5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-1837
HYPR Server Web
8.5
HIGH
EPSS
0.1%
2023 CWE-306 1 PoC

Missing Authentication for critical function vulnerability in HYPR Server allows Authentication Bypass when using Legacy APIs.This issue affects HYPR Server: before 8.0 (with enabled Legacy APIs)

CVE-2023-2141
DELMIA Apriso General
8.5
HIGH
EPSS
3.5%
2023 CWE-502 1 PoC

An unsafe .NET object deserialization in DELMIA Apriso Release 2017 through Release 2022 could lead to post-authentication remote code execution.

CVE-2023-53937
Hubstaff General
8.5
HIGH
EPSS
0.0%
2023 CWE-427 1 PoC

Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious library. Attackers can generate a custom DLL using Metasploit and place it in the system32 directory to obtain a reverse shell during application startup.

CVE-2023-54336
Mediconta General
8.5
HIGH
EPSS
0.0%
2023 CWE-428 1 PoC

Mediconta 3.7.27 contains an unquoted service path vulnerability in the servermedicontservice that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\medicont3\ to inject malicious code that would execute with LocalSystem permissions during service startup.

CVE-2023-53957
Kimai Web
8.5
HIGH
EPSS
0.2%
2023 CWE-1275 1 PoC

Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.

CVE-2023-3532
outline/outline Web
8.5
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to 0.70.1.

CVE-2023-21491
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control vulnerability in ThemeManager prior to SMR May-2023 Release 1 allows local attackers to write arbitrary files with system privilege.

CVE-2023-41808
Pandora FMS General
8.5
HIGH
EPSS
0.1%
2023 CWE-269 1 PoC

Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability allows an unauthorised user to escalate and read sensitive files as if they were root. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-35157
xwiki-platform Web
8.5
HIGH
EPSS
1.4%
2023 CWE-80 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to perform an XSS by forging a request to a delete attachment action with a specific attachment name. Now this XSS can be exploited only if the attacker knows the CSRF token of the user, or if the user ignores the warning about the missing CSRF token. The vulnerability has been patched in XWiki 15.1-rc-1 and XWiki 14.10.6.

CVE-2023-30656
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in LSOItemData prior to SMR Jul-2023 Release 1 allows attackers to launch certain activities.

CVE-2023-30655
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in SCEPProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

CVE-2023-45358
Software Genérico Web
8.5
HIGH
EPSS
0.2%
2023 1 PoC

Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application. 6.14 (6.14.0) is also a fixed release.

CVE-2023-1362
unilogies/bumsys General ⚡ nuclei
8.4
HIGH
EPSS
53.5%
2023 CWE-1021 1 PoC

Improper Restriction of Rendered UI Layers or Frames in GitHub repository unilogies/bumsys prior to v2.0.2.

CVE-2023-6071
ESM General
8.4
HIGH
EPSS
0.6%
2023 CWE-77 1 PoC

An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administrator to execute arbitrary code as root on the ESM. This is possible as the input isn't correctly sanitized when adding a new data source.

CVE-2023-41791
Pandora FMS Web
8.4
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed users with low privileges to introduce Javascript executables via a translation string that could affect the integrity of some configuration files. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-5060
librenms/librenms Web
8.4
HIGH
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.1.

CVE-2023-42537
Samsung Mobile Devices General
8.4
HIGH
EPSS
0.1%
2023 1 PoC

An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

CVE-2023-36538
Zoom Rooms for Windows Windows
8.4
HIGH
EPSS
0.0%
2023 CWE-426 1 PoC

Improper access control in Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.

CVE-2023-20854
VMware Workstation General
8.4
HIGH
EPSS
0.1%
2023 1 PoC

VMware Workstation contains an arbitrary file deletion vulnerability. A malicious actor with local user privileges on the victim's machine may exploit this vulnerability to delete arbitrary files from the file system of the machine on which Workstation is installed.

CVE-2023-24530
BusinessObjects Business Intelligence Platform (CMC) General
8.4
HIGH
EPSS
0.6%
2023 CWE-434 1 PoC

SAP BusinessObjects Business Intelligence Platform (CMC) - versions 420, 430, allows an authenticated admin user to upload malicious code that can be executed by the application over the network. On successful exploitation, attacker can perform operations that may completely compromise the application causing high impact on confidentiality, integrity and availability of the application.