3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-5223
HOJ General
6.3
MEDIUM
EPSS
0.2%
2023 CWE-265 1 PoC

A vulnerability, which was classified as critical, has been found in HimitZH HOJ up to 4.6-9a65e3f. This issue affects some unknown processing of the component Topic Handler. The manipulation leads to sandbox issue. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240365 was assigned to this vulnerability.

CVE-2023-5753
Zephyr General
6.3
MEDIUM
EPSS
0.2%
2023 CWE-120 1 PoC

Potential buffer overflows in the Bluetooth subsystem due to asserts being disabled in /subsys/bluetooth/host/hci_core.c

CVE-2023-35870
SAP S/4HANA (Manage Journal Entry Template) General
6.3
MEDIUM
EPSS
0.1%
2023 CWE-732 1 PoC

When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 107, an attacker could intercept the save request and change the template, leading to an impact on confidentiality and integrity of the resource. Furthermore, a standard template could be deleted, hence making the resource temporarily unavailable.

CVE-2023-4450
JimuReport General ⚡ nuclei
6.3
MEDIUM
EPSS
90.8%
2023 CWE-74 1 PoC

A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-237571.

CVE-2023-32491
PowerScale OneFS General
6.3
MEDIUM
EPSS
0.1%
2023 CWE-532 1 PoC

Dell PowerScale OneFS 9.5.0.x, contains an insertion of sensitive information into log file vulnerability in SNMPv3. A low privileges user could potentially exploit this vulnerability, leading to information disclosure.

CVE-2023-42483
Software Genérico General
6.3
MEDIUM
EPSS
0.0%
2023 1 PoC

A TOCTOU race condition in Samsung Mobile Processor Exynos 9820, Exynos 980, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, and Exynos 1380 can cause unexpected termination of a system.

CVE-2023-1350
liferea General
6.3
MEDIUM
EPSS
0.5%
2023 CWE-78 1 PoC

A vulnerability was found in liferea. It has been rated as critical. Affected by this issue is the function update_job_run of the file src/update.c of the component Feed Enrichment. The manipulation of the argument source with the input |date >/tmp/bad-item-link.txt leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 8d8b5b963fa64c7a2122d1bbfbb0bed46e813e59. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-222848.

CVE-2023-2670
Lost and Found Information System General
6.3
MEDIUM
EPSS
0.3%
2023 CWE-284 2 PoCs

A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/?page=user/manage_user. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-228886 is the identifier assigned to this vulnerability.

CVE-2023-7134
Medicine Tracking System General
6.3
MEDIUM
EPSS
0.1%
2023 CWE-24 1 PoC

A vulnerability was found in SourceCodester Medicine Tracking System 1.0. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument page leads to path traversal: '../filedir'. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249137 was assigned to this vulnerability.

CVE-2023-42534
Samsung Mobile Devices General
6.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper input validation vulnerability in ChooserActivity prior to SMR Nov-2023 Release 1 allows local attackers to read arbitrary files with system privilege.

CVE-2023-30951
com.palantir.magritte:magritte-rest-source-bundle General
6.3
MEDIUM
EPSS
0.2%
2023 CWE-611 1 PoC

The Foundry Magritte plugin rest-source was found to be vulnerable to an an XML external Entity attack (XXE).

CVE-2023-0417
Wireshark General
6.3
MEDIUM
EPSS
0.1%
2023 1 PoC

Memory leak in the NFS dissector in Wireshark 4.0.0 to 4.0.2 and 3.6.0 to 3.6.10 and allows denial of service via packet injection or crafted capture file

CVE-2023-5326
CL4NX-J Plus General
6.3
MEDIUM
EPSS
0.1%
2023 CWE-287 1 PoC

A vulnerability was found in SATO CL4NX-J Plus 1.13.2-u455_r2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component WebConfig. The manipulation leads to improper authentication. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-241027.

CVE-2023-2980
Pydio Cells General
6.3
MEDIUM
EPSS
0.1%
2023 CWE-99 1 PoC

A vulnerability classified as critical was found in Abstrium Pydio Cells 4.2.0. This vulnerability affects unknown code of the component User Creation Handler. The manipulation leads to improper control of resource identifiers. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-230212.

CVE-2023-1463
nilsteampassnet/teampass General
6.3
MEDIUM
EPSS
0.2%
2023 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.

CVE-2023-0976
Trellix Agent General
6.3
MEDIUM
EPSS
0.2%
2023 CWE-427 1 PoC

A command Injection Vulnerability in TA for mac-OS prior to version 5.7.9 allows local users to place an arbitrary file into the /Library/Trellix/Agent/bin/ folder. The malicious file is executed by running the TA deployment feature located in the System Tree.

CVE-2023-42961
iOS and iPadOS General
6.3
MEDIUM
EPSS
0.4%
2023 1 PoC

A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, iOS 16.7 and iPadOS 16.7, macOS Sonoma 14, macOS Ventura 13.6, macOS Monterey 12.7. A sandboxed process may be able to circumvent sandbox restrictions.

CVE-2023-4260
Zephyr General
6.3
MEDIUM
EPSS
0.3%
2023 CWE-120 1 PoC

Potential off-by-one buffer overflow vulnerability in the Zephyr fuse file system.

CVE-2023-1388
Trellix Agent General
6.3
MEDIUM
EPSS
0.6%
2023 1 PoC

A heap-based overflow vulnerability in TA prior to version 5.7.9 allows a remote user to alter the page heap in the macmnsvc process memory block, resulting in the service becoming unavailable.

CVE-2023-29113
Volkswagen MIB3 infotainment system MIB3 OI MQB General
6.3
MEDIUM
EPSS
0.1%
2023 CWE-284 2 PoCs

The MIB3 infotainment unit used in Skoda and Volkswagen vehicles does not incorporate any privilege separation for the proprietary inter-process communication mechanism, leaving attackers with presence in the system an ability to undermine access control restrictions implemented at the operating system level. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources.