3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-28872
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic link from a %LOCALAPPDATA%\Temp\NcpSupport* location.

CVE-2023-20569
Ryzen™ 3000 Series Desktop Processors General
N/A
UNKNOWN
EPSS
2.0%
2023 2 PoCs

A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.

CVE-2023-26469
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.0%
2023 2 PoCs

In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.

CVE-2023-41646
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 3 PoCs

Buttercup v2.20.3 allows attackers to obtain the hash of the master password for the password manager via accessing the file /vaults.json/

CVE-2023-46386
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via registry.xml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication.

CVE-2023-2530
Puppet Enterprise General
N/A
UNKNOWN
EPSS
7.8%
2023 1 PoC

A privilege escalation allowing remote code execution was discovered in the orchestration service.

CVE-2023-5240
Server General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAM propagation scripts to retrieve passwords stored in it via a GET request.

CVE-2023-51020
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langType’ parameter of the setLanguageCfg interface of the cstecgi .cgi.

CVE-2023-44962
Software Genérico General
N/A
UNKNOWN
EPSS
3.2%
2023 1 PoC

File Upload vulnerability in Koha Library Software 23.05.04 and before allows a remote attacker to read arbitrary files via the upload-cover-image.pl component.

CVE-2023-5725
Firefox General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

CVE-2023-41613
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 2 PoCs

EzViz Studio v2.2.0 is vulnerable to DLL hijacking.

CVE-2023-43869
Software Genérico General
N/A
UNKNOWN
EPSS
3.4%
2023 1 PoC

D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard56 function.

CVE-2023-38352
Software Genérico General
N/A
UNKNOWN
EPSS
6.0%
2023 1 PoC

MiniTool Partition Wizard 12.8 contains an insecure update mechanism that allows attackers to achieve remote code execution through a man in the middle attack.

CVE-2023-4350
Chrome General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)

CVE-2023-20589
Ryzen™ 3000 Series Desktop Processors General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary code execution. 

CVE-2023-38997
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2023 1 PoC

A directory traversal vulnerability in the Captive Portal templates of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands as root via a crafted ZIP archive.

CVE-2023-52664
Linux General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In the Linux kernel, the following vulnerability has been resolved: net: atlantic: eliminate double free in error handling logic Driver has a logic leak in ring data allocation/free, where aq_ring_free could be called multiple times on same ring, if system is under stress and got memory allocation error. Ring pointer was used as an indicator of failure, but this is not correct since only ring data is allocated/deallocated. Ring itself is an array member. Changing ring allocation functions to return error code directly. This simplifies error handling and eliminates aq_ring_free on higher la

CVE-2023-2905
Mongoose General
N/A
UNKNOWN
EPSS
0.2%
2023 CWE-122 1 PoC

Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version 7.9 and prior does not appear to be vulnerable. This issue is resolved in version 7.11.

CVE-2023-24130
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey parameter at /goform/WifiBasicSet.

CVE-2023-2004
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Sin descripción disponible.