5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-1755
thorsten/phpmyfaq Web
8.4
HIGH
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2023-47129
cms Web
8.4
HIGH
EPSS
5.4%
2023 CWE-434 1 PoC

Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded. This only affects forms using the "Forms" feature and not just _any_ arbitrary form. This does not affect the control panel. This issue has been patched in 3.4.13 and 4.33.0.

CVE-2023-6143
Midgard GPU Kernel Driver General
8.4
HIGH
EPSS
0.1%
2023 CWE-416 1 PoC

Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to exploit a software race condition to perform improper memory processing operations. If the system’s memory is carefully prepared by the user and the system is under heavy load, then this in turn cause a use-after-free.This issue affects Midgard GPU Kernel Driver: from r13p0 through r32p0; Bifrost GPU Kernel Driver: from r1p0 through r18p0; Valhall GPU Kernel Driver: from

CVE-2023-24530
BusinessObjects Business Intelligence Platform (CMC) General
8.4
HIGH
EPSS
0.6%
2023 CWE-434 1 PoC

SAP BusinessObjects Business Intelligence Platform (CMC) - versions 420, 430, allows an authenticated admin user to upload malicious code that can be executed by the application over the network. On successful exploitation, attacker can perform operations that may completely compromise the application causing high impact on confidentiality, integrity and availability of the application.

CVE-2023-6071
ESM General
8.4
HIGH
EPSS
0.6%
2023 CWE-77 1 PoC

An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administrator to execute arbitrary code as root on the ESM. This is possible as the input isn't correctly sanitized when adding a new data source.

CVE-2023-42536
Samsung Mobile Devices General
8.4
HIGH
EPSS
0.1%
2023 1 PoC

An improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

CVE-2023-28528
AIX General
8.4
HIGH
EPSS
1.6%
2023 CWE-78 2 PoCs

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 251207.

CVE-2023-29360
🔥 KEV Windows 10 Version 1809 Windows
8.4
HIGH
EPSS
30.3%
2023 CWE-822 3 PoCs

Microsoft Streaming Service Elevation of Privilege Vulnerability

CVE-2023-1355
vim/vim General
8.4
HIGH
EPSS
0.0%
2023 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1402.

CVE-2023-40286
Software Genérico Web
8.3
HIGH
EPSS
0.7%
2023 1 PoC

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

CVE-2023-28597
Zoom (for Android, iOS, Linux, macOS, and Windows) Windows
8.3
HIGH
EPSS
0.6%
2023 CWE-501 1 PoC

Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond to client requests, causing the client to execute attacker controlled executables. This could result in an attacker gaining access to a user's device and data, and remote code execution.

CVE-2023-4432
cockpit-hq/cockpit Web
8.3
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

CVE-2023-6185
LibreOffice General
8.3
HIGH
EPSS
1.4%
2023 1 PoC

Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker to run arbitrary gstreamer plugins depending on what plugins are installed on the target system.

CVE-2023-4433
cockpit-hq/cockpit Web
8.3
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

CVE-2023-6186
LibreOffice General
8.3
HIGH
EPSS
1.0%
2023 1 PoC

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.

CVE-2023-45234
edk2 General
8.3
HIGH
EPSS
0.3%
2023 CWE-119 1 PoC

EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.

CVE-2023-4321
cockpit-hq/cockpit Web
8.3
HIGH
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.4.3.

CVE-2023-45230
edk2 General
8.3
HIGH
EPSS
0.3%
2023 CWE-119 1 PoC

EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability.

CVE-2023-1892
sidekiq/sidekiq Web ⚡ nuclei
8.3
HIGH
EPSS
72.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.

CVE-2023-28601
Zoom for Windows Client Windows
8.3
HIGH
EPSS
0.3%
2023 CWE-358 1 PoC

Zoom for Windows clients prior to 5.14.0 contain an improper restriction of operations within the bounds of a memory buffer vulnerability. A malicious user may alter protected Zoom Client memory buffer potentially causing integrity issues within the Zoom Client.