7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-47684
Essential Grid Web ⚡ nuclei
7.1
HIGH
EPSS
2.1%
2023 CWE-79 0 PoCs

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ThemePunch OHG Essential Grid plugin <= 3.1.0 versions.

CVE-2023-0181
vGPU software (guest driver - Windows), vGPU software (guest driver - Linux), vGPU software (Virtual GPU Manager - Citrix Hypervisor, VMware vSphere, Red Hat Enterprise Linux KVM), NVIDIA Cloud Gaming (guest driver - Windows), NVIDIA Cloud Gaming (guest driver - Linux), NVIDIA Cloud Gaming (Virtual GPU Manager - Red Hat Enterprise Linux KVM) Networking Cloud Windows
7.1
HIGH
EPSS
0.0%
2023 CWE-280 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a kernel mode layer handler, where memory permissions are not correctly checked, which may lead to denial of service and data tampering.

CVE-2023-40208
Stock Ticker Web ⚡ nuclei
7.1
HIGH
EPSS
3.2%
2023 CWE-79 0 PoCs

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Aleksandar Urošević Stock Ticker plugin <= 3.23.3 versions.

CVE-2023-30777
Advanced Custom Fields Pro Web ⚡ nuclei
7.1
HIGH
EPSS
87.3%
2023 CWE-79 2 PoCs

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Engine Advanced Custom Fields Pro, WP Engine Advanced Custom Fields plugins <= 6.1.5 versions.

CVE-2023-6279
Woostify Sites Library Web Windows
7.1
HIGH
EPSS
0.1%
2023 1 PoC

The Woostify Sites Library WordPress plugin before 1.4.8 does not have authorisation in an AJAX action, allowing any authenticated users, such as subscriber to update arbitrary blog options and set them to 'activated' which could lead to DoS when using a specific option name

CVE-2023-41111
Software Genérico General
7.1
HIGH
EPSS
0.3%
2023 1 PoC

An issue was discovered in Samsung Mobile Processor, Wearable Processor, Automotive Processor, and Modem (Exynos 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, W920, Modem 5123, Modem 5300, and Auto T5123). Improper handling of a length parameter inconsistency can cause abnormal termination of a mobile phone. This occurs in the RLC task and RLC module.

CVE-2023-41704
OX App Suite General
7.1
HIGH
EPSS
0.5%
2023 CWE-79 1 PoC

Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could be injected to a users sessions when interacting with E-Mails. Please deploy the provided updates and patch releases. CID handing has been improved and resulting content is checked for malicious content. No publicly available exploits are known.

CVE-2023-47115
label-studio Web ⚡ nuclei
7.1
HIGH
EPSS
3.2%
2023 CWE-79 0 PoCs

Label Studio is an a popular open source data labeling tool. Versions prior to 1.9.2 have a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. Executing arbitrary JavaScript could result in an attacker performing malicious actions on Label Studio users if they visit the crafted avatar image. For an example, an attacker can craft a JavaScript payload that adds a new Django Super Administrator user if a Django administrator visits the image. The file `users/fu

CVE-2023-36535
Zoom Clients General
7.1
HIGH
EPSS
0.2%
2023 CWE-449 1 PoC

Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network access.

CVE-2023-42493
v3.0.6433.1964 General
7.1
HIGH
EPSS
0.1%
2023 CWE-256 1 PoC

EisBaer Scada - CWE-256: Plaintext Storage of a Password

CVE-2023-41112
Software Genérico General
7.1
HIGH
EPSS
0.2%
2023 1 PoC

An issue was discovered in Samsung Mobile Processor, Wearable Processor, Automotive Processor, and Modem (Exynos 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, W920, Modem 5123, Modem 5300, and Auto T5123). A buffer copy, without checking the size of the input, can cause abnormal termination of a mobile phone. This occurs in the RLC task and RLC module.

CVE-2023-21489
Samsung Mobile Devices General
7.1
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

Heap out-of-bounds write vulnerability in bootloader prior to SMR May-2023 Release 1 allows a physical attacker to execute arbitrary code.

CVE-2023-53930
projectSend Web
7.1
HIGH
EPSS
0.1%
2023 CWE-639 1 PoC

ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manipulating the download ID parameter. Attackers can access any user's private files by changing the 'id' parameter in the download request to process.php.

CVE-2023-27647
Software Genérico General
7.1
HIGH
EPSS
0.1%
2023 1 PoC

An issue found in DUALSPACE Lock Master v.2.2.4 allows a local attacker to cause a denial of service or gain sensitive information via the com.ludashi.superlock.util.pref.SharedPrefProviderEntryMethod: insert of the android.net.Uri.insert method.

CVE-2023-26607
Software Genérico General
7.1
HIGH
EPSS
0.1%
2023 1 PoC

In the Linux kernel 6.0.8, there is an out-of-bounds read in ntfs_attr_find in fs/ntfs/attrib.c.

CVE-2023-6458
Mattermost General
7.1
HIGH
EPSS
0.5%
2023 CWE-74 1 PoC

Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traversal.

CVE-2023-0183
vGPU software (guest driver - Linux), vGPU software (Virtual GPU Manager - Citrix Hypervisor, VMware vSphere, Red Hat Enterprise Linux KVM), NVIDIA Cloud Gaming (guest driver - Linux), NVIDIA Cloud Gaming (Virtual GPU Manager - Red Hat Enterprise Linux KVM) Networking Cloud
7.1
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an out-of-bounds write can lead to denial of service and data tampering.

CVE-2023-21750
Windows 10 Version 1809 Windows
7.1
HIGH
EPSS
2.7%
2023 CWE-284 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-47514
Star CloudPRNT for WooCommerce Web Cloud
7.1
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in lawrenceowen, gcubero, acunnningham, fmahmood Star CloudPRNT for WooCommerce plugin <= 2.0.3 versions.

CVE-2023-45896
Software Genérico Cloud
7.1
HIGH
EPSS
0.1%
2023 1 PoC

ntfs3 in the Linux kernel through 6.8.0 allows a physically proximate attacker to read kernel memory by mounting a filesystem (e.g., if a Linux distribution is configured to allow unprivileged mounts of removable media) and then leveraging local access to trigger an out-of-bounds read. A length value can be larger than the amount of memory allocated. NOTE: the supplier's perspective is that there is no vulnerability when an attack requires an attacker-modified filesystem image.