7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-24932
Windows Server 2025 (Server Core installation) Windows
6.7
MEDIUM
EPSS
0.6%
2023 1 PoC

Secure Boot Security Feature Bypass Vulnerability

CVE-2023-34570
Software Genérico General
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter devName at /goform/SetOnlineDevName.

CVE-2023-30702
Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 Networking Windows
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

Stack overflow vulnerability in SSHDCPAPP TA prior to "SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023" in Windows Update for Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 allows local attacker to execute arbitrary code.

CVE-2023-32490
PowerScale OneFS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-269 1 PoC

Dell PowerScale OneFS 8.2x -9.5x contains an improper privilege management vulnerability. A high privilege local attacker could potentially exploit this vulnerability, leading to system takeover.

CVE-2023-49114
VMS Client Viewer General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-427 2 PoCs

A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL, if some specific pre-conditions are met.

CVE-2023-42563
Samsung Mobile Devices General
6.7
MEDIUM
EPSS
0.2%
2023 1 PoC

Integer overflow vulnerability in landmarkCopyImageToNative of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attacker to trigger heap overflow.

CVE-2023-5078
ThinkPad BIOS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-1419 1 PoC

A vulnerability was reported in some ThinkPad BIOS that could allow a physical or local attacker with elevated privileges to tamper with BIOS firmware.

CVE-2023-41793
Pandora FMS General
6.7
MEDIUM
EPSS
0.1%
2023 CWE-35 1 PoC

: Path Traversal vulnerability in Pandora FMS on all allows Path Traversal. This vulnerability allowed changing directories and creating files and downloading them outside the allowed directories. This issue affects Pandora FMS: from 700 through <776.

CVE-2023-43576
Desktop BIOS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-120 1 PoC

A buffer overflow was reported in the WMISwSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

CVE-2023-30652
Samsung Mobile Devices General
6.7
MEDIUM
EPSS
0.1%
2023 1 PoC

Out of bounds read and write in callrunTspCmdNoRead of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.

CVE-2023-43578
Desktop BIOS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-120 1 PoC

A buffer overflow was reported in the SmiFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

CVE-2023-43577
Desktop BIOS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-120 1 PoC

A buffer overflow was reported in the ReFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

CVE-2023-20797
MT6879, MT6886, MT6895, MT6983, MT6985, MT8188, MT8195, MT8673 General
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

In camera middleware, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629582; Issue ID: ALPS07629582.

CVE-2023-43579
Desktop BIOS General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-120 1 PoC

A buffer overflow was reported in the SmuV11Dxe driver in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.

CVE-2023-21969
SQL Developer Database
6.7
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in Oracle SQL Developer (component: Installation). Supported versions that are affected are Prior to 23.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle SQL Developer executes to compromise Oracle SQL Developer. Successful attacks of this vulnerability can result in takeover of Oracle SQL Developer. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVE-2023-20630
MT6580, MT6735, MT6739, MT6761, MT6763, MT6765, MT6768, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6853, MT6855, MT6873, MT6885, MT6893, MT6895, MT6983, MT8167, MT8168, MT8666, MT8675 General
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

In usb, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628505; Issue ID: ALPS07628505.

CVE-2023-49794
KernelSU General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-290 1 PoC

KernelSU is a Kernel-based root solution for Android devices. In versions 0.7.1 and prior, the logic of get apk path in KernelSU kernel module can be bypassed, which causes any malicious apk named `me.weishu.kernelsu` get root permission. If a KernelSU module installed device try to install any not checked apk which package name equal to the official KernelSU Manager, it can take over root privileges on the device. As of time of publication, a patched version is not available.

CVE-2023-30669
Samsung Mobile Devices General
6.7
MEDIUM
EPSS
0.0%
2023 1 PoC

Out-of-bounds Write in DoOemFactorySendFactoryTestResult of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.

CVE-2023-4107
Mattermost General
6.7
MEDIUM
EPSS
0.0%
2023 CWE-863 1 PoC

Mattermost fails to properly validate the requesting user permissions when updating a system admin, allowing a user manager to update a system admin's details such as email, first name and last name.