7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-21472
Samsung Mobile Devices General
6.8
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader.

CVE-2023-0804
libtiff General
6.8
MEDIUM
EPSS
0.0%
2023 1 PoC

LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3609, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.

CVE-2023-30962
com.palantir.acme.cerberus:cerberus Web
6.8
MEDIUM
EPSS
0.6%
2023 CWE-434 1 PoC

The Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Gotham to launch attacks against other users. This vulnerability is resolved in Cerberus 100.230704.0-27-g031dd58 .

CVE-2023-0795
libtiff General
6.8
MEDIUM
EPSS
0.0%
2023 1 PoC

LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3488, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit afaabc3e.

CVE-2023-50124
Software Genérico General
6.8
MEDIUM
EPSS
0.1%
2023 1 PoC

Flient Smart Door Lock v1.0 is vulnerable to Use of Default Credentials. Due to default credentials on a debug interface, in combination with certain design choices, an attacker can unlock the Flient Smart Door Lock by replacing the fingerprint that is stored on the scanner.

CVE-2023-21922
Health Sciences InForm Web Database
6.8
MEDIUM
EPSS
0.7%
2023 1 PoC

Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Health Sciences InForm accessible

CVE-2023-29085
Software Genérico General
6.8
MEDIUM
EPSS
0.9%
2023 2 PoCs

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficient parameter validation while decoding an SIP status line.

CVE-2023-0378
Greenshift Web Windows
6.8
MEDIUM
EPSS
0.5%
2023 1 PoC

The Greenshift WordPress plugin before 5.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2023-22880
Zoom for Windows Windows
6.8
MEDIUM
EPSS
0.5%
2023 CWE-200 1 PoC

Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 contain an information disclosure vulnerability. A recent update to the Microsoft Edge WebView2 runtime used by the affected Zoom clients, transmitted text to Microsoft’s online Spellcheck service instead of the local Windows Spellcheck. Updating Zoom remediates this vulnerability by disabling the feature. Updating Microsoft Edge WebView2 Runtime to at least version 109.0.1481.0 and restarting Zoom remediates this vulnerability by updating Microsof

CVE-2023-2426
vim/vim General
6.8
MEDIUM
EPSS
0.0%
2023 CWE-823 1 PoC

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499.

CVE-2023-30712
Samsung Mobile Devices General
6.8
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper input validation in Settings Suggestions prior to SMR Sep-2023 Release 1 allows attackers to launch arbitrary activity.

CVE-2023-0796
libtiff General
6.8
MEDIUM
EPSS
0.0%
2023 1 PoC

LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3592, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit afaabc3e.

CVE-2023-35719
ADSelfService Plus Web
6.8
MEDIUM
EPSS
0.1%
2023 CWE-345 1 PoC

ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of ManageEngine ADSelfService Plus. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Password Reset Portal used by the GINA client. The issue results from the lack of proper authentication of data received via HTTP. An attacker can leverage this vulnerability to bypass authentication and execute code in the contex

CVE-2023-0797
libtiff General
6.8
MEDIUM
EPSS
0.0%
2023 1 PoC

LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tools/tiffcrop.c:6921, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit afaabc3e.

CVE-2023-30705
Galaxy Store General
6.8
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.56.6?allows local attackers to access privileged content providers as Galaxy Store permission.

CVE-2023-29091
Software Genérico General
6.8
MEDIUM
EPSS
0.6%
2023 2 PoCs

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exynos Auto T5123. Memory corruption can occur due to insufficient parameter validation while decoding an SIP URI.

CVE-2023-51820
Software Genérico General
6.8
MEDIUM
EPSS
0.2%
2023 2 PoCs

An issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate attackers to execute arbitrary code.

CVE-2023-3394
fossbilling/fossbilling General
6.8
MEDIUM
EPSS
0.1%
2023 CWE-384 1 PoC

Session Fixation in GitHub repository fossbilling/fossbilling prior to 0.5.1.

CVE-2023-3589
Teamwork Cloud - Business Edition Web Cloud
6.8
MEDIUM
EPSS
0.2%
2023 CWE-352 1 PoC

A Cross-Site Request Forgery (CSRF) vulnerability affecting Teamwork Cloud from No Magic Release 2021x through No Magic Release 2022x could allow with some very specific conditions an attacker to send a specifically crafted query to the server.

CVE-2023-46446
Software Genérico Networking
6.8
MEDIUM
EPSS
0.4%
2023 1 PoC

An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulation, aka a "Rogue Session Attack."