3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-0734
wallabag/wallabag General
7.3
HIGH
EPSS
0.3%
2023 CWE-285 1 PoC

Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4.

CVE-2023-37219
Telecom Composit General
7.3
HIGH
EPSS
0.1%
2023 CWE-1236 1 PoC

Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV File

CVE-2023-51751
Software Genérico General
7.3
HIGH
EPSS
0.2%
2023 2 PoCs

ScaleFusion 10.5.2 does not properly limit users to the Edge application because Alt-F4 can be used. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode.

CVE-2023-3643
Boss Mini General ⚡ nuclei
7.3
HIGH
EPSS
40.7%
2023 CWE-73 1 PoC

A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233889 was assigned to this vulnerability.

CVE-2023-37013
Software Genérico General
7.3
HIGH
EPSS
0.2%
2023 1 PoC

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a sufficiently large ASN.1 packet over the S1AP interface. An attacker may repeatedly send such an oversized packet to cause the `ogs_sctp_recvmsg` routine to reach an unexpected network state and crash, leading to denial of service.

CVE-2023-4322
radareorg/radare2 General
7.3
HIGH
EPSS
0.2%
2023 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.

CVE-2023-0049
vim/vim General
7.3
HIGH
EPSS
0.0%
2023 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.

CVE-2023-32493
PowerScale OneFS General
7.3
HIGH
EPSS
0.4%
2023 CWE-693 1 PoC

Dell PowerScale OneFS, 9.5.0.x, contains a protection mechanism bypass vulnerability. An unprivileged, remote attacker could potentially exploit this vulnerability, leading to denial of service, information disclosure and remote execution.

CVE-2023-4733
vim/vim General
7.3
HIGH
EPSS
0.0%
2023 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.1840.

CVE-2023-24059
Software Genérico General
7.3
HIGH
EPSS
9.3%
2023 1 PoC

Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January 2023.

CVE-2023-7261
Omaha General
7.3
HIGH
EPSS
0.0%
2023 2 PoCs

Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High)

CVE-2023-26159
follow-redirects General
7.3
HIGH
EPSS
0.1%
2023 CWE-20 1 PoC

Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error, it can be manipulated to misinterpret the hostname. An attacker could exploit this weakness to redirect traffic to a malicious site, potentially leading to information disclosure, phishing attacks, or other security breaches.

CVE-2023-0051
vim/vim General
7.3
HIGH
EPSS
0.0%
2023 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1144.

CVE-2023-40109
Android General
7.3
HIGH
EPSS
0.0%
2023 1 PoC

In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVE-2023-42568
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.1%
2023 1 PoC

Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files with system privilege.

CVE-2023-0288
vim/vim General
7.3
HIGH
EPSS
0.0%
2023 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.

CVE-2023-20921
Android General
7.3
HIGH
EPSS
0.0%
2023 2 PoCs

In onPackageRemoved of AccessibilityManagerService.java, there is a possibility to automatically grant accessibility services due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-243378132

CVE-2023-5521
tiann/kernelsu General
7.3
HIGH
EPSS
0.5%
2023 CWE-863 2 PoCs

Incorrect Authorization in GitHub repository tiann/kernelsu prior to v0.6.9.

CVE-2023-3891
Lapce General
7.3
HIGH
EPSS
0.1%
2023 CWE-367 1 PoC

Race condition in Lapce v0.2.8 allows an attacker to elevate privileges on the system

CVE-2023-42565
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.1%
2023 1 PoC

Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local attackers with shell privilege to execute arbitrary code.