5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-22062
Hyperion Financial Reporting Web Database
8.5
HIGH
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that is affected is 11.2.13.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. While the vulnerability is in Oracle Hyperion Financial Reporting, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Repor

CVE-2023-32190
openSUSE Tumbleweed General
8.5
HIGH
EPSS
0.1%
2023 1 PoC

mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.

CVE-2023-53959
FileZilla Client Web
8.5
HIGH
EPSS
0.4%
2023 CWE-427 1 PoC

FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll in the application directory. Attackers can generate a reverse shell payload using msfvenom and replace the missing DLL to achieve remote code execution when the application launches.

CVE-2023-53984
HotKey Clipboard General
8.5
HIGH
EPSS
0.0%
2023 CWE-428 1 PoC

Clevo HotKey Clipboard 2.1.0.6 contains an unquoted service path vulnerability in the HKClipSvc service that allows local non-privileged users to potentially execute code with system privileges. Attackers can exploit the misconfigured service path to inject and execute arbitrary code by placing malicious executables in specific file system locations.

CVE-2023-53949
AspEmail General
8.5
HIGH
EPSS
0.0%
2023 CWE-732 1 PoC

AspEmail 5.6.0.2 contains a binary permission vulnerability that allows local users to escalate privileges through the Persits Software EmailAgent service. Attackers can exploit full write permissions in the BIN directory to replace the service executable and gain elevated system access.

CVE-2023-2141
DELMIA Apriso General
8.5
HIGH
EPSS
3.5%
2023 CWE-502 1 PoC

An unsafe .NET object deserialization in DELMIA Apriso Release 2017 through Release 2022 could lead to post-authentication remote code execution.

CVE-2023-22508
Confluence Data Center General
8.5
HIGH
EPSS
5.1%
2023 3 PoCs

This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22508 was introduced in version 6.1.0 of Confluence Data Center & Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user interaction. Atlassian recommends that you upgrade your instance to avoid this bug using the following options: * Upgrade to a Confluence feature release greater than or equal to 8.2.0 (ie: 8.2, 8.2, 8.4,

CVE-2023-30658
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in DataProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

CVE-2023-45657
Nexter Database
8.5
HIGH
EPSS
11.2%
2023 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in POSIMYTH Nexter allows SQL Injection.This issue affects Nexter: from n/a through 2.0.3.

CVE-2023-3517
Pentaho Data Integration & Analytics General
8.5
HIGH
EPSS
0.1%
2023 CWE-99 1 PoC

Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.

CVE-2023-53912
USB Flash Drives Control Windows
8.5
HIGH
EPSS
0.0%
2023 CWE-428 1 PoC

USB Flash Drives Control 4.1.0.0 contains an unquoted service path vulnerability in its service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\USB Flash Drives Control\usbcs.exe' to inject malicious executables and escalate privileges on Windows systems.

CVE-2023-54338
Tftpd32_SE General
8.5
HIGH
EPSS
0.0%
2023 CWE-428 1 PoC

Tftpd32 SE 4.60 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be run with system-level permissions.

CVE-2023-1837
HYPR Server Web
8.5
HIGH
EPSS
0.1%
2023 CWE-306 1 PoC

Missing Authentication for critical function vulnerability in HYPR Server allows Authentication Bypass when using Legacy APIs.This issue affects HYPR Server: before 8.0 (with enabled Legacy APIs)

CVE-2023-41808
Pandora FMS General
8.5
HIGH
EPSS
0.1%
2023 CWE-269 1 PoC

Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability allows an unauthorised user to escalate and read sensitive files as if they were root. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-53937
Hubstaff General
8.5
HIGH
EPSS
0.0%
2023 CWE-427 1 PoC

Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious library. Attackers can generate a custom DLL using Metasploit and place it in the system32 directory to obtain a reverse shell during application startup.

CVE-2023-21439
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.1%
2023 CWE-20 1 PoC

Improper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allows attackers to launch certain activities.

CVE-2023-30656
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in LSOItemData prior to SMR Jul-2023 Release 1 allows attackers to launch certain activities.

CVE-2023-0020
SAP BusinessObjects Business Intelligence Platform General
8.5
HIGH
EPSS
0.3%
2023 CWE-200 1 PoC

SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high impact on confidentiality and limited impact on integrity of the application.

CVE-2023-45358
Software Genérico Web
8.5
HIGH
EPSS
0.2%
2023 1 PoC

Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application. 6.14 (6.14.0) is also a fixed release.

CVE-2023-30692
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.1%
2023 1 PoC

Improper input validation vulnerability in Evaluator prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.