5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-31493
Software Genérico Web
6.6
MEDIUM
EPSS
2.5%
2023 2 PoCs

RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing execution of any commands on the remote system.

CVE-2023-34045
Fusion General
6.6
MEDIUM
EPSS
0.1%
2023 1 PoC

VMware Fusion(13.x prior to 13.5) contains a local privilege escalation vulnerability that occurs during installation for the first time (the user needs to drag or copy the application to a folder from the '.dmg' volume) or when installing an upgrade. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed or being installed for the first time.

CVE-2023-37941
Apache Superset Web
6.6
MEDIUM
EPSS
84.2%
2023 CWE-502 2 PoCs

If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. The Superset metadata db is an 'internal' component that is typically only accessible directly by the system administrator and the superset process itself. Gaining access to that database should be difficult and require significant privileges. This vulnerability impacts Apache Superset versions 1.5.0 up to and including 2.1.0. Users are recommended to upgrade to version 2.1.1 or later.

CVE-2023-3441
GitLab DevOps
6.6
MEDIUM
EPSS
0.1%
2023 CWE-213 1 PoC

An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not sufficiently warn about security implications of granting merge rights to protected branches.

CVE-2023-40660
Software Genérico General
6.6
MEDIUM
EPSS
0.0%
2023 CWE-287 1 PoC

A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed. This issue poses a security risk, particularly for OS logon/screen unlock and for small, permanently connected tokens to computers. Additionally, the token can internally track login status. This flaw allows an attacker to gain unauthorized access, carry out malicious actions, or compromise the system without the user's awareness.

CVE-2023-2429
thorsten/phpmyfaq Web
6.6
MEDIUM
EPSS
0.3%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.13.

CVE-2023-0198
vGPU software (guest driver - Linux), vGPU software (Virtual GPU Manager - Citrix Hypervisor, VMware vSphere, Red Hat Enterprise Linux KVM), , NVIDIA Cloud Gaming (guest driver - Linux), NVIDIA Cloud Gaming (Virtual GPU Manager - Red Hat Enterprise Linux KVM) Networking Cloud
6.6
MEDIUM
EPSS
0.1%
2023 CWE-119 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where improper restriction of operations within the bounds of a memory buffer can lead to denial of service, information disclosure, and data tampering.

CVE-2023-42564
Samsung Mobile Devices General
6.6
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to send broadcast with system privilege.

CVE-2023-42533
Samsung Mobile Devices General
6.6
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper Input Validation with USB Gadget Interface prior to SMR Nov-2023 Release 1 allows a physical attacker to execute arbitrary code in Kernel.

CVE-2023-42509
Artifactory General
6.6
MEDIUM
EPSS
0.3%
2023 CWE-755 1 PoC

JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data.

CVE-2023-50290
Apache Solr Web ⚡ nuclei
6.5
MEDIUM
EPSS
93.0%
2023 CWE-200 0 PoCs

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr. The Solr Metrics API publishes all unprotected environment variables available to each Apache Solr instance. Users are able to specify which environment variables to hide, however, the default list is designed to work for known secret Java system properties. Environment variables cannot be strictly defined in Solr, like Java system properties can be, and may be set for the entire host, unlike Java system properties which are set per-Java-proccess. The Solr Metrics API is protected by the "metrics-read" pe

CVE-2023-22037
Web Applications Desktop Integrator Web Database
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: MS Excel Specific). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Web Applications Desktop Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vu

CVE-2023-26987
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2023 2 PoCs

An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST request.

CVE-2023-26143
blamer Web
6.5
MEDIUM
EPSS
0.1%
2023 CWE-88 1 PoC

Versions of the package blamer before 1.0.4 are vulnerable to Arbitrary Argument Injection via the blameByFile() API. The library does not sanitize for user input or validate the given file path conforms to a specific schema, nor does it properly pass command-line flags to the git binary using the double-dash POSIX characters (--) to communicate the end of options.

CVE-2023-5006
WP Discord Invite Web Windows
6.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The WP Discord Invite WordPress plugin before 2.5.1 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to perform actions on their behalf by tricking a logged in administrator to submit a crafted request.

CVE-2023-3218
it-novum/openitcockpit General
6.5
MEDIUM
EPSS
0.0%
2023 CWE-366 1 PoC

Race Condition within a Thread in GitHub repository it-novum/openitcockpit prior to 4.6.5.

CVE-2023-47430
Software Genérico DevOps
6.5
MEDIUM
EPSS
0.0%
2023 1 PoC

Stack-buffer-overflow vulnerability in ReadyMedia (MiniDLNA) v1.3.3 allows attackers to cause a denial of service via via the SendContainer() function at tivo_commands.c.

CVE-2023-28180
macOS General
6.5
MEDIUM
EPSS
0.2%
2023 1 PoC

A denial-of-service issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. A user in a privileged network position may be able to cause a denial-of-service.

CVE-2023-1371
W4 Post List Web Windows
6.5
MEDIUM
EPSS
0.4%
2023 1 PoC

The W4 Post List WordPress plugin before 2.4.6 does not ensure that password protected posts can be accessed before displaying their content, which could allow any authenticated users to access them

CVE-2023-23458
DVR General
6.5
MEDIUM
EPSS
0.3%
2023 CWE-200 1 PoC

Sunell DVR, latest version, CWE-200: Exposure of Sensitive Information to an Unauthorized Actor through an unspecified request.