5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-41810
Pandora FMS Web
4.0
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed Javascript code to be executed in some Widgets' text box. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-2327
pimcore/pimcore Web
4.0
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-21449
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2023 CWE-200 1 PoC

Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive information without proper permission.

CVE-2023-1701
pimcore/pimcore Web
4.0
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.20.

CVE-2023-21428
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2023 CWE-20 1 PoC

Improper input validation vulnerability in TelephonyUI prior to SMR Jan-2023 Release 1 allows attackers to configure Preferred Call. The patch removes unused code.

CVE-2023-21464
Samsung Calendar General
4.0
MEDIUM
EPSS
0.1%
2023 CWE-281 1 PoC

Improper access control in Samsung Calendar prior to versions 12.4.02.9000 in Android 13 and 12.3.08.2000 in Android 12 allows local attacker to configure improper status.

CVE-2023-21447
Samsung Cloud Cloud
4.0
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control vulnerabilities in Samsung Cloud prior to version 5.3.0.32 allows local attackers to access information with Samsung Cloud's privilege via implicit intent.

CVE-2023-5520
gpac/gpac General
4.0
MEDIUM
EPSS
0.0%
2023 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.

CVE-2023-4720
gpac/gpac General
4.0
MEDIUM
EPSS
0.0%
2023 CWE-1077 1 PoC

Floating Point Comparison with Incorrect Operator in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-21469
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.GEOFENCE action.

CVE-2023-50007
Software Genérico Networking
4.0
MEDIUM
EPSS
0.0%
2023 1 PoC

FFmpeg v.n6.1-3-g466799d4f5 allows an attacker to trigger use of a parameter of negative size in the av_samples_set_silence function in thelibavutil/samplefmt.c:260:9 component.

CVE-2023-30715
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper access control vulnerability in Weather prior to SMR Sep-2023 Release 1 allows attackers to access location information set in Weather without permission.

CVE-2023-30724
Gallery General
4.0
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper authentication in GallerySearchProvider of Gallery prior to version 14.5.01.2 allows attacker to access search history.

CVE-2023-30737
Samsung Health General
4.0
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive information via implicit intent.

CVE-2023-1517
pimcore/pimcore Web
4.0
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.19.

CVE-2023-21470
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.NETWORK_LOCATION action.

CVE-2023-21495
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install KSP app when device admin is set.

CVE-2023-0780
cockpit-hq/cockpit General
4.0
MEDIUM
EPSS
0.2%
2023 CWE-1021 1 PoC

Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev.

CVE-2023-30717
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2023 1 PoC

Sensitive information exposure vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows attackers to get unresettable identifiers.

CVE-2023-21463
MyFiles General
4.0
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control vulnerability in MyFiles application prior to versions 12.2.09.0 in Android 11, 13.1.03.501 in Android 12 and 14.1.03.0 in Android 13 allows local attacker to get sensitive information of secret mode in Samsung Internet application with specific conditions.