7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-42531
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass restrictions on starting activities from the background.

CVE-2023-31184
client General
6.2
MEDIUM
EPSS
3.5%
2023 CWE-798 1 PoC

ROZCOM client CWE-798: Use of Hard-coded Credentials

CVE-2023-21118
Android General
6.2
MEDIUM
EPSS
0.1%
2023 2 PoCs

In unflattenString8 of Sensor.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-269014004

CVE-2023-3095
nilsteampassnet/teampass General
6.2
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

CVE-2023-30659
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in Transaction prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

CVE-2023-53905
projectSend General
6.2
MEDIUM
EPSS
0.1%
2023 CWE-1236 1 PoC

ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into user profile names. Attackers can craft payloads like =calc|a!z| in the name field to trigger code execution when administrators export action logs as CSV files.

CVE-2023-23946
git General
6.2
MEDIUM
EPSS
1.5%
2023 CWE-22 1 PoC

Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8. By feeding a crafted input to `git apply`, a path outside the working tree can be overwritten as the user who is running `git apply`. A fix has been prepared and will appear in v2.39.2, v2.38.4, v2.37.6, v2.36.5, v2.35.7, v2.34.7, v2.33.7, v2.32.6, v2.31.7, and v2.30.8. As a workaround, use `git apply --stat` to inspect a patch before applying; avoid applying one that creates a symbolic link and then creates a file beyond the symb

CVE-2023-45184
i Access Client Solutions General
6.2
MEDIUM
EPSS
7.8%
2023 CWE-922 1 PoC

IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to obtain a decryption key due to improper authority checks. IBM X-Force ID: 268270.

CVE-2023-30713
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper privilege management vulnerability in FolderLockNotifier in One UI Home prior to SMR Sep-2023 Release 1 allows local attackers to change some settings of the folder lock.

CVE-2023-30660
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2023 1 PoC

Exposure of Sensitive Information vulnerability in getDefaultChipId in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.

CVE-2023-30675
Samsung Pass General
6.2
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account information when Samsung Wallet is not installed.

CVE-2023-53913
Rukovoditel General
6.2
MEDIUM
EPSS
0.2%
2023 CWE-1236 1 PoC

Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field. Attackers can craft payloads like =calc|a!z| to trigger code execution when an admin exports customer data as a CSV file.

CVE-2023-3771
t1 Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect users to arbitrary websites.

CVE-2023-25292
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2023 2 PoCs

Reflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated privileges and gain sensitive information via the GO_LANGUAGE cookie.

CVE-2023-54341
Webgrind Web
6.1
MEDIUM
EPSS
0.1%
2023 CWE-79 1 PoC

Webgrind 1.1 and before contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts via the file parameter in index.php. The application does not sufficiently encode user-controlled inputs, allowing attackers to execute arbitrary JavaScript in victim's browsers by crafting malicious URLs.

CVE-2023-23852
Solution Manager Web
6.1
MEDIUM
EPSS
0.7%
2023 CWE-79 1 PoC

SAP Solution Manager (System Monitoring) - version 720, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

CVE-2023-2503
10Web Social Post Feed Web Windows
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

The 10Web Social Post Feed WordPress plugin before 1.2.9 does not sanitise and escape some parameter before outputting it back in a page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2023-0442
Loan Comparison Web Windows
6.1
MEDIUM
EPSS
0.2%
2023 1 PoC

The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its query parameters before outputting them back in a page/post via an embedded shortcode, which could allow an attacker to inject javascript into into the site via a crafted URL.

CVE-2023-50883
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2023 2 PoCs

ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and therefore a sandbox escape is possible by directly calling the constructor of the Function object. NOTE: this issue exists because of an incorrect fix for CVE-2021-43446.

CVE-2023-33763
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2023 1 PoC

eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /scheduler/index.php.