5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-26269
Apache James server Web
7.8
HIGH
EPSS
1.2%
2023 CWE-862 1 PoC

Apache James server version 3.7.3 and earlier provides a JMX management service without authentication by default. This allows privilege escalation by a malicious local user. Administrators are advised to disable JMX, or set up a JMX password. Note that version 3.7.4 onward will set up a JMX password automatically for Guice users.

CVE-2023-39374
NAC SecureConnector General
7.8
HIGH
EPSS
0.1%
2023 CWE-427 1 PoC

ForeScout NAC SecureConnector version 11.2 - CWE-427: Uncontrolled Search Path Element

CVE-2023-37420
GTKWave General
7.8
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the vcd2lxt conversion utility.

CVE-2023-38112
PDF Reader General
7.8
HIGH
EPSS
1.8%
2023 CWE-416 1 PoC

Foxit PDF Reader XFA Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of th

CVE-2023-23421
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
1.0%
2023 CWE-416 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-30646
Samsung Mobile Devices General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

Heap out of bound write vulnerability in BroadcastSmsConfig of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.

CVE-2023-41992
🔥 KEV macOS General
7.8
HIGH
EPSS
1.1%
2023 1 PoC

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CVE-2023-32837
MT6883, MT6885, MT6889, MT6893, MT8797, MT8798 General
7.8
HIGH
EPSS
0.0%
2023 1 PoC

In video, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08235273; Issue ID: ALPS08250357.

CVE-2023-4736
vim/vim General
7.8
HIGH
EPSS
0.0%
2023 CWE-426 1 PoC

Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.

CVE-2023-21774
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
2.0%
2023 CWE-416 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-4738
vim/vim General
7.8
HIGH
EPSS
0.0%
2023 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.

CVE-2023-23399
Microsoft Office 2019 General
7.8
HIGH
EPSS
7.3%
2023 CWE-125 1 PoC

Microsoft Excel Remote Code Execution Vulnerability

CVE-2023-42092
PDF Reader General
7.8
HIGH
EPSS
1.9%
2023 CWE-416 1 PoC

Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current p

CVE-2023-27330
PDF Reader General
7.8
HIGH
EPSS
3.5%
2023 CWE-416 1 PoC

Foxit PDF Reader XFA Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of th

CVE-2023-0386
🔥 KEV Kernel General
7.8
HIGH
EPSS
54.3%
2023 CWE-282 18 PoCs

A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.

CVE-2023-28596
Zoom Client for Meetings for IT Admin macOS installers General
7.8
HIGH
EPSS
0.2%
2023 CWE-427 1 PoC

Zoom Client for IT Admin macOS installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain during the installation process to escalate their privileges to privileges to root.

CVE-2023-35633
Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
2.7%
2023 CWE-59 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-3812
Red Hat Enterprise Linux 8 Web
7.8
HIGH
EPSS
0.0%
2023 CWE-787 1 PoC

An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVE-2023-30533
Software Genérico General
7.8
HIGH
EPSS
7.7%
2023 1 PoC

SheetJS Community Edition before 0.19.3 allows Prototype Pollution via a crafted file. In other words. 0.19.2 and earlier are affected, whereas 0.19.3 and later are unaffected.

CVE-2023-24985
Tecnomatix Plant Simulation General
7.8
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19807)