5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-42137
POS terminals General
7.8
HIGH
EPSS
0.4%
2023 CWE-59 1 PoC

PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privileges by using malicious symlinks. The attacker must have shell access to the device in order to exploit this vulnerability.

CVE-2023-42091
PDF Reader General
7.8
HIGH
EPSS
1.9%
2023 CWE-416 1 PoC

Foxit PDF Reader XFA Doc Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the curre

CVE-2023-20871
VMware Fusion General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate privileges to gain root access to the host operating system.

CVE-2023-30679
Samsung Mobile Devices General
7.8
HIGH
EPSS
0.0%
2023 1 PoC

Improper access control in HDCP trustlet prior to SMR Aug-2023 Release 1 allows local attackers to execute arbitrary code.

CVE-2023-5643
Bifrost GPU Kernel Driver General
7.8
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

Out-of-bounds Write vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations. Depending on the configuration of the Mali GPU Kernel Driver, and if the system’s memory is carefully prepared by the user, then this in turn could write to memory outside of buffer bounds.This issue affects Bifrost GPU Kernel Driver: from r41p0 through r45p0; Valhall GPU Kernel Driver: from r41p0 through r45p0; Arm 5th Gen GPU Architecture Kernel Driver

CVE-2023-0463
Remote Desktop Manager General
7.8
HIGH
EPSS
0.0%
2023 1 PoC

The force offline MFA prompt setting is not respected when switching to offline mode in Devolutions Remote Desktop Manager 2022.3.29 to 2022.3.30 allows a user to save sensitive data on disk.

CVE-2023-21537
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.4%
2023 CWE-367 1 PoC

Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability

CVE-2023-25438
Software Genérico General
7.8
HIGH
EPSS
1.4%
2023 1 PoC

An issue was discovered in Genomedics MilleGP5 5.9.2, allows remote attackers to execute arbitrary code and gain escalated privileges via modifying specific files.

CVE-2023-40283
Software Genérico General
7.8
HIGH
EPSS
0.0%
2023 2 PoCs

An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled.

CVE-2023-27193
Software Genérico General
7.8
HIGH
EPSS
0.2%
2023 1 PoC

An issue found in DUALSPACE v.1.1.3 allows a local attacker to gain privileges via the key_ad_new_user_avoid_time field.

CVE-2023-0860
modoboa/modoboa-installer General
7.8
HIGH
EPSS
0.5%
2023 CWE-307 2 PoCs

Improper Restriction of Excessive Authentication Attempts in GitHub repository modoboa/modoboa-installer prior to 2.0.4.

CVE-2023-3313
Enterprise Security Manager Web
7.8
HIGH
EPSS
0.2%
2023 CWE-78 1 PoC

An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed an unauthorized user to execute system command injection for the purpose of privilege escalation or to execute arbitrary commands.

CVE-2023-5591
librenms/librenms Database
7.8
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository librenms/librenms prior to 23.10.0.

CVE-2023-3389
Kernel Networking
7.8
HIGH
EPSS
0.0%
2023 CWE-416 1 PoC

A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Racing a io_uring cancel poll request with a linked timeout can cause a UAF in a hrtimer. We recommend upgrading past commit ef7dfac51d8ed961b742218f526bd589f3900a59 (4716c73b188566865bdd79c3a6709696a224ac04 for 5.10 stable and 0e388fce7aec40992eadee654193cad345d62663 for 5.15 stable).

CVE-2023-32434
🔥 KEV macOS General
7.8
HIGH
EPSS
52.8%
2023 1 PoC

An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.

CVE-2023-32046
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
42.7%
2023 1 PoC

Windows MSHTML Platform Elevation of Privilege Vulnerability

CVE-2023-38117
PDF Reader General
7.8
HIGH
EPSS
1.8%
2023 CWE-416 1 PoC

Foxit PDF Reader AcroForm Doc Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the

CVE-2023-27400
Tecnomatix Plant Simulation General
7.8
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-20300)

CVE-2023-30649
Samsung Mobile Devices General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

Heap out of bound write vulnerability in RmtUimNeedApdu of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.