7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-3712
PM23/43 General
6.6
MEDIUM
EPSS
0.1%
2023 CWE-552 2 PoCs

Files or Directories Accessible to External Parties vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Privilege Escalation.This issue affects PM43 versions prior to P10.19.050004.  Update to the latest available firmware version of the respective printers to version MR19.5 (e.g. P10.19.050006).

CVE-2023-3441
GitLab DevOps
6.6
MEDIUM
EPSS
0.1%
2023 CWE-213 1 PoC

An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not sufficiently warn about security implications of granting merge rights to protected branches.

CVE-2023-31493
Software Genérico Web
6.6
MEDIUM
EPSS
2.5%
2023 2 PoCs

RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing execution of any commands on the remote system.

CVE-2023-42509
Artifactory General
6.6
MEDIUM
EPSS
0.3%
2023 CWE-755 1 PoC

JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data.

CVE-2023-42533
Samsung Mobile Devices General
6.6
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper Input Validation with USB Gadget Interface prior to SMR Nov-2023 Release 1 allows a physical attacker to execute arbitrary code in Kernel.

CVE-2023-42564
Samsung Mobile Devices General
6.6
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to send broadcast with system privilege.

CVE-2023-34045
Fusion General
6.6
MEDIUM
EPSS
0.1%
2023 1 PoC

VMware Fusion(13.x prior to 13.5) contains a local privilege escalation vulnerability that occurs during installation for the first time (the user needs to drag or copy the application to a folder from the '.dmg' volume) or when installing an upgrade. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed or being installed for the first time.

CVE-2023-3106
Red Hat Enterprise Linux 6 General
6.6
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

A NULL pointer dereference vulnerability was found in netlink_dump. This issue can occur when the Netlink socket receives the message(sendmsg) for the XFRM_MSG_GETSA, XFRM_MSG_GETPOLICY type message, and the DUMP flag is set and can cause a denial of service or possibly another unspecified impact. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is unlikely.

CVE-2023-37941
Apache Superset Web
6.6
MEDIUM
EPSS
84.2%
2023 CWE-502 2 PoCs

If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. The Superset metadata db is an 'internal' component that is typically only accessible directly by the system administrator and the superset process itself. Gaining access to that database should be difficult and require significant privileges. This vulnerability impacts Apache Superset versions 1.5.0 up to and including 2.1.0. Users are recommended to upgrade to version 2.1.1 or later.

CVE-2023-0198
vGPU software (guest driver - Linux), vGPU software (Virtual GPU Manager - Citrix Hypervisor, VMware vSphere, Red Hat Enterprise Linux KVM), , NVIDIA Cloud Gaming (guest driver - Linux), NVIDIA Cloud Gaming (Virtual GPU Manager - Red Hat Enterprise Linux KVM) Networking Cloud
6.6
MEDIUM
EPSS
0.1%
2023 CWE-119 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where improper restriction of operations within the bounds of a memory buffer can lead to denial of service, information disclosure, and data tampering.

CVE-2023-3981
omeka/omeka-s General
6.5
MEDIUM
EPSS
0.1%
2023 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository omeka/omeka-s prior to 4.0.2.

CVE-2023-30950
com.palantir.campaigns:campaigns General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-290 1 PoC

The foundry campaigns service was found to be vulnerable to an unauthenticated information disclosure in a rest endpoint

CVE-2023-2792
Mattermost General
6.5
MEDIUM
EPSS
0.3%
2023 CWE-200 1 PoC

Mattermost fails to sanitize ephemeral error messages, allowing an attacker to obtain arbitrary message contents by a specially crafted /groupmsg command.

CVE-2023-6199
BookStack General
6.5
MEDIUM
EPSS
13.4%
2023 CWE-918 2 PoCs

Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.

CVE-2023-20235
Cisco IOS XE Software DevOps Networking
6.5
MEDIUM
EPSS
0.2%
2023 CWE-552 1 PoC

A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an authenticated, remote attacker to access the underlying operating system as the root user. This vulnerability exists because Docker containers with the privileged runtime option are not blocked when they are in application development mode. An attacker could exploit this vulnerability by using the Docker CLI to access an affected device. The application development workflow is meant to be used only on development systems and n

CVE-2023-26142
Crow Web
6.5
MEDIUM
EPSS
0.2%
2023 CWE-113 1 PoC

All versions of the package crow are vulnerable to HTTP Response Splitting when untrusted user input is used to build header values. Header values are not properly sanitized against CRLF Injection in the set_header and add_header functions. An attacker can add the \r\n (carriage return line feeds) characters to end the HTTP response headers and inject malicious content.

CVE-2023-26150
asyncua General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-287 1 PoC

Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space without encryption and authentication. **Note:** This issue is a result of missing checks for services that require an active session.

CVE-2023-3218
it-novum/openitcockpit General
6.5
MEDIUM
EPSS
0.0%
2023 CWE-366 1 PoC

Race Condition within a Thread in GitHub repository it-novum/openitcockpit prior to 4.6.5.

CVE-2023-26428
OX App Suite General
6.5
MEDIUM
EPSS
0.3%
2023 CWE-639 1 PoC

Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same context. Signatures of other users could be read even though they are not explicitly shared. We improved permission handling when requesting snippets that are not explicitly shared with other users. No publicly available exploits are known.

CVE-2023-35872
SAP NetWeaver Process Integration (Message Display Tool) General
6.5
MEDIUM
EPSS
0.2%
2023 CWE-306 1 PoC

The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might access technical data about the product status and its configuration. The vulnerability does not allow access to sensitive information or administrative functionalities. On successful exploitation an attacker can cause limited impact on confidentiality and availability of the application.