3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-0299
publify/publify General
8.4
HIGH
EPSS
0.3%
2023 CWE-20 1 PoC

Improper Input Validation in GitHub repository publify/publify prior to 9.2.10.

CVE-2023-50806
Software Genérico General
8.4
HIGH
EPSS
0.1%
2023 2 PoCs

A vulnerability was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850 Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380 Exynos 1330, Exynos 9110, Exynos W920, Exynos W930, Exynos Modem 5123, Exynos Modem 5300 that allows out-of-bounds access to a heap buffer in the SIM Proactive Command.

CVE-2023-23771
MBTS Base Radio General
8.4
HIGH
EPSS
0.0%
2023 CWE-259 1 PoC

Motorola MBTS Base Radio accepts hard-coded backdoor password. The Motorola MBTS Base Radio Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled.

CVE-2023-26286
AIX General
8.4
HIGH
EPSS
0.1%
2023 1 PoC

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX runtime services library to execute arbitrary commands. IBM X-Force ID: 248421.

CVE-2023-42537
Samsung Mobile Devices General
8.4
HIGH
EPSS
0.1%
2023 1 PoC

An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

CVE-2023-23774
EBTS/MBTS Base Radio General
8.4
HIGH
EPSS
0.0%
2023 CWE-248 1 PoC

Motorola EBTS/MBTS Site Controller drops to debug prompt on unhandled exception. The Motorola MBTS Site Controller exposes a debug prompt on the device's serial port in case of an unhandled exception. This allows an attacker with physical access that is able to trigger such an exception to extract secret key material and/or gain arbitrary code execution on the device.

CVE-2023-1362
unilogies/bumsys General ⚡ nuclei
8.4
HIGH
EPSS
53.5%
2023 CWE-1021 1 PoC

Improper Restriction of Rendered UI Layers or Frames in GitHub repository unilogies/bumsys prior to v2.0.2.

CVE-2023-42535
Samsung Mobile Devices General
8.4
HIGH
EPSS
0.1%
2023 1 PoC

Out-of-bounds Write in read_block of vold prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.

CVE-2023-30680
Samsung Mobile Devices General
8.4
HIGH
EPSS
0.1%
2023 1 PoC

Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privilege.

CVE-2023-5607
Trellix Application and Change Control (TACC) General
8.4
HIGH
EPSS
0.5%
2023 CWE-22 1 PoC

An improper limitation of a path name to a restricted directory (path traversal) vulnerability in the TACC ePO extension, for on-premises ePO servers, prior to version 8.4.0 could lead to an authorised administrator attacker executing arbitrary code through uploading a specially crafted GTI reputation file. The attacker would need the appropriate privileges to access the relevant section of the User Interface. The import logic has been updated to restrict file types and content.

CVE-2023-45230
edk2 General
8.3
HIGH
EPSS
0.3%
2023 CWE-119 1 PoC

EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.

CVE-2023-42931
macOS General
8.3
HIGH
EPSS
2.8%
2023 2 PoCs

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. A process may gain admin privileges without proper authentication.

CVE-2023-3243
BCM-WEB General
8.3
HIGH
EPSS
0.1%
2023 CWE-290 1 PoC

** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an authenticating hash and utilize it to create new sessions. The hash is also a poorly salted MD5 hash, which could result in a successful brute force password attack. Impacted product is BCM-WEB version 3.3.X. Recommended fix: Upgrade to a supported product such as Alerton ACM.] Out of an abundance of caution, this CVE ID is being assigned to better serve our customers and ensure all who are still running this product understand that the product is end of life and should be removed or upgraded. 

CVE-2023-6186
LibreOffice General
8.3
HIGH
EPSS
1.0%
2023 1 PoC

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.

CVE-2023-32226
Sysaid General
8.3
HIGH
EPSS
0.1%
2023 CWE-552 1 PoC

Sysaid - CWE-552: Files or Directories Accessible to External Parties -  Authenticated users may exfiltrate files from the server via an unspecified method.

CVE-2023-3188
owncast/owncast General ⚡ nuclei
8.3
HIGH
EPSS
48.7%
2023 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository owncast/owncast prior to 0.1.0.

CVE-2023-40465
ALEOS General
8.3
HIGH
EPSS
0.0%
2023 CWE-121 1 PoC

Several versions of ALEOS, including ALEOS 4.16.0, include an opensource third-party component which can be exploited from the local area network, resulting in a Denial of Service condition for the captive portal.

CVE-2023-3548
IQ Wifi 6 General
8.3
HIGH
EPSS
0.2%
2023 CWE-307 1 PoC

An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack.

CVE-2023-0954
Illustra Pro Gen 4 Dome General
8.3
HIGH
EPSS
0.1%
2023 CWE-489 1 PoC

A debug feature in Sensormatic Electronics Illustra Pro Gen 4 Dome and PTZ cameras allows a user to compromise credentials after a long period of sustained attack.

CVE-2023-0227
pyload/pyload General
8.3
HIGH
EPSS
0.1%
2023 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository pyload/pyload prior to 0.5.0b3.dev36.