5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-4108
Mattermost General
4.5
MEDIUM
EPSS
0.2%
2023 CWE-532 1 PoC

Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged

CVE-2023-21435
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-200 1 PoC

Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address information via log.

CVE-2023-30681
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.0%
2023 1 PoC

An improper input validation vulnerability within initialize function in HAL VaultKeeper prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.

CVE-2023-4636
File Sharing & Download Manager – User Private Files Web Windows
4.4
MEDIUM
EPSS
3.3%
2023 CWE-79 1 PoC

The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVE-2023-20813
MT6580, MT6739, MT6761, MT6765, MT6768, MT6779, MT6781, MT6833, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6891, MT6893, MT6895, MT6983, MT6985 General
4.4
MEDIUM
EPSS
0.0%
2023 1 PoC

In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453549; Issue ID: ALPS07453549.

CVE-2023-21510
Samsung Blockchain Keystore General
4.4
MEDIUM
EPSS
0.0%
2023 CWE-125 1 PoC

Out-of-bounds Read vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.

CVE-2023-29109
Application Interface Framework (Message Dashboard) General
4.4
MEDIUM
EPSS
0.4%
2023 CWE-1236 1 PoC

The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows an Excel formula injection. An authorized attacker can inject arbitrary Excel formulas into fields like the Tooltip of the Custom Hints List. Once the victim opens the downloaded Excel document, the formula will be executed. As a result, an attacker can cause limited impact on the confidentiality and integrity of the application.

CVE-2023-0677
phpipam/phpipam Web
4.4
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to v1.5.1.

CVE-2023-30736
Samsung Assistant Web
4.4
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper authorization in PushMsgReceiver of Samsung Assistant prior to version 8.7.00.1 allows attacker to execute javascript interface. To trigger this vulnerability, user interaction is required.

CVE-2023-30728
PackageInstallerCHN General
4.4
MEDIUM
EPSS
0.1%
2023 1 PoC

Intent redirection vulnerability in PackageInstallerCHN prior to version 13.1.03.00 allows local attacker to access arbitrary file. This vulnerability requires user interaction.

CVE-2023-49100
Software Genérico General
4.4
MEDIUM
EPSS
0.0%
2023 1 PoC

Trusted Firmware-A (TF-A) before 2.10 has a potential read out-of-bounds in the SDEI service. The input parameter passed in register x1 is not validated well enough in the function sdei_interrupt_bind. The parameter is passed to a call to plat_ic_get_interrupt_type. It can be any arbitrary value passing checks in the function plat_ic_is_sgi. A compromised Normal World (Linux kernel) can enable a root-privileged attacker to issue arbitrary SMC calls. Using this primitive, he can control the content of registers x0 through x6, which are used to send parameters to TF-A. Out-of-bounds addresses ca

CVE-2023-30665
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper input validation vulnerability in OnOemServiceMode in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds read.

CVE-2023-21518
Samsung SearchWidget General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control vulnerability in SearchWidget prior to version 3.3 in China models allows untrusted applications to start arbitrary activity.

CVE-2023-21430
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-125 1 PoC

An out-of-bound read vulnerability in mapToBuffer function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR JAN-2023 Release 1 allows attacker to cause memory access fault.

CVE-2023-20579
AMD Ryzen™ 5000 Series Desktop Processor with Radeon™ Graphics General
4.4
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability.

CVE-2023-21460
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-287 1 PoC

Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting.

CVE-2023-42756
Red Hat Enterprise Linux 9 General
4.4
MEDIUM
EPSS
0.0%
2023 CWE-362 1 PoC

A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP can lead to a kernel panic due to the invocation of `__ip_set_put` on a wrong `set`. This issue may allow a local user to crash the system.

CVE-2023-2485
GitLab DevOps
4.4
MEDIUM
EPSS
0.2%
2023 CWE-266 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A malicious maintainer in a project can escalate other users to Owners in that project if they import members from another project that those other users are Owners of.

CVE-2023-30721
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2023 1 PoC

Insertion of sensitive information into log vulnerability in Locksettings prior to SMR Sep-2023 Release 1 allows a privileged local attacker to get lock screen match information from the log.

CVE-2023-0907
Twister Antivirus General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability, which was classified as problematic, has been found in Filseclab Twister Antivirus 8.17. Affected by this issue is the function 0x220017 in the library ffsmon.sys of the component IoControlCode Handler. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-221456.