7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-37988
Contact Form Generator Web ⚡ nuclei
7.1
HIGH
EPSS
21.8%
2023 CWE-79 2 PoCs

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Creative Solutions Contact Form Generator plugin <= 2.5.5 versions.

CVE-2023-41112
Software Genérico General
7.1
HIGH
EPSS
0.2%
2023 1 PoC

An issue was discovered in Samsung Mobile Processor, Wearable Processor, Automotive Processor, and Modem (Exynos 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, W920, Modem 5123, Modem 5300, and Auto T5123). A buffer copy, without checking the size of the input, can cause abnormal termination of a mobile phone. This occurs in the RLC task and RLC module.

CVE-2023-45896
Software Genérico Cloud
7.1
HIGH
EPSS
0.1%
2023 1 PoC

ntfs3 in the Linux kernel through 6.8.0 allows a physically proximate attacker to read kernel memory by mounting a filesystem (e.g., if a Linux distribution is configured to allow unprivileged mounts of removable media) and then leveraging local access to trigger an out-of-bounds read. A length value can be larger than the amount of memory allocated. NOTE: the supplier's perspective is that there is no vulnerability when an attack requires an attacker-modified filesystem image.

CVE-2023-0191
vGPU software (guest driver - Windows), vGPU software (guest driver - Linux), vGPU software (Virtual GPU Manager - Citrix Hypervisor, VMware vSphere, Red Hat Enterprise Linux KVM), NVIDIA Cloud Gaming (guest driver - Windows), NVIDIA Cloud Gaming (guest driver - Linux), NVIDIA Cloud Gaming (Virtual GPU Manager - Red Hat Enterprise Linux KVM) Networking Cloud Windows
7.1
HIGH
EPSS
0.1%
2023 CWE-119 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds access may lead to denial of service or data tampering.

CVE-2023-53930
projectSend Web
7.1
HIGH
EPSS
0.1%
2023 CWE-639 1 PoC

ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manipulating the download ID parameter. Attackers can access any user's private files by changing the 'id' parameter in the download request to process.php.

CVE-2023-0519
modoboa/modoboa Web
7.1
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository modoboa/modoboa prior to 2.0.4.

CVE-2023-7174
aBitGone CommentSafe Web Windows
7.1
HIGH
EPSS
0.1%
2023 1 PoC

The aBitGone CommentSafe WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2023-41704
OX App Suite General
7.1
HIGH
EPSS
0.5%
2023 CWE-79 1 PoC

Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could be injected to a users sessions when interacting with E-Mails. Please deploy the provided updates and patch releases. CID handing has been improved and resulting content is checked for malicious content. No publicly available exploits are known.

CVE-2023-2859
nilsteampassnet/teampass General
7.1
HIGH
EPSS
5.8%
2023 CWE-94 2 PoCs

Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

CVE-2023-0183
vGPU software (guest driver - Linux), vGPU software (Virtual GPU Manager - Citrix Hypervisor, VMware vSphere, Red Hat Enterprise Linux KVM), NVIDIA Cloud Gaming (guest driver - Linux), NVIDIA Cloud Gaming (Virtual GPU Manager - Red Hat Enterprise Linux KVM) Networking Cloud
7.1
HIGH
EPSS
0.1%
2023 CWE-787 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an out-of-bounds write can lead to denial of service and data tampering.

CVE-2023-0793
thorsten/phpmyfaq Web
7.1
HIGH
EPSS
0.2%
2023 CWE-521 1 PoC

Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

CVE-2023-27264
Mattermost Web
7.1
HIGH
EPSS
0.1%
2023 CWE-862 1 PoC

A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks/[playbookID] API.

CVE-2023-29745
Software Genérico General
7.1
HIGH
EPSS
0.1%
2023 1 PoC

An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database.

CVE-2023-39215
Zoom Clients General
7.1
HIGH
EPSS
0.3%
2023 CWE-449 1 PoC

Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-3749
VideoEdge General
7.1
HIGH
EPSS
0.0%
2023 CWE-349 1 PoC

A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.

CVE-2023-53907
Backup Plugin General
7.1
HIGH
EPSS
0.4%
2023 CWE-22 1 PoC

Bludit versions before 3.13.1 contain an authenticated file download vulnerability in the Backup Plugin that allows logged-in users to access arbitrary files. Attackers can exploit the plugin's download functionality by manipulating file path parameters to read sensitive system files through directory traversal.

CVE-2023-2591
nilsteampassnet/teampass Web
7.1
HIGH
EPSS
0.3%
2023 CWE-79 2 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitHub repository nilsteampassnet/teampass prior to 3.0.7.

CVE-2023-0108
usememos/memos Web
7.1
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

CVE-2023-3141
Kernel General
7.1
HIGH
EPSS
0.0%
2023 CWE-416 1 PoC

A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak.