5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-1487
WiseCleaner Wise System Monitor General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-404 3 PoCs

A vulnerability, which was classified as problematic, has been found in Lespeed WiseCleaner Wise System Monitor 1.5.3.54. This issue affects the function 0x9C40208C/0x9C402000/0x9C402084/0x9C402088/0x9C402004/0x9C4060C4/0x9C4060CC/0x9C4060D0/0x9C4060D4/0x9C40A0DC/0x9C40A0D8/0x9C40A0DC/0x9C40A0E0 in the library WiseHDInfo64.dll of the component IoControlCode Handler. The manipulation leads to denial of service. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The identifier VDB-223373 was assigned to this vulnerability.

CVE-2023-6765
Online Tours & Travels Management System Web Database
5.5
MEDIUM
EPSS
0.1%
2023 CWE-89 2 PoCs

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. This issue affects the function prepare of the file email_setup.php. The manipulation of the argument name leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-247895.

CVE-2023-6054
OA 2017 Web Database
5.5
MEDIUM
EPSS
0.2%
2023 CWE-89 1 PoC

A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.9. This affects an unknown part of the file general/wiki/cp/manage/lock.php. The manipulation of the argument TERM_ID_STR leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-244875. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-1630
Antivirus General
5.5
MEDIUM
EPSS
0.2%
2023 CWE-404 2 PoCs

A vulnerability, which was classified as problematic, has been found in JiangMin Antivirus 16.2.2022.418. Affected by this issue is the function 0x222000 in the library kvcore.sys of the component IOCTL Handler. The manipulation leads to denial of service. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224012.

CVE-2023-36629
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2023 2 PoCs

The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.

CVE-2023-28469
Software Genérico General
5.5
MEDIUM
EPSS
0.2%
2023 1 PoC

An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Valhall r29p0 through r42p0 before r43p0, and Arm's GPU Architecture Gen5 r41p0 through r42p0 before r43p0.

CVE-2023-43065
Unity Web
5.5
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Dell Unity prior to 5.3 contains a Cross-site scripting vulnerability. A low-privileged authenticated attacker can exploit these issues to obtain escalated privileges.

CVE-2023-2908
Libtiff General
5.5
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

A null pointer dereference issue was found in Libtiff's tif_dir.c file. This issue may allow an attacker to pass a crafted TIFF image file to the tiffcp utility which triggers a runtime error that causes undefined behavior. This will result in an application crash, eventually leading to a denial of service.

CVE-2023-21776
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
1.9%
2023 CWE-125 2 PoCs

Windows Kernel Information Disclosure Vulnerability

CVE-2023-3795
ChainCity Real Estate Investment Platform Database
5.5
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability classified as critical was found in Bug Finder ChainCity Real Estate Investment Platform 1.0. Affected by this vulnerability is an unknown functionality of the file /property of the component GET Parameter Handler. The manipulation of the argument name leads to sql injection. The associated identifier of this vulnerability is VDB-235063. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-3772
Red Hat Enterprise Linux 8 General
5.5
MEDIUM
EPSS
0.0%
2023 CWE-476 2 PoCs

A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of service.

CVE-2023-30722
Samsung Blockchain Keystore General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Protection Mechanism Failure in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.13.5 allows local attacker to execute arbitrary code.

CVE-2023-0516
Online Tours & Travels Management System Web Database
5.5
MEDIUM
EPSS
0.4%
2023 CWE-89 1 PoC

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. Affected is an unknown function of the file user/forget_password.php of the component Parameter Handler. The manipulation of the argument email leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-219336.

CVE-2023-36404
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
0.2%
2023 CWE-284 1 PoC

Windows Kernel Information Disclosure Vulnerability

CVE-2023-38368
Security Access Manager Docker DevOps
5.5
MEDIUM
EPSS
0.0%
2023 CWE-863 2 PoCs

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could disclose sensitive information to a local user to do improper permission controls. IBM X-Force ID: 261195.

CVE-2023-43582
Zoom Clients General
5.5
MEDIUM
EPSS
0.2%
2023 CWE-939 1 PoC

Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.

CVE-2023-5452
snipe/snipe-it Web
5.5
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.2.2.

CVE-2023-2620
GitLab DevOps
5.5
MEDIUM
EPSS
0.4%
2023 CWE-201 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1. A maintainer could modify a webhook URL to leak masked webhook secrets by manipulating other masked portions. This addresses an incomplete fix for CVE-2023-0838.

CVE-2023-0591
ubi_reader General
5.5
MEDIUM
EPSS
0.3%
2023 CWE-22 1 PoC

ubireader_extract_files is vulnerable to path traversal when run against specifically crafted UBIFS files, allowing the attacker to overwrite files outside of the extraction directory (provided the process has write access to that file or directory). This is due to the fact that a node name (dent_node.name) is considered trusted and joined to the extraction directory path during processing, then the node content is written to that joined path. By crafting a malicious UBIFS file with node names holding path traversal payloads (e.g. ../../tmp/outside.txt), it's possible to force ubi_reader to

CVE-2023-0597
Kernel General
5.5
MEDIUM
EPSS
0.0%
2023 CWE-200 2 PoCs

A flaw possibility of memory leak in the Linux kernel cpu_entry_area mapping of X86 CPU data to memory was found in the way user can guess location of exception stack(s) or other important data. A local user could use this flaw to get access to some important data with expected location in memory.