown in the exploit demonstration does not match any technology that Nissan provides to customers.

CVE-2023-25433
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

libtiff 4.5.0 is vulnerable to Buffer Overflow via /libtiff/tools/tiffcrop.c:8499. Incorrect updating of buffer size after rotateImage() in tiffcrop cause heap-buffer-overflow and SEGV.

CVE-2023-48028
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 2 PoCs

kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack.

CVE-2023-37679
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.4%
2023 2 PoCs

A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.

CVE-2023-47470
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2023 2 PoCs

Buffer Overflow vulnerability in Ffmpeg before github commit 4565747056a11356210ed8edcecb920105e40b60 allows a remote attacker to achieve an out-of-array write, execute arbitrary code, and cause a denial of service (DoS) via the ref_pic_list_struct function in libavcodec/evc_ps.c