5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-52169
Software Genérico General
8.2
HIGH
EPSS
0.2%
2023 1 PoC

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.

CVE-2023-0740
answerdev/answer Web
8.2
HIGH
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.

CVE-2023-6549
🔥 KEV NetScaler ADC General ⚡ nuclei
8.2
HIGH
EPSS
76.5%
2023 CWE-119 0 PoCs

Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read

CVE-2023-34116
Zoom Desktop Client for Windows Windows
8.2
HIGH
EPSS
0.4%
2023 CWE-78 1 PoC

Improper input validation in the Zoom Desktop Client for Windows before version 5.15.0 may allow an unauthorized user to enable an escalation of privilege via network access.

CVE-2023-41806
Pandora FMS General
8.2
HIGH
EPSS
0.1%
2023 CWE-269 1 PoC

Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability causes that a bad privilege assignment could cause a DOS attack that affects the availability of the Pandora FMS server. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-30744
SAP AS NetWeaver JAVA Web
8.2
HIGH
EPSS
0.3%
2023 CWE-306 1 PoC

In SAP AS NetWeaver JAVA - versions SERVERCORE 7.50, J2EE-FRMW 7.50, CORE-TOOLS 7.50, an unauthenticated attacker can attach to an open interface and make use of an open naming and directory API to instantiate an object which has methods which can be called without further authorization and authentication.  A subsequent call to one of these methods can read or change the state of existing services without any effect on availability.

CVE-2023-2186
SCADA Data Gateway General
8.2
HIGH
EPSS
0.4%
2023 CWE-134 1 PoC

On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send a specially crafted broadcast message including format string characters to the SCADA Data Gateway to perform unrestricted memory reads.An unauthenticated user can use this format string vulnerability to repeatedly crash the GTWWebMonitor.exe process to DoS the Web Monitor. Furthermore, an authenticated user can leverage this vulnerability to leak memory from the GTWWebMonitor.exe process. This

CVE-2023-31027
NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver Cloud Windows
8.2
HIGH
EPSS
0.0%
2023 CWE-427 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability that allows Windows users with low levels of privilege to escalate privileges when an administrator is updating GPU drivers, which may lead to escalation of privileges.

CVE-2023-5760
Avast/Avg Antivirus General
8.2
HIGH
EPSS
0.1%
2023 CWE-367 1 PoC

A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be further exploited, allowing an attacker to gain full local privilege escalation on the system.This issue affects Avast/Avg Antivirus: 23.8.

CVE-2023-43017
Security Verify Access Appliance General
8.2
HIGH
EPSS
0.0%
2023 CWE-295 1 PoC

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. IBM X-Force ID: 266155.

CVE-2023-4898
mintplex-labs/anything-llm General
8.2
HIGH
EPSS
0.1%
2023 CWE-305 1 PoC

Authentication Bypass by Primary Weakness in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.

CVE-2023-32220
NCR/camera General
8.2
HIGH
EPSS
0.0%
2023 1 PoC

Milesight NCR/camera version 71.8.0.6-r5 allows authentication bypass through an unspecified method.

CVE-2023-26573
IDWeb General
8.2
HIGH
EPSS
0.2%
2023 CWE-306 1 PoC

Missing authentication in the SetDB method in IDAttend’s IDWeb application 3.1.052 and earlier allows denial of service or theft of database login credentials.

CVE-2023-33991
SAP UI5 Variant Management Web
8.2
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

SAP UI5 Variant Management - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, does not sufficiently encode user-controlled inputs on reading data from the server, resulting in Stored Cross-Site Scripting (Stored XSS) vulnerability. After successful exploitation, an attacker with user level access can cause high impact on confidentiality, modify some information and can cause unavailability of the application at user level.

CVE-2023-21990
VM VirtualBox Database
8.2
HIGH
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Int

CVE-2023-26114
code-server General
8.2
HIGH
EPSS
0.2%
2023 CWE-1385 1 PoC

Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.

CVE-2023-21501
Samsung Mobile Devices General
8.2
HIGH
EPSS
0.1%
2023 CWE-20 1 PoC

Improper input validation vulnerability in mPOS fiserve trustlet prior to SMR May-2023 Release 1 allows local attackers to execute arbitrary code.

CVE-2023-34119
Zoom Rooms for Windows Windows
8.2
HIGH
EPSS
0.1%
2023 CWE-426 1 PoC

Insecure temporary file in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.

CVE-2023-29051
OX App Suite Web
8.1
HIGH
EPSS
0.2%
2023 CWE-284 1 PoC

User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature by default was not effective in this case. Unauthorized users could discover and modify application state, including objects related to other users and contexts. We now make sure that the switch to disable user-generated templates by default works as intended and will remove the feature in future generations of the product. No publicly available exploits are known.

CVE-2023-3531
nilsteampassnet/teampass Web
8.1
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10.