7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-34970
Valhall GPU Kernel Driver General
4.7
MEDIUM
EPSS
0.1%
2023 CWE-416 1 PoC

A local non-privileged user can make improper GPU processing operations to access a limited amount outside of buffer bounds or to exploit a software race condition. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory

CVE-2023-0160
kernel General
4.7
MEDIUM
EPSS
0.0%
2023 CWE-833 1 PoC

A deadlock flaw was found in the Linux kernel’s BPF subsystem. This flaw allows a local user to potentially crash the system.

CVE-2023-1442
QYKCMS Web
4.7
MEDIUM
EPSS
0.5%
2023 CWE-434 1 PoC

A vulnerability was found in Meizhou Qingyunke QYKCMS 4.3.0. It has been classified as problematic. This affects an unknown part of the file /admin_system/api.php of the component Update Handler. The manipulation of the argument downurl leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223287.

CVE-2023-7236
Backup Bolt Web Windows
4.7
MEDIUM
EPSS
0.4%
2023 1 PoC

The Backup Bolt WordPress plugin through 1.3.0 is vulnerable to Information Exposure via the unprotected access of debug logs. This makes it possible for unauthenticated attackers to retrieve the debug log which may contain information like system errors which could contain sensitive information.

CVE-2023-0045
Linux Kernel General
4.7
MEDIUM
EPSS
0.2%
2023 CWE-610 2 PoCs

The current implementation of the prctl syscall does not issue an IBPB immediately during the syscall. The ib_prctl_set  function updates the Thread Information Flags (TIFs) for the task and updates the SPEC_CTRL MSR on the function __speculation_ctrl_update, but the IBPB is only issued on the next schedule, when the TIF bits are checked. This leaves the victim vulnerable to values already injected on the BTB, prior to the prctl syscall.  The patch that added the support for the conditional mitigation via prctl (ib_prctl_set) dates back to the kernel 4.9.176. We recommend upgrading past commi

CVE-2023-3450
RG-BCR860 General
4.7
MEDIUM
EPSS
61.4%
2023 CWE-78 3 PoCs

A vulnerability was found in Ruijie RG-BCR860 2.5.13 and classified as critical. This issue affects some unknown processing of the component Network Diagnostic Page. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-232547. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-42573
Search Widget General
4.7
MEDIUM
EPSS
0.1%
2023 1 PoC

PendingIntent hijacking vulnerability in Search Widget prior to version 3.4 in China models allows local attackers to access data.

CVE-2023-1595
novel-plus Database
4.7
MEDIUM
EPSS
0.4%
2023 CWE-89 1 PoC

A vulnerability has been found in novel-plus 3.6.2 and classified as critical. Affected by this vulnerability is an unknown functionality of the file common/log/list. The manipulation of the argument sort leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223663.

CVE-2023-7178
Online College Library System Web Database
4.7
MEDIUM
EPSS
0.0%
2023 CWE-89 1 PoC

A vulnerability, which was classified as critical, has been found in Campcodes Online College Library System 1.0. This issue affects some unknown processing of the file /admin/book_row.php of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249365 was assigned to this vulnerability.

CVE-2023-3380
WN579X3 General ⚡ nuclei
4.7
MEDIUM
EPSS
80.3%
2023 CWE-74 0 PoCs

A vulnerability classified as critical has been found in Wavlink WN579X3 up to 20230615. Affected is an unknown function of the file /cgi-bin/adm.cgi of the component Ping Test. The manipulation of the argument pingIp leads to injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-232236. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-23694
Dell VxRail HCI General
4.7
MEDIUM
EPSS
0.2%
2023 CWE-78 1 PoC

Dell VxRail versions earlier than 7.0.450, contain(s) an OS command injection vulnerability in VxRail Manager. A local authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. Exploitation may lead to a system take over by an attacker.

CVE-2023-3478
OA Database
4.7
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability classified as critical was found in IBOS OA 4.5.5. Affected by this vulnerability is the function actionEdit of the file ?r=dashboard/roleadmin/edit&op=member of the component Add User Handler. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-232759. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-3439
Linux Kernel (mctp) General
4.7
MEDIUM
EPSS
0.0%
2023 CWE-416 1 PoC

A flaw was found in the MCTP protocol in the Linux kernel. The function mctp_unregister() reclaims the device's relevant resource when a netcard detaches. However, a running routine may be unaware of this and cause the use-after-free of the mdev->addrs object, potentially leading to a denial of service.

CVE-2023-1909
BP Monitoring Management System Web Database
4.7
MEDIUM
EPSS
0.3%
2023 CWE-89 1 PoC

A vulnerability, which was classified as critical, was found in PHPGurukul BP Monitoring Management System 1.0. Affected is an unknown function of the file profile.php of the component User Profile Update Handler. The manipulation of the argument name/mobno leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-225318 is the identifier assigned to this vulnerability.

CVE-2023-32019
Windows 10 Version 1809 Windows
4.7
MEDIUM
EPSS
2.8%
2023 1 PoC

Windows Kernel Information Disclosure Vulnerability

CVE-2023-30720
Samsung Mobile Devices General
4.7
MEDIUM
EPSS
0.1%
2023 1 PoC

PendingIntent hijacking in LmsAssemblyTrackerCTC prior to SMR Sep-2023 Release 1 allows local attacker to gain arbitrary file access.

CVE-2023-7181
DedeBIZ General
4.7
MEDIUM
EPSS
0.1%
2023 CWE-434 1 PoC

A vulnerability was found in Muyun DedeBIZ up to 6.2.12 and classified as critical. Affected by this issue is some unknown functionality of the component Add Attachment Handler. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249368. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-5294
ECshop Web Database
4.7
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

A vulnerability has been found in ECshop 4.1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/order.php. The manipulation of the argument goods_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240925 was assigned to this vulnerability.

CVE-2023-1759
thorsten/phpmyfaq Web
4.7
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2023-42482
Software Genérico General
4.7
MEDIUM
EPSS
0.1%
2023 1 PoC

Samsung Mobile Processor Exynos 2200 allows a GPU Use After Free.