5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-26607
Software Genérico General
7.1
HIGH
EPSS
0.1%
2023 1 PoC

In the Linux kernel 6.0.8, there is an out-of-bounds read in ntfs_attr_find in fs/ntfs/attrib.c.

CVE-2023-47514
Star CloudPRNT for WooCommerce Web Cloud
7.1
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in lawrenceowen, gcubero, acunnningham, fmahmood Star CloudPRNT for WooCommerce plugin <= 2.0.3 versions.

CVE-2023-0191
vGPU software (guest driver - Windows), vGPU software (guest driver - Linux), vGPU software (Virtual GPU Manager - Citrix Hypervisor, VMware vSphere, Red Hat Enterprise Linux KVM), NVIDIA Cloud Gaming (guest driver - Windows), NVIDIA Cloud Gaming (guest driver - Linux), NVIDIA Cloud Gaming (Virtual GPU Manager - Red Hat Enterprise Linux KVM) Networking Cloud Windows
7.1
HIGH
EPSS
0.1%
2023 CWE-119 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds access may lead to denial of service or data tampering.

CVE-2023-2859
nilsteampassnet/teampass General
7.1
HIGH
EPSS
5.8%
2023 CWE-94 2 PoCs

Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

CVE-2023-30743
SAPUI5 General
7.1
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Due to improper neutralization of input in SAPUI5 - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, sap.m.FormattedText SAPUI5 control allows injection of untrusted CSS. This blocks user’s interaction with the application. Further, in the absence of URL validation by the application, the vulnerability could lead to the attacker reading or modifying user’s information through phishing attack.

CVE-2023-0470
modoboa/modoboa Web
7.1
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository modoboa/modoboa prior to 2.0.4.

CVE-2023-4561
omeka/omeka-s Web
7.1
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.4.

CVE-2023-20900
VMware Tools Web
7.1
HIGH
EPSS
0.8%
2023 2 PoCs

A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .

CVE-2023-42493
v3.0.6433.1964 General
7.1
HIGH
EPSS
0.1%
2023 CWE-256 1 PoC

EisBaer Scada - CWE-256: Plaintext Storage of a Password

CVE-2023-36535
Zoom Clients General
7.1
HIGH
EPSS
0.2%
2023 CWE-449 1 PoC

Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network access.

CVE-2023-29439
FooGallery Web ⚡ nuclei
7.1
HIGH
EPSS
67.0%
2023 CWE-79 2 PoCs

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.35 versions.

CVE-2023-3567
Red Hat Enterprise Linux 8 General
7.1
HIGH
EPSS
0.0%
2023 CWE-416 4 PoCs

A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue may allow an attacker with local user access to cause a system crash or leak internal kernel information.

CVE-2023-42561
Samsung Mobile Devices General
7.1
HIGH
EPSS
0.2%
2023 1 PoC

Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physical attacker to execute arbitrary code.

CVE-2023-41112
Software Genérico General
7.1
HIGH
EPSS
0.2%
2023 1 PoC

An issue was discovered in Samsung Mobile Processor, Wearable Processor, Automotive Processor, and Modem (Exynos 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, W920, Modem 5123, Modem 5300, and Auto T5123). A buffer copy, without checking the size of the input, can cause abnormal termination of a mobile phone. This occurs in the RLC task and RLC module.

CVE-2023-30777
Advanced Custom Fields Pro Web ⚡ nuclei
7.1
HIGH
EPSS
87.3%
2023 CWE-79 2 PoCs

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced Custom Fields plugins <= 6.1.5 versions.

CVE-2023-47684
Essential Grid Web ⚡ nuclei
7.1
HIGH
EPSS
2.1%
2023 CWE-79 0 PoCs

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ThemePunch OHG Essential Grid plugin <= 3.1.0 versions.

CVE-2023-34044
Workstation General
7.1
HIGH
EPSS
0.0%
2023 1 PoC

VMware Workstation( 17.x prior to 17.5) and Fusion(13.x prior to 13.5) contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.

CVE-2023-26440
OX App Suite Web Database
7.1
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

The cacheservice API could be abused to indirectly inject parameters with SQL syntax which was insufficiently sanitized and would later be executed when creating new cache groups. Attackers with access to a local or restricted network could perform arbitrary SQL queries. We have improved the input check for API calls and filter for potentially malicious content. No publicly available exploits are known.

CVE-2023-40208
Stock Ticker Web ⚡ nuclei
7.1
HIGH
EPSS
3.2%
2023 CWE-79 0 PoCs

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Aleksandar Urošević Stock Ticker plugin <= 3.23.3 versions.

CVE-2023-41704
OX App Suite General
7.1
HIGH
EPSS
0.5%
2023 CWE-79 1 PoC

Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could be injected to a users sessions when interacting with E-Mails. Please deploy the provided updates and patch releases. CID handing has been improved and resulting content is checked for malicious content. No publicly available exploits are known.