2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-35358
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.2%
2023 CWE-125 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-20945
Android General
7.8
HIGH
EPSS
0.0%
2023 1 PoC

In phNciNfc_MfCreateXchgDataHdr of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-246932269

CVE-2023-29336
🔥 KEV Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
79.5%
2023 CWE-416 2 PoCs

Win32k Elevation of Privilege Vulnerability

CVE-2023-22809
Software Genérico General
7.8
HIGH
EPSS
48.0%
2023 21 PoCs

In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.

CVE-2023-24982
Tecnomatix Plant Simulation General
7.8
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19804)

CVE-2023-6179
ProWatch General
7.8
HIGH
EPSS
0.0%
2023 CWE-732 1 PoC

Honeywell ProWatch, 4.5, including all Service Pack versions, contain a Vulnerability in Application Server's executable folder(s). A(n) attacker could potentially exploit this vulnerability, leading to a standard user to have arbitrary system code execution. Honeywell recommends updating to the most recent version of this product, service or offering (Pro-watch 6.0.2, 6.0, 5.5.2,5.0.5).

CVE-2023-27651
Software Genérico General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges via the update_info field of the _default_.xml file.

CVE-2023-32495
PowerScale OneFS General
7.8
HIGH
EPSS
0.1%
2023 CWE-200 1 PoC

Dell PowerScale OneFS, 8.2.x-9.5.x, contains a exposure of sensitive information to an unauthorized Actor vulnerability. An authorized local attacker could potentially exploit this vulnerability, leading to escalation of privileges.

CVE-2023-33137
Microsoft Office 2019 General
7.8
HIGH
EPSS
2.7%
2023 CWE-415 1 PoC

Microsoft Excel Remote Code Execution Vulnerability

CVE-2023-31436
Software Genérico General
7.8
HIGH
EPSS
0.0%
2023 4 PoCs

qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can exceed QFQ_MIN_LMAX.

CVE-2023-36424
🔥 KEV Windows 11 version 22H3 Windows
7.8
HIGH
EPSS
8.0%
2023 CWE-125 2 PoCs

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2023-6817
Kernel Networking
7.8
HIGH
EPSS
0.0%
2023 CWE-416 3 PoCs

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The function nft_pipapo_walk did not skip inactive elements during set walk which could lead double deactivations of PIPAPO (Pile Packet Policies) elements, leading to use-after-free. We recommend upgrading past commit 317eb9685095678f2c9f5a8189de698c5354316a.

CVE-2023-31468
Software Genérico General
7.8
HIGH
EPSS
0.1%
2023 4 PoCs

An issue was discovered in Inosoft VisiWin 7 through 2022-2.1 (Runtime RT7.3 RC3 20221209.5). The "%PROGRAMFILES(X86)%\INOSOFT GmbH" folder has weak permissions for Everyone, allowing an attacker to insert a Trojan horse file that runs as SYSTEM. 2024-1 is a fixed version.

CVE-2023-21097
Android General
7.8
HIGH
EPSS
0.2%
2023 3 PoCs

In toUriInner of Intent.java, there is a possible way to launch an arbitrary activity due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-261858325

CVE-2023-24991
Tecnomatix Plant Simulation General
7.8
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19813)

CVE-2023-20928
Android General
7.8
HIGH
EPSS
0.1%
2023 1 PoC

In binder_vma_close of binder.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-254837884References: Upstream kernel

CVE-2023-27402
Tecnomatix Plant Simulation General
7.8
HIGH
EPSS
0.1%
2023 CWE-125 1 PoC

A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted SPP files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-20334)

CVE-2023-35788
Software Genérico General
7.8
HIGH
EPSS
0.0%
2023 2 PoCs

An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.

CVE-2023-23422
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
1.1%
2023 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-36250
Software Genérico General
7.8
HIGH
EPSS
3.6%
2023 2 PoCs

CSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via crafted .tsv file when creating a new record.