3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-30664
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in RegisteredMSISDN prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

CVE-2023-54336
Mediconta General
8.5
HIGH
EPSS
0.0%
2023 CWE-428 1 PoC

Mediconta 3.7.27 contains an unquoted service path vulnerability in the servermedicontservice that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\medicont3\ to inject malicious code that would execute with LocalSystem permissions during service startup.

CVE-2023-21491
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control vulnerability in ThemeManager prior to SMR May-2023 Release 1 allows local attackers to write arbitrary files with system privilege.

CVE-2023-21480
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in CertByte prior to SMR Apr-2023 Release 1 allows local attackers to launch privileged activities.

CVE-2023-53949
AspEmail General
8.5
HIGH
EPSS
0.0%
2023 CWE-732 1 PoC

AspEmail 5.6.0.2 contains a binary permission vulnerability that allows local users to escalate privileges through the Persits Software EmailAgent service. Attackers can exploit full write permissions in the BIN directory to replace the service executable and gain elevated system access.

CVE-2023-30655
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in SCEPProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

CVE-2023-53947
OCS Inventory NG General
8.5
HIGH
EPSS
0.0%
2023 CWE-428 1 PoC

OCS Inventory NG 2.3.0.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges to system level. Attackers can place a malicious executable in the unquoted service path and trigger the service restart to execute code with elevated system privileges.

CVE-2023-30656
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in LSOItemData prior to SMR Jul-2023 Release 1 allows attackers to launch certain activities.

CVE-2023-53984
HotKey Clipboard General
8.5
HIGH
EPSS
0.0%
2023 CWE-428 1 PoC

Clevo HotKey Clipboard 2.1.0.6 contains an unquoted service path vulnerability in the HKClipSvc service that allows local non-privileged users to potentially execute code with system privileges. Attackers can exploit the misconfigured service path to inject and execute arbitrary code by placing malicious executables in specific file system locations.

CVE-2023-53937
Hubstaff General
8.5
HIGH
EPSS
0.0%
2023 CWE-427 1 PoC

Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious library. Attackers can generate a custom DLL using Metasploit and place it in the system32 directory to obtain a reverse shell during application startup.

CVE-2023-53954
ActFax General
8.5
HIGH
EPSS
0.0%
2023 CWE-428 1 PoC

ActFax 10.10 contains an unquoted service path vulnerability that allows local attackers to potentially escalate privileges by exploiting the ActiveFaxServiceNT service configuration. Attackers with write permissions to Program Files directories can inject a malicious ActSrvNT.exe executable to gain elevated system access when the service restarts.

CVE-2023-22508
Confluence Data Center General
8.5
HIGH
EPSS
5.1%
2023 3 PoCs

This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22508 was introduced in version 6.1.0 of Confluence Data Center & Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user interaction. Atlassian recommends that you upgrade your instance to avoid this bug using the following options: * Upgrade to a Confluence feature release greater than or equal to 8.2.0 (ie: 8.2, 8.2, 8.4,

CVE-2023-30658
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in DataProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

CVE-2023-0020
SAP BusinessObjects Business Intelligence Platform General
8.5
HIGH
EPSS
0.3%
2023 CWE-200 1 PoC

SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high impact on confidentiality and limited impact on integrity of the application.

CVE-2023-3517
Pentaho Data Integration & Analytics General
8.5
HIGH
EPSS
0.1%
2023 CWE-99 1 PoC

Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.

CVE-2023-32190
openSUSE Tumbleweed General
8.5
HIGH
EPSS
0.1%
2023 1 PoC

mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.

CVE-2023-54338
Tftpd32_SE General
8.5
HIGH
EPSS
0.0%
2023 CWE-428 1 PoC

Tftpd32 SE 4.60 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be run with system-level permissions.

CVE-2023-30692
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.1%
2023 1 PoC

Improper input validation vulnerability in Evaluator prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.

CVE-2023-30710
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.1%
2023 1 PoC

Improper input validation vulnerability in Knox AI prior to SMR Sep-2023 Release 1 allows local attackers to launch privileged activities.

CVE-2023-53973
Zillya Total Security General
8.5
HIGH
EPSS
0.0%
2023 CWE-59 1 PoC

Zillya Total Security 3.0.2367.0 contains a privilege escalation vulnerability that allows low-privileged users to copy files to unauthorized system locations using the quarantine module. Attackers can leverage symbolic link techniques to restore quarantined files to restricted directories, potentially enabling system-level access through techniques like DLL hijacking.