5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-20937
Android General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

In several functions of the Android Linux kernel, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-257443051References: Upstream kernel

CVE-2023-29738
Software Genérico General
7.8
HIGH
EPSS
0.2%
2023 2 PoCs

An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause code execution and escalation of Privileges via the database files.

CVE-2023-30533
Software Genérico General
7.8
HIGH
EPSS
7.7%
2023 1 PoC

SheetJS Community Edition before 0.19.3 allows Prototype Pollution via a crafted file. In other words. 0.19.2 and earlier are affected, whereas 0.19.3 and later are unaffected.

CVE-2023-31436
Software Genérico General
7.8
HIGH
EPSS
0.0%
2023 4 PoCs

qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can exceed QFQ_MIN_LMAX.

CVE-2023-41064
🔥 KEV macOS General
7.8
HIGH
EPSS
85.4%
2023 6 PoCs

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macOS Ventura 13.5.2, iOS 15.7.9 and iPadOS 15.7.9, macOS Big Sur 11.7.10. Processing a maliciously crafted image may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVE-2023-28596
Zoom Client for Meetings for IT Admin macOS installers General
7.8
HIGH
EPSS
0.2%
2023 CWE-427 1 PoC

Zoom Client for IT Admin macOS installers before version 5.13.5 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain during the installation process to escalate their privileges to privileges to root.

CVE-2023-4734
vim/vim General
7.8
HIGH
EPSS
0.0%
2023 CWE-190 1 PoC

Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.

CVE-2023-21086
Android General
7.8
HIGH
EPSS
0.0%
2023 1 PoC

In isToggleable of SecureNfcEnabler.java and SecureNfcPreferenceController.java, there is a possible way to enable NFC from a secondary account due to a permissions bypass. This could lead to local escalation of privilege from the Guest account with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-238298970

CVE-2023-43787
Software Genérico General
7.8
HIGH
EPSS
0.0%
2023 CWE-122 1 PoC

A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges.

CVE-2023-31019
NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver Cloud Windows
7.8
HIGH
EPSS
0.0%
2023 CWE-284 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation does not restrict or incorrectly restricts access from the named pipe server to a connecting client, which may lead to potential impersonation to the client's secure context.

CVE-2023-45805
pdm General
7.8
HIGH
EPSS
0.1%
2023 CWE-20 1 PoC

pdm is a Python package and dependency manager supporting the latest PEP standards. It's possible to craft a malicious `pdm.lock` file that could allow e.g. an insider or a malicious open source project to appear to depend on a trusted PyPI project, but actually install another project. A project `foo` can be targeted by creating the project `foo-2` and uploading the file `foo-2-2.tar.gz` to pypi.org. PyPI will see this as project `foo-2` version `2`, while PDM will see this as project `foo` version `2-2`. The version must only be `parseable as a version` and the filename must be a prefix of t

CVE-2023-20871
VMware Fusion General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate privileges to gain root access to the host operating system.

CVE-2023-35633
Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
2.7%
2023 CWE-59 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-43591
Zoom Rooms for macOS General
7.8
HIGH
EPSS
0.1%
2023 CWE-280 1 PoC

Improper privilege management in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access.

CVE-2023-30679
Samsung Mobile Devices General
7.8
HIGH
EPSS
0.0%
2023 1 PoC

Improper access control in HDCP trustlet prior to SMR Aug-2023 Release 1 allows local attackers to execute arbitrary code.

CVE-2023-21987
VM VirtualBox Database
7.8
HIGH
EPSS
9.7%
2023 2 PoCs

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, In

CVE-2023-4752
vim/vim General
7.8
HIGH
EPSS
0.1%
2023 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.1858.