7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-5014
Food Ordering Website Web Database
6.3
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability was found in Sakshi2610 Food Ordering Website 1.0 and classified as critical. This issue affects some unknown processing of the file categoryfood.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-239855.

CVE-2023-53929
phpMyFAQ Web
6.2
MEDIUM
EPSS
0.1%
2023 CWE-1236 1 PoC

phpMyFAQ 3.1.12 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into their profile names. Attackers can modify their user profile name with a payload like 'calc|a!z|' to trigger code execution when an administrator exports user data as a CSV file.

CVE-2023-30662
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2023 1 PoC

Exposure of Sensitive Information vulnerability in getChipIds in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.

CVE-2023-5441
vim/vim General
6.2
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository vim/vim prior to 20d161ace307e28690229b68584f2d84556f8960.

CVE-2023-42543
Bixby Voice General
6.2
MEDIUM
EPSS
0.3%
2023 1 PoC

Improper verification of intent by broadcast receiver vulnerability in Bixby Voice prior to version 3.3.35.12 allows attackers to access arbitrary data with Bixby Voice privilege.

CVE-2023-37215
soundbar multibeam General
6.2
MEDIUM
EPSS
0.1%
2023 CWE-798 1 PoC

JBL soundbar multibeam 5.1 - CWE-798: Use of Hard-coded Credentials

CVE-2023-21434
Galaxy Store Web
6.2
MEDIUM
EPSS
0.7%
2023 CWE-20 1 PoC

Improper input validation vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to execute JavaScript by launching a web page.

CVE-2023-32329
Security Verify Access Appliance DevOps
6.2
MEDIUM
EPSS
0.0%
2023 CWE-345 1 PoC

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a user to download files from an incorrect repository due to improper file validation. IBM X-Force ID: 254972.

CVE-2023-46048
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2023 1 PoC

Tex Live 944e257 has a NULL pointer dereference in texk/web2c/pdftexdir/writet1.c. NOTE: this is disputed because it should be categorized as a usability problem.

CVE-2023-21446
MyFiles General
6.2
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper input validation in MyFiles prior to version 12.2.09 in Android R(11), 13.1.03.501 in Android S( 12) and 14.1.00.422 in Android T(13) allows local attacker to access data of MyFiles.

CVE-2023-21458
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2023 CWE-269 1 PoC

Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent.

CVE-2023-30657
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in EnhancedAttestationResult prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

CVE-2023-21440
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2023 CWE-285 1 PoC

Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a screen capture.

CVE-2023-38267
Security Verify Access Appliance DevOps
6.2
MEDIUM
EPSS
0.0%
2023 CWE-311 1 PoC

IBM Security Access Manager Appliance (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 260584.

CVE-2023-21118
Android General
6.2
MEDIUM
EPSS
0.1%
2023 2 PoCs

In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-269014004

CVE-2023-2788
Mattermost General
6.2
MEDIUM
EPSS
0.1%
2023 CWE-862 1 PoC

Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while the attacker's account is deactivated.

CVE-2023-31005
Security Verify Access Appliance DevOps
6.2
MEDIUM
EPSS
0.0%
2023 CWE-269 1 PoC

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a local user to escalate their privileges due to an improper security configuration. IBM X-Force ID: 254767.

CVE-2023-42531
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass restrictions on starting activities from the background.

CVE-2023-30661
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2023 1 PoC

Exposure of Sensitive Information vulnerability in getChipInfos in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.

CVE-2023-31184
client General
6.2
MEDIUM
EPSS
3.5%
2023 CWE-798 1 PoC

ROZCOM client CWE-798: Use of Hard-coded Credentials