3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-21118
Android General
6.2
MEDIUM
EPSS
0.1%
2023 2 PoCs

In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-269014004

CVE-2023-23946
git General
6.2
MEDIUM
EPSS
1.5%
2023 CWE-22 1 PoC

Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8. By feeding a crafted input to `git apply`, a path outside the working tree can be overwritten as the user who is running `git apply`. A fix has been prepared and will appear in v2.39.2, v2.38.4, v2.37.6, v2.36.5, v2.35.7, v2.34.7, v2.33.7, v2.32.6, v2.31.7, and v2.30.8. As a workaround, use `git apply --stat` to inspect a patch before applying; avoid applying one that creates a symbolic link and then creates a file beyond the symb

CVE-2023-3095
nilsteampassnet/teampass General
6.2
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

CVE-2023-53905
projectSend General
6.2
MEDIUM
EPSS
0.1%
2023 CWE-1236 1 PoC

ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into user profile names. Attackers can craft payloads like =calc|a!z| in the name field to trigger code execution when administrators export action logs as CSV files.

CVE-2023-30660
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2023 1 PoC

Exposure of Sensitive Information vulnerability in getDefaultChipId in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.

CVE-2023-30642
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper privilege management vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to call privilege function.

CVE-2023-30675
Samsung Pass General
6.2
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account information when Samsung Wallet is not installed.

CVE-2023-21446
MyFiles General
6.2
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper input validation in MyFiles prior to version 12.2.09 in Android R(11), 13.1.03.501 in Android S( 12) and 14.1.00.422 in Android T(13) allows local attacker to access data of MyFiles.

CVE-2023-31184
client General
6.2
MEDIUM
EPSS
3.5%
2023 CWE-798 1 PoC

ROZCOM client CWE-798: Use of Hard-coded Credentials

CVE-2023-53913
Rukovoditel General
6.2
MEDIUM
EPSS
0.2%
2023 CWE-1236 1 PoC

Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field. Attackers can craft payloads like =calc|a!z| to trigger code execution when an admin exports customer data as a CSV file.

CVE-2023-45184
i Access Client Solutions General
6.2
MEDIUM
EPSS
7.8%
2023 CWE-922 1 PoC

IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to obtain a decryption key due to improper authority checks. IBM X-Force ID: 268270.

CVE-2023-5441
vim/vim General
6.2
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository vim/vim prior to 20d161ace307e28690229b68584f2d84556f8960.

CVE-2023-30662
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2023 1 PoC

Exposure of Sensitive Information vulnerability in getChipIds in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.

CVE-2023-42531
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass restrictions on starting activities from the background.

CVE-2023-30659
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in Transaction prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

CVE-2023-29713
Software Genérico General
6.1
MEDIUM
EPSS
0.4%
2023 1 PoC

Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a crafted payload to the GET request after the /css/ directory.

CVE-2023-27000
Software Genérico General
6.1
MEDIUM
EPSS
0.8%
2023 1 PoC

Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the name parameter of the Profile and Exclusion List page(s).

CVE-2023-22432
web2py General ⚡ nuclei
6.1
MEDIUM
EPSS
40.8%
2023 1 PoC

Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirected to an arbitrary website by accessing a specially crafted URL. As a result, the user may become a victim of a phishing attack.

CVE-2023-23858
SAP NetWeaver AS for ABAP and ABAP Platform General
6.1
MEDIUM
EPSS
0.6%
2023 CWE-79 1 PoC

Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to send a crafted URL to a user, and by clicking the URL, the tricked user accesses SAP and might be directed with the response to somewhere out-side SAP and enter sensitive data. This could cause a limited impact on confidentiality and integrity of the application.

CVE-2023-1877
microweber/microweber General
6.1
MEDIUM
EPSS
4.7%
2023 CWE-77 1 PoC

Command Injection in GitHub repository microweber/microweber prior to 1.3.3.