5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-21980
MySQL Server Database
7.1
HIGH
EPSS
0.4%
2023 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 5.7.41 and prior and 8.0.32 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/

CVE-2023-21752
Windows 10 Version 22H2 Windows
7.1
HIGH
EPSS
33.0%
2023 CWE-284 2 PoCs

Windows Backup Service Elevation of Privilege Vulnerability

CVE-2023-36533
Zoom SDK's General
7.1
HIGH
EPSS
0.4%
2023 CWE-772 1 PoC

Uncontrolled resource consumption in Zoom SDKs before 5.14.7 may allow an unauthenticated user to enable a denial of service via network access.

CVE-2023-30868
CMS Tree Page View Web ⚡ nuclei
7.1
HIGH
EPSS
54.1%
2023 CWE-79 1 PoC

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jon Christopher CMS Tree Page View plugin <= 1.6.7 versions.

CVE-2023-5289
ikus060/rdiffweb General
7.1
HIGH
EPSS
0.1%
2023 CWE-770 1 PoC

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.4.

CVE-2023-32961
Zotpress Web
7.1
HIGH
EPSS
4.7%
2023 CWE-79 2 PoCs

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Katie Seaborn Zotpress plugin <= 7.3.3 versions.

CVE-2023-2591
nilsteampassnet/teampass Web
7.1
HIGH
EPSS
0.3%
2023 CWE-79 2 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitHub repository nilsteampassnet/teampass prior to 3.0.7.

CVE-2023-53907
Backup Plugin General
7.1
HIGH
EPSS
0.4%
2023 CWE-22 1 PoC

Bludit versions before 3.13.1 contain an authenticated file download vulnerability in the Backup Plugin that allows logged-in users to access arbitrary files. Attackers can exploit the plugin's download functionality by manipulating file path parameters to read sensitive system files through directory traversal.

CVE-2023-3749
VideoEdge General
7.1
HIGH
EPSS
0.0%
2023 CWE-349 1 PoC

A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.

CVE-2023-39215
Zoom Clients General
7.1
HIGH
EPSS
0.3%
2023 CWE-449 1 PoC

Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-1652
Linux Kernel General
7.1
HIGH
EPSS
0.0%
2023 CWE-416 1 PoC

A use-after-free flaw was found in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c in the NFS filesystem in the Linux Kernel. This issue could allow a local attacker to crash the system or it may lead to a kernel information leak problem.

CVE-2023-28229
🔥 KEV Windows 10 Version 1809 Windows
7.0
HIGH
EPSS
8.6%
2023 CWE-591 1 PoC

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

CVE-2023-29483
Software Genérico General
7.0
HIGH
EPSS
7.3%
2023 1 PoC

eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.

CVE-2023-4504
CUPS General
7.0
HIGH
EPSS
0.0%
2023 CWE-122 1 PoC

Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.

CVE-2023-35828
Software Genérico General
7.0
HIGH
EPSS
0.0%
2023 3 PoCs

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in renesas_usb3_remove in drivers/usb/gadget/udc/renesas_usb3.c.

CVE-2023-35823
Software Genérico General
7.0
HIGH
EPSS
0.0%
2023 1 PoC

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_finidev in drivers/media/pci/saa7134/saa7134-core.c.

CVE-2023-28466
Software Genérico General
7.0
HIGH
EPSS
0.0%
2023 1 PoC

do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race condition (with a resultant use-after-free or NULL pointer dereference).

CVE-2023-22291
Ichitaro General
7.0
HIGH
EPSS
0.2%
2023 CWE-590 2 PoCs

An invalid free vulnerability exists in the Frame stream parser functionality of Ichitaro 2022 1.0.1.57600. A specially crafted document can lead to an attempt to free a stack pointer, which causes memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-5097
Workforce Access Windows
7.0
HIGH
EPSS
0.1%
2023 CWE-22 1 PoC

Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: before 8.7.

CVE-2023-0887
TFTPD64-SE General
7.0
HIGH
EPSS
0.1%
2023 CWE-428 1 PoC

A vulnerability was found in phjounin TFTPD64-SE 4.64 and classified as critical. This issue affects some unknown processing of the file tftpd64_svc.exe. The manipulation leads to unquoted search path. An attack has to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The associated identifier of this vulnerability is VDB-221351.