3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-3819
pimcore/pimcore General
7.6
HIGH
EPSS
0.0%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pimcore/pimcore prior to 10.6.4.

CVE-2023-39214
Zoom SDK's General
7.6
HIGH
EPSS
0.4%
2023 CWE-749 1 PoC

Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.

CVE-2023-44092
Pandora FMS General
7.6
HIGH
EPSS
0.1%
2023 CWE-78 1 PoC

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Pandora FMS on all allows OS Command Injection. This vulnerability allowed to create a reverse shell and execute commands in the OS. This issue affects Pandora FMS: from 700 through <776.

CVE-2023-3069
tsolucio/corebos General
7.6
HIGH
EPSS
0.1%
2023 CWE-620 1 PoC

Unverified Password Change in GitHub repository tsolucio/corebos prior to 8.

CVE-2023-33248
Software Genérico General
7.6
HIGH
EPSS
0.7%
2023 2 PoCs

Amazon Alexa software version 8960323972 on Echo Dot 2nd generation and 3rd generation devices potentially allows attackers to deliver security-relevant commands via an audio signal between 16 and 22 kHz (often outside the range of human adult hearing). Commands at these frequencies are essentially never spoken by authorized actors, but a substantial fraction of the commands are successful.

CVE-2023-3725
Zephyr General
7.6
HIGH
EPSS
0.6%
2023 CWE-120 1 PoC

Potential buffer overflow vulnerability in the Zephyr CAN bus subsystem

CVE-2023-4003
One General
7.6
HIGH
EPSS
0.1%
2023 CWE-250 1 PoC

One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method. CWE-250: Execution with Unnecessary Privileges.

CVE-2023-4257
Zephyr General
7.6
HIGH
EPSS
0.4%
2023 CWE-120 1 PoC

Unchecked user input length in /subsys/net/l2/wifi/wifi_shell.c can cause buffer overflows.

CVE-2023-26074
Software Genérico General
7.6
HIGH
EPSS
0.8%
2023 3 PoCs

An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123.. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient parameter validation when decoding operator-defined access category definitions.

CVE-2023-26073
Software Genérico General
7.6
HIGH
EPSS
0.8%
2023 3 PoCs

An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient parameter validation when decoding the extended emergency number list.

CVE-2023-6538
System Management Unit (SMU) General
7.6
HIGH
EPSS
5.3%
2023 CWE-285 1 PoC

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Server or combined Server+Storage administrative roles are able to access SMU configuration backup, that would normally be barred to those specific administrative roles.

CVE-2023-42571
Find My Mobile General
7.6
HIGH
EPSS
0.2%
2023 1 PoC

Abuse of remote unlock in Find My Mobile prior to version 7.3.13.4 allows physical attacker to unlock the device remotely by resetting the Samsung Account password with SMS verification when user lost the device.

CVE-2023-0455
unilogies/bumsys General
7.6
HIGH
EPSS
5.6%
2023 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type in GitHub repository unilogies/bumsys prior to v1.0.3-beta.

CVE-2023-22833
com.palantir.lime:lime2 General
7.6
HIGH
EPSS
0.1%
2023 CWE-304 1 PoC

Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that allowed authenticated users within a Foundry organization to bypass discretionary or mandatory access controls under certain circumstances.

CVE-2023-5808
System Management Unit (SMU) General
7.6
HIGH
EPSS
0.3%
2023 CWE-285 1 PoC

SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be barred to that specific administrative role.

CVE-2023-26072
Software Genérico General
7.6
HIGH
EPSS
0.8%
2023 3 PoCs

An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient parameter validation when decoding the Emergency number list.

CVE-2023-41790
Pandora FMS General
7.6
HIGH
EPSS
0.1%
2023 CWE-427 1 PoC

Uncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File Search Paths. This vulnerability allows to access the server configuration file and to compromise the database. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-4818
A920 General
7.6
HIGH
EPSS
0.3%
2023 CWE-74 1 PoC

PAX A920 device allows to downgrade bootloader due to a bug in its version check. The signature is correctly checked and only bootloader signed by PAX can be used.  The attacker must have physical USB access to the device in order to exploit this vulnerability.

CVE-2023-45966
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

umputun remark42 version 1.12.1 and before has a Blind Server-Side Request Forgery (SSRF) vulnerability.

CVE-2023-50387
Software Genérico General
7.5
HIGH
EPSS
52.0%
2023 2 PoCs

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.