5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-42541
Samsung Push Service General
4.0
MEDIUM
EPSS
0.3%
2023 1 PoC

Improper authorization in PushClientProvider of Samsung Push Service prior to version 3.4.10 allows attacker to access unique id.

CVE-2023-5873
pimcore/pimcore Web
4.0
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 11.1.0.

CVE-2023-23003
Software Genérico General
4.0
MEDIUM
EPSS
0.1%
2023 1 PoC

In the Linux kernel before 5.16, tools/perf/util/expr.c lacks a check for the hashmap__new return value.

CVE-2023-1702
pimcore/pimcore Web
4.0
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.20.

CVE-2023-1429
pimcore/pimcore Web
4.0
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.19.

CVE-2023-30718
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper export of android application components vulnerability in WifiApAutoHotspotEnablingActivity prior to SMR Sep-2023 Release 1 allows local attacker to change a Auto Hotspot setting.

CVE-2023-45864
Software Genérico General
4.0
MEDIUM
EPSS
0.0%
2023 1 PoC

A race condition issue discovered in Samsung Mobile Processor Exynos 9820, 980, 1080, 2100, 2200, 1280, and 1380 allows unintended modifications of values within certain areas.

CVE-2023-5998
gpac/gpac General
4.0
MEDIUM
EPSS
0.1%
2023 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3.0-DEV.

CVE-2023-21471
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper access control vulnerability in SemClipboard prior to SMR Apr-2023 Release 1 allows attackers to read arbitrary files with system permission.

CVE-2023-30707
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in FileProviderStatusReceiver in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows local attackers to delete arbitrary files with Samsung Keyboard privilege.

CVE-2023-21429
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2023 CWE-285 1 PoC

Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID.

CVE-2023-42540
Samsung Account General
4.0
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper access control vulnerability in Samsung Account prior to version 14.5.01.1 allows attackers to access sensitive information via implicit intent.

CVE-2023-21900
Solaris Operating System Database
4.0
MEDIUM
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: NSSwitch). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Solaris, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle

CVE-2023-21437
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2023 CWE-287 1 PoC

Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive information via implicit broadcast.

CVE-2023-21461
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2023 CWE-285 1 PoC

Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity.

CVE-2023-21442
Runestone General
4.0
MEDIUM
EPSS
0.0%
2023 CWE-284 1 PoC

Improper access control vulnerability in Runestone application prior to version 2.9.09.003 in Android R(11) and 3.2.01.007 in Android S(12) allows local attackers to get device location information.

CVE-2023-1160
cockpit-hq/cockpit General
4.0
MEDIUM
EPSS
0.1%
2023 CWE-1103 1 PoC

Use of Platform-Dependent Third Party Components in GitHub repository cockpit-hq/cockpit prior to 2.4.0.

CVE-2023-30711
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to insert arbitrary data to the provider.

CVE-2023-21505
Samsung Core Service General
4.0
MEDIUM
EPSS
0.3%
2023 CWE-285 1 PoC

Improper access control in Samsung Core Service prior to version 2.1.00.36 allows attacker to write arbitrary file in sandbox.

CVE-2023-5344
vim/vim General
4.0
MEDIUM
EPSS
0.1%
2023 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.