7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-20043
Cisco CX Cloud Agent Networking Cloud
6.7
MEDIUM
EPSS
0.1%
2023 CWE-708 1 PoC

A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. This vulnerability is due to insecure file permissions. An attacker could exploit this vulnerability by calling the script with sudo. A successful exploit could allow the attacker to take complete control of the affected device.

CVE-2023-32494
PowerScale OneFS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-274 1 PoC

Dell PowerScale OneFS, 8.0.x-9.5.x, contains an improper handling of insufficient privileges vulnerability. A local privileged attacker could potentially exploit this vulnerability, leading to elevation of privilege and affect in compliance mode also.

CVE-2023-32490
PowerScale OneFS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-269 1 PoC

Dell PowerScale OneFS 8.2x -9.5x contains an improper privilege management vulnerability. A high privilege local attacker could potentially exploit this vulnerability, leading to system takeover.

CVE-2023-21508
Samsung Blockchain Keystore General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-787 1 PoC

Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code.

CVE-2023-24518
Pandora FMS Web
6.7
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

A Cross-site Request Forgery (CSRF) vulnerability in Pandora FMS allows an attacker to force authenticated users to send a request to a web application they are currently authenticated against. This issue affects Pandora FMS version 767 and earlier versions on all platforms.

CVE-2023-20815
MT6580, MT6739, MT6761, MT6765, MT6768, MT6779, MT6781, MT6833, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6891, MT6893, MT6895, MT6983, MT6985 General
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453587; Issue ID: ALPS07453587.

CVE-2023-1578
pimcore/pimcore Database
6.7
MEDIUM
EPSS
3.6%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19.

CVE-2023-30687
Samsung Mobile Devices General
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

Out-of-bounds Write in RmtUimApdu of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

CVE-2023-49114
VMS Client Viewer General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-427 2 PoCs

A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL, if some specific pre-conditions are met.

CVE-2023-30669
Samsung Mobile Devices General
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

Out-of-bounds Write in DoOemFactorySendFactoryTestResult of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.

CVE-2023-45078
BIOS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-125 1 PoC

A memory leakage vulnerability was reported in the DustFilterAlertSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

CVE-2023-23693
Dell VxRail HCI General
6.7
MEDIUM
EPSS
0.1%
2023 CWE-78 1 PoC

Dell VxRail, versions prior to 7.0.450, contains an OS command injection Vulnerability in DCManager command-line utility. A local high privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker.

CVE-2023-30653
Samsung Mobile Devices General
6.7
MEDIUM
EPSS
0.1%
2023 1 PoC

Out of bounds read and write in enableTspDevice of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.

CVE-2023-30440
PowerVM Hypervisor General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-20 1 PoC

IBM PowerVM Hypervisor FW860.00 through FW860.B3, FW950.00 through FW950.70, FW1010.00 through FW1010.50, FW1020.00 through FW1020.30, and FW1030.00 through FW1030.10 could allow a local attacker with control a partition that has been assigned SRIOV virtual function (VF) to cause a denial of service to a peer partition or arbitrary data corruption. IBM X-Force ID: 253175.

CVE-2023-5847
Nessus Windows
6.7
MEDIUM
EPSS
0.1%
2023 CWE-269 1 PoC

Under certain conditions, a low privileged attacker could load a specially crafted file during installation or upgrade to escalate privileges on Windows and Linux hosts.

CVE-2023-24932
Windows Server 2025 (Server Core installation) Windows
6.7
MEDIUM
EPSS
0.6%
2023 1 PoC

Secure Boot Security Feature Bypass Vulnerability

CVE-2023-43571
Desktop BIOS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-120 1 PoC

A buffer overflow was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

CVE-2023-53874
GOM Player General
6.7
MEDIUM
EPSS
0.1%
2023 CWE-120 1 PoC

GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field that allows attackers to crash the application. Attackers can overwrite the preset name with 260 'A' characters to trigger a buffer overflow and cause application instability.

CVE-2023-30702
Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 Networking Windows
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

Stack overflow vulnerability in SSHDCPAPP TA prior to "SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023" in Windows Update for Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 allows local attacker to execute arbitrary code.

CVE-2023-43577
Desktop BIOS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-120 1 PoC

A buffer overflow was reported in the ReFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.