7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-23005
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2023 1 PoC

In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case, whereas it is actually an error pointer). NOTE: this is disputed by third parties because there are no realistic cases in which a user can cause the alloc_memory_type error case to be reached.

CVE-2023-51777
Software Genérico Windows
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error.

CVE-2023-1640
Malware Fighter General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

A vulnerability classified as problematic was found in IObit Malware Fighter 9.4.0.776. This vulnerability affects the function 0x222010 in the library ObCallbackProcess.sys of the component IOCTL Handler. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224020.

CVE-2023-26818
Software Genérico General
5.5
MEDIUM
EPSS
4.7%
2023 1 PoC

Telegram 9.3.1 and 9.4.0 allows attackers to access restricted files, microphone ,or video recording via the DYLD_INSERT_LIBRARIES flag.

CVE-2023-6105
Service Desk Plus General
5.5
MEDIUM
EPSS
0.1%
2023 CWE-200 1 PoC

An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.

CVE-2023-42829
macOS Networking
5.5
MEDIUM
EPSS
0.4%
2023 1 PoC

The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Big Sur 11.7.9, macOS Monterey 12.6.8, macOS Ventura 13.5. An app may be able to access SSH passphrases.

CVE-2023-7229
illi Link Party! Web Windows
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

The illi Link Party! WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVE-2023-24577
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

McAfee Total Protection prior to 16.0.50 allows attackers to elevate user privileges due to Improper Link Resolution via registry keys. This could enable a user with lower privileges to execute unauthorized tasks.

CVE-2023-4987
taskhub Database
5.5
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability, which was classified as critical, has been found in infinitietech taskhub 2.8.7. Affected by this issue is some unknown functionality of the file /home/get_tasks_list of the component GET Parameter Handler. The manipulation of the argument project/status/user_id/sort/search leads to sql injection. VDB-239798 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-6902
Stupid Simple CMS Web
5.5
MEDIUM
EPSS
0.1%
2023 CWE-434 1 PoC

A vulnerability has been found in codelyfe Stupid Simple CMS up to 1.2.4 and classified as critical. This vulnerability affects unknown code of the file /file-manager/upload.php. The manipulation of the argument file leads to unrestricted upload. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-248260.

CVE-2023-5784
NS-ASG Application Security Gateway Web Networking Database
5.5
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by this issue is some unknown functionality of the file /protocol/firewall/uploadfirewall.php. The manipulation of the argument messagecontent leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-243590 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-30722
Samsung Blockchain Keystore General
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

Protection Mechanism Failure in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.13.5 allows local attacker to execute arbitrary code.

CVE-2023-29753
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2023 1 PoC

An issue found in Facemoji Emoji Keyboard v.2.9.1.2 for Android allows a local attacker to cause a denial of service via the SharedPreference files.

CVE-2023-46316
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2023 1 PoC

In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3, the wrapper scripts do not properly parse command lines.

CVE-2023-2336
pimcore/pimcore General
5.5
MEDIUM
EPSS
0.0%
2023 CWE-22 1 PoC

Path Traversal in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-1637
Kernel General
5.5
MEDIUM
EPSS
0.0%
2023 CWE-226 1 PoC

A flaw that boot CPU could be vulnerable for the speculative execution behavior kind of attacks in the Linux kernel X86 CPU Power management options functionality was found in the way user resuming CPU from suspend-to-RAM. A local user could use this flaw to potentially get unauthorized access to some memory of the CPU similar to the speculative execution behavior kind of attacks.

CVE-2023-31022
NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver Cloud Windows
5.5
MEDIUM
EPSS
0.1%
2023 CWE-476 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a NULL-pointer dereference may lead to denial of service.

CVE-2023-2872
FlexiHub General
5.5
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

A vulnerability classified as problematic has been found in FlexiHub 5.5.14691.0. This affects the function 0x220088 in the library fusbhub.sys of the component IoControlCode Handler. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-229851. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-21036
Android General
5.5
MEDIUM
EPSS
0.2%
2023 1 PoC

In BitmapExport.java, there is a possible failure to truncate images due to a logic error in the code.Product: AndroidVersions: Android kernelAndroid ID: A-264261868References: N/A

CVE-2023-0516
Online Tours & Travels Management System Web Database
5.5
MEDIUM
EPSS
0.4%
2023 CWE-89 1 PoC

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. Affected is an unknown function of the file user/forget_password.php of the component Parameter Handler. The manipulation of the argument email leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-219336.