5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-1070
nilsteampassnet/teampass General
7.1
HIGH
EPSS
0.3%
2023 CWE-73 1 PoC

External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22.

CVE-2023-3141
Kernel General
7.1
HIGH
EPSS
0.0%
2023 CWE-416 1 PoC

A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak.

CVE-2023-0183
vGPU software (guest driver - Linux), vGPU software (Virtual GPU Manager - Citrix Hypervisor, VMware vSphere, Red Hat Enterprise Linux KVM), NVIDIA Cloud Gaming (guest driver - Linux), NVIDIA Cloud Gaming (Virtual GPU Manager - Red Hat Enterprise Linux KVM) Networking Cloud
7.1
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an out-of-bounds write can lead to denial of service and data tampering.

CVE-2023-34458
mx-chain-go General
7.1
HIGH
EPSS
2.6%
2023 CWE-400 3 PoCs

mx-chain-go is the official implementation of the MultiversX blockchain protocol, written in golang. When executing a relayed transaction, if the inner transaction failed, it would have increased the inner transaction's sender account nonce. This could have contributed to a limited DoS attack on a targeted account. The fix is a breaking change so a new flag `RelayedNonceFixEnableEpoch` was needed. This was a strict processing issue while validating blocks on a chain. This vulnerability has been patched in version 1.4.17.

CVE-2023-4814
Data Loss Prevention Endpoint for Windows General
7.1
HIGH
EPSS
0.0%
2023 CWE-250 1 PoC

A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for which the user does not have permission to.

CVE-2023-53930
projectSend Web
7.1
HIGH
EPSS
0.1%
2023 CWE-639 1 PoC

ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manipulating the download ID parameter. Attackers can access any user's private files by changing the 'id' parameter in the download request to process.php.

CVE-2023-51747
Apache James server Web
7.1
HIGH
EPSS
0.2%
2023 CWE-20 1 PoC

Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a difference of interpretation between the sender and the receiver which can be exploited by an attacker to forge an SMTP envelop, allowing for instance to bypass SPF checks. The patch implies enforcement of CRLF as a line delimiter as part of the DATA transaction. We recommend James users to upgrade to non vulnerable versions.

CVE-2023-6458
Mattermost General
7.1
HIGH
EPSS
0.5%
2023 CWE-74 1 PoC

Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traversal.

CVE-2023-1385
Fire TV Stick 3rd gen General
7.1
HIGH
EPSS
0.2%
2023 CWE-330 1 PoC

Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to unauthorized authentication to amzn.lightning services. This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS 7.6.3.3.

CVE-2023-53944
EasyPHP Webserver Web Windows
7.1
HIGH
EPSS
0.2%
2023 CWE-22 1 PoC

EasyPHP Webserver 14.1 contains a path traversal vulnerability that allows remote users with low privileges to access files outside the document root by bypassing SecurityManager restrictions. Attackers can send GET requests with encoded directory traversal sequences like /..%5c..%5c to read system files such as /windows/win.ini.

CVE-2023-1320
osticket/osticket Web
7.1
HIGH
EPSS
0.7%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.

CVE-2023-42492
v3.0.6433.1964 General
7.1
HIGH
EPSS
0.1%
2023 CWE-321 1 PoC

EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key

CVE-2023-26436
OX App Suite Web
7.1
HIGH
EPSS
0.2%
2023 CWE-94 1 PoC

Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not properly checked during deserialization. Access to this API endpoint is restricted to local networks by default. Arbitrary code could be injected that is being executed when processing the request. A check has been introduced to restrict processing of legal and expected classes for this API. We now log a warning in case there are attempts to inject illegal classes. No publicly available exploits are known.

CVE-2023-4264
Zephyr General
7.1
HIGH
EPSS
0.2%
2023 CWE-120 1 PoC

Potential buffer overflow vulnerabilities n the Zephyr Bluetooth subsystem.

CVE-2023-7197
Marketing Twitter Bot Web Windows
7.1
HIGH
EPSS
0.1%
2023 1 PoC

The Marketing Twitter Bot WordPress plugin through 1.11 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2023-37988
Contact Form Generator Web ⚡ nuclei
7.1
HIGH
EPSS
21.8%
2023 CWE-79 2 PoCs

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Creative Solutions Contact Form Generator plugin <= 2.5.5 versions.

CVE-2023-0818
gpac/gpac General
7.1
HIGH
EPSS
0.0%
2023 CWE-193 1 PoC

Off-by-one Error in GitHub repository gpac/gpac prior to v2.3.0-DEV.

CVE-2023-0181
vGPU software (guest driver - Windows), vGPU software (guest driver - Linux), vGPU software (Virtual GPU Manager - Citrix Hypervisor, VMware vSphere, Red Hat Enterprise Linux KVM), NVIDIA Cloud Gaming (guest driver - Windows), NVIDIA Cloud Gaming (guest driver - Linux), NVIDIA Cloud Gaming (Virtual GPU Manager - Red Hat Enterprise Linux KVM) Networking Cloud Windows
7.1
HIGH
EPSS
0.0%
2023 CWE-280 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a kernel mode layer handler, where memory permissions are not correctly checked, which may lead to denial of service and data tampering.

CVE-2023-0180
vGPU software (guest driver - Linux), vGPU software (Virtual GPU Manager - Citrix Hypervisor, VMware vSphere, Red Hat Enterprise Linux KVM), NVIDIA Cloud Gaming (guest driver - Linux), NVIDIA Cloud Gaming (Virtual GPU Manager - Red Hat Enterprise Linux KVM) Networking Cloud
7.1
HIGH
EPSS
0.1%
2023 CWE-125 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in a kernel mode layer handler, which may lead to denial of service or information disclosure.