7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-37988
Contact Form Generator Web ⚡ nuclei
7.1
HIGH
EPSS
21.8%
2023 CWE-79 2 PoCs

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Creative Solutions Contact Form Generator plugin <= 2.5.5 versions.

CVE-2023-2591
nilsteampassnet/teampass Web
7.1
HIGH
EPSS
0.3%
2023 CWE-79 2 PoCs

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitHub repository nilsteampassnet/teampass prior to 3.0.7.

CVE-2023-20900
VMware Tools Web
7.1
HIGH
EPSS
0.8%
2023 2 PoCs

A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .

CVE-2023-3268
Kernel General
7.1
HIGH
EPSS
0.0%
2023 CWE-125 1 PoC

An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs. This flaw could allow a local attacker to crash the system or leak kernel internal information.

CVE-2023-4259
Zephyr General
7.1
HIGH
EPSS
0.2%
2023 CWE-120 1 PoC

Two potential buffer overflow vulnerabilities at the following locations in the Zephyr eS-WiFi driver source code.

CVE-2023-3141
Kernel General
7.1
HIGH
EPSS
0.0%
2023 CWE-416 1 PoC

A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak.

CVE-2023-22710
Return and Warranty Management System for WooCommerce Web
7.1
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in chilidevs Return and Warranty Management System for WooCommerce plugin <= 1.2.3 versions.

CVE-2023-26436
OX App Suite Web
7.1
HIGH
EPSS
0.2%
2023 CWE-94 1 PoC

Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not properly checked during deserialization. Access to this API endpoint is restricted to local networks by default. Arbitrary code could be injected that is being executed when processing the request. A check has been introduced to restrict processing of legal and expected classes for this API. We now log a warning in case there are attempts to inject illegal classes. No publicly available exploits are known.

CVE-2023-4814
Data Loss Prevention Endpoint for Windows General
7.1
HIGH
EPSS
0.0%
2023 CWE-250 1 PoC

A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for which the user does not have permission to.

CVE-2023-53901
WBCE CMS Web
7.1
HIGH
EPSS
0.1%
2023 CWE-601 1 PoC

WBCE CMS 1.6.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML and CSS to capture user keystrokes. Attackers can upload a crafted HTML file with CSS-based keylogging techniques to intercept password characters through background image requests.

CVE-2023-2239
microweber/microweber General
7.1
HIGH
EPSS
0.3%
2023 CWE-359 1 PoC

Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository microweber/microweber prior to 1.3.4.

CVE-2023-7114
Mattermost Web
7.1
HIGH
EPSS
0.3%
2023 CWE-74 1 PoC

Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.

CVE-2023-42492
v3.0.6433.1964 General
7.1
HIGH
EPSS
0.1%
2023 CWE-321 1 PoC

EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key

CVE-2023-35918
Bulk Stock Management Web
7.1
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Bulk Stock Management plugin <= 2.2.33 versions.

CVE-2023-4561
omeka/omeka-s Web
7.1
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.4.

CVE-2023-30489
Email Subscription Popup Web
7.1
HIGH
EPSS
0.5%
2023 CWE-79 1 PoC

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Email Subscription Popup plugin <= 1.2.16 versions.

CVE-2023-21752
Windows 10 Version 22H2 Windows
7.1
HIGH
EPSS
33.0%
2023 CWE-284 2 PoCs

Windows Backup Service Elevation of Privilege Vulnerability

CVE-2023-42561
Samsung Mobile Devices General
7.1
HIGH
EPSS
0.2%
2023 1 PoC

Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physical attacker to execute arbitrary code.

CVE-2023-32327
Security Verify Access Appliance DevOps
7.1
HIGH
EPSS
0.0%
2023 CWE-611 1 PoC

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 254783.

CVE-2023-40208
Stock Ticker Web ⚡ nuclei
7.1
HIGH
EPSS
3.2%
2023 CWE-79 0 PoCs

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Aleksandar Urošević Stock Ticker plugin <= 3.23.3 versions.