33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-6071
ESM General
8.4
HIGH
EPSS
0.6%
2023 CWE-77 1 PoC

An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administrator to execute arbitrary code as root on the ESM. This is possible as the input isn't correctly sanitized when adding a new data source.

CVE-2023-42536
Samsung Mobile Devices General
8.4
HIGH
EPSS
0.1%
2023 1 PoC

An improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

CVE-2023-28528
AIX General
8.4
HIGH
EPSS
1.6%
2023 CWE-78 2 PoCs

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 251207.

CVE-2023-29360
🔥 KEV Windows 10 Version 1809 Windows
8.4
HIGH
EPSS
30.3%
2023 CWE-822 3 PoCs

Microsoft Streaming Service Elevation of Privilege Vulnerability

CVE-2023-1355
vim/vim General
8.4
HIGH
EPSS
0.0%
2023 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1402.

CVE-2024-43704
Graphics DDK General
8.4
HIGH
EPSS
0.0%
2024 CWE-668 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain access to the graphics buffers of a parent process.

CVE-2024-43087
Android General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled accessibility service in the accessibility service settings due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVE-2024-52035
catdoc General
8.4
HIGH
EPSS
0.2%
2024 CWE-190 2 PoCs

An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-35142
Security Verify Access Docker DevOps
8.4
HIGH
EPSS
0.0%
2024 CWE-250 1 PoC

IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges. IBM X-Force ID: 292418.

CVE-2024-47921
SPS General
8.4
HIGH
EPSS
0.0%
2024 CWE-327 1 PoC

Smadar SPS – CWE-327: Use of a Broken or Risky Cryptographic Algorithm

CVE-2024-51379
Software Genérico Web
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Stored Cross-Site Scripting (XSS) vulnerability discovered in JATOS v3.9.3. The vulnerability exists in the description component of the study section, where an attacker can inject JavaScript into the description field. This allows for the execution of malicious scripts when an admin views the description, potentially leading to account takeover and unauthorized actions.

CVE-2024-40781
macOS General
8.4
HIGH
EPSS
0.0%
2024 2 PoCs

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A local attacker may be able to elevate their privileges.

CVE-2024-51380
Software Genérico Web
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Stored Cross-Site Scripting (XSS) vulnerability discovered in the Properties Component of JATOS v3.9.3. This flaw allows an attacker to inject malicious JavaScript into the properties section of a study, specifically within the UUID field. When an admin user accesses the study's properties, the injected script is executed in the admin's browser, which could lead to unauthorized actions, including account compromise and privilege escalation.

CVE-2024-36474
G Structured File Library (libgsf) General
8.4
HIGH
EPSS
0.1%
2024 CWE-190 2 PoCs

An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library (libgsf) version v1.14.52. A specially crafted file can result in an integer overflow when processing the directory from the file that allows for an out-of-bounds index to be used when reading and writing to an array. This can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-6769
Windows 10 Windows
8.4
HIGH
EPSS
16.0%
2024 CWE-426 1 PoC

A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated attacker to elevate from a medium integrity process to a high integrity process without the intervention of a UAC prompt.

CVE-2024-31956
Software Genérico General
8.4
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks proper buffer length checking, which can result in an Out-of-Bounds Write.

CVE-2024-36600
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.

CVE-2024-34620
Samsung Mobile Devices General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Improper privilege management in SumeNNService prior to SMR Aug-2024 Release 1 allows local attackers to start privileged service.

CVE-2024-25817
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Buffer Overflow vulnerability in eza before version 0.18.2, allows local attackers to execute arbitrary code via the .git/HEAD, .git/refs, and .git/objects components.

CVE-2024-27169
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
8.4
HIGH
EPSS
0.0%
2024 CWE-306 1 PoC

Toshiba printers provides API without authentication for internal access. A local attacker can bypass authentication in applications, providing administrative access. As for the affected products/models/versions, see the reference URL.