5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-4548
eCommerce CMS Web Database
6.3
MEDIUM
EPSS
1.5%
2023 CWE-89 2 PoCs

A vulnerability classified as critical has been found in SPA-Cart eCommerce CMS 1.9.0.3. This affects an unknown part of the file /search of the component GET Parameter Handler. The manipulation of the argument filter[brandid] leads to sql injection. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-238059.

CVE-2023-53905
projectSend General
6.2
MEDIUM
EPSS
0.1%
2023 CWE-1236 1 PoC

ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into user profile names. Attackers can craft payloads like =calc|a!z| in the name field to trigger code execution when administrators export action logs as CSV files.

CVE-2023-21458
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2023 CWE-269 1 PoC

Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent.

CVE-2023-3095
nilsteampassnet/teampass General
6.2
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

CVE-2023-46048
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2023 1 PoC

Tex Live 944e257 has a NULL pointer dereference in texk/web2c/pdftexdir/writet1.c. NOTE: this is disputed because it should be categorized as a usability problem.

CVE-2023-38267
Security Verify Access Appliance DevOps
6.2
MEDIUM
EPSS
0.0%
2023 CWE-311 1 PoC

IBM Security Access Manager Appliance (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 260584.

CVE-2023-30675
Samsung Pass General
6.2
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account information when Samsung Wallet is not installed.

CVE-2023-53913
Rukovoditel General
6.2
MEDIUM
EPSS
0.2%
2023 CWE-1236 1 PoC

Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field. Attackers can craft payloads like =calc|a!z| to trigger code execution when an admin exports customer data as a CSV file.

CVE-2023-30662
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2023 1 PoC

Exposure of Sensitive Information vulnerability in getChipIds in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.

CVE-2023-32329
Security Verify Access Appliance DevOps
6.2
MEDIUM
EPSS
0.0%
2023 CWE-345 1 PoC

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a user to download files from an incorrect repository due to improper file validation. IBM X-Force ID: 254972.

CVE-2023-30657
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in EnhancedAttestationResult prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

CVE-2023-21440
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2023 CWE-285 1 PoC

Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a screen capture.

CVE-2023-2788
Mattermost General
6.2
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while the attacker's account is deactivated.

CVE-2023-30660
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2023 1 PoC

Exposure of Sensitive Information vulnerability in getDefaultChipId in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.

CVE-2023-31184
client General
6.2
MEDIUM
EPSS
3.5%
2023 CWE-798 1 PoC

ROZCOM client CWE-798: Use of Hard-coded Credentials

CVE-2023-42531
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass restrictions on starting activities from the background.

CVE-2023-31005
Security Verify Access Appliance DevOps
6.2
MEDIUM
EPSS
0.0%
2023 CWE-269 1 PoC

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a local user to escalate their privileges due to an improper security configuration. IBM X-Force ID: 254767.

CVE-2023-53929
phpMyFAQ Web
6.2
MEDIUM
EPSS
0.1%
2023 CWE-1236 1 PoC

phpMyFAQ 3.1.12 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into their profile names. Attackers can modify their user profile name with a payload like 'calc|a!z|' to trigger code execution when an administrator exports user data as a CSV file.

CVE-2023-21118
Android General
6.2
MEDIUM
EPSS
0.1%
2023 2 PoCs

In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-269014004

CVE-2023-21434
Galaxy Store Web
6.2
MEDIUM
EPSS
0.7%
2023 CWE-20 1 PoC

Improper input validation vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to execute JavaScript by launching a web page.