2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-47564
Qsync Central General
8.0
HIGH
EPSS
8.0%
2023 CWE-732 1 PoC

An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.15 ( 2024/01/04 ) and later Qsync Central 4.3.0.11 ( 2024/01/11 ) and later

CVE-2023-36745
Microsoft Exchange Server 2019 Cumulative Update 13 Windows
8.0
HIGH
EPSS
73.6%
2023 CWE-502 1 PoC

Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2023-51148
Software Genérico General
8.0
HIGH
EPSS
0.1%
2023 1 PoC

An issue in TRENDnet Trendnet AC1200 Dual Band PoE Indoor Wireless Access Point TEW-821DAP v.3.00b06 allows an attacker to execute arbitrary code via the 'mycli' command-line interface component.

CVE-2023-0742
answerdev/answer Web
8.0
HIGH
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.

CVE-2023-28905
Volkswagen MIB3 infotainment system MIB3 OI MQB General
8.0
HIGH
EPSS
0.3%
2023 CWE-122 2 PoCs

A heap buffer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker to execute arbitrary code on it. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources.

CVE-2023-49528
Software Genérico Networking
8.0
HIGH
EPSS
0.0%
2023 1 PoC

Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.

CVE-2023-24334
Software Genérico General
8.0
HIGH
EPSS
0.1%
2023 1 PoC

A stack overflow vulnerability in Tenda AC23 with firmware version US_AC23V1.0re_V16.03.07.45_cn_TDC01 allows attackers to run arbitrary commands via schedStartTime parameter.

CVE-2023-51795
Software Genérico General
8.0
HIGH
EPSS
0.1%
2023 2 PoCs

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showspectrum.c:1789:52 component in showspectrumpic_request_frame

CVE-2023-28909
Volkswagen MIB3 infotainment system MIB3 OI MQB General
8.0
HIGH
EPSS
0.2%
2023 CWE-190 2 PoCs

A specific flaw exists within the Bluetooth stack of the MIB3 unit. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow when receiving fragmented HCI packets on a channel. An attacker can leverage this vulnerability to bypass the MTU check on a channel with enabled fragmentation. Consequently, this can lead to a buffer overflow in upper layer profiles, which can be used to obtain remote code execution. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The lis

CVE-2023-22726
act General
8.0
HIGH
EPSS
1.5%
2023 CWE-434 1 PoC

act is a project which allows for local running of github actions. The artifact server that stores artifacts from Github Action runs does not sanitize path inputs. This allows an attacker to download and overwrite arbitrary files on the host from a Github Action. This issue may lead to privilege escalation. The /upload endpoint is vulnerable to path traversal as filepath is user controlled, and ultimately flows into os.Mkdir and os.Open. The /artifact endpoint is vulnerable to path traversal as the path is variable is user controlled, and the specified file is ultimately returned by the server

CVE-2023-51146
Software Genérico General
8.0
HIGH
EPSS
0.1%
2023 1 PoC

Buffer Overflow vulnerability in TRENDnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via the adm_add_user action.

CVE-2023-30860
AVideo General
8.0
HIGH
EPSS
3.6%
2023 CWE-79 1 PoC

WWBN AVideo is an open source video platform. In AVideo prior to version 12.4, a normal user can make a Meeting Schedule where the user can invite another user in that Meeting, but it does not properly sanitize the malicious characters when creating a Meeting Room. This allows attacker to insert malicious scripts. Since any USER including the ADMIN can see the meeting room that was created by the attacker this can lead to cookie hijacking and takeover of any accounts. Version 12.4 contains a patch for this issue.

CVE-2023-21475
Samsung Mobile Devices General
8.0
HIGH
EPSS
0.0%
2023 1 PoC

Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.

CVE-2023-36541
Zoom Desktop Client for Windows Windows
8.0
HIGH
EPSS
0.4%
2023 CWE-345 1 PoC

Insufficient verification of data authenticity in Zoom Desktop Client for Windows before 5.14.5 may allow an authenticated user to enable an escalation of privilege via network access.

CVE-2023-1094
MonicaHQ General
8.0
HIGH
EPSS
0.8%
2023 1 PoC

MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/food` endpoint and food parameter.

CVE-2023-28910
Volkswagen MIB3 infotainment system MIB3 OI MQB General
8.0
HIGH
EPSS
0.1%
2023 CWE-754 2 PoCs

A specific flaw exists within the Bluetooth stack of the MIB3 infotainment system. The issue results from the disabled abortion flag eventually leading to bypassing assertion functions. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources.

CVE-2023-51147
Software Genérico General
8.0
HIGH
EPSS
0.1%
2023 1 PoC

Buffer Overflow vulnerability in TRENDnet Trendnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via the adm_mod_pwd action.

CVE-2023-39212
Zoom Rooms for Windows Windows
7.9
HIGH
EPSS
0.0%
2023 CWE-144 1 PoC

Untrusted search path in Zoom Rooms for Windows before version 5.15.5 may allow an authenticated user to enable a denial of service via local access.

CVE-2023-30709
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.1%
2023 1 PoC

Improper access control in Dual Messenger prior to SMR Sep-2023 Release 1 allows local attackers launch activity with system privilege.

CVE-2023-21477
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.0%
2023 1 PoC

Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.