7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-4108
Mattermost General
4.5
MEDIUM
EPSS
0.2%
2023 CWE-532 1 PoC

Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged

CVE-2023-22005
MySQL Server Database
4.4
MEDIUM
EPSS
0.0%
2023 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.33 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVE-2023-30665
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper input validation vulnerability in OnOemServiceMode in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds read.

CVE-2023-0221
Application and Change Control General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-269 1 PoC

Product security bypass vulnerability in ACC prior to version 8.3.4 allows a locally logged-in attacker with administrator privileges to bypass the execution controls provided by ACC using the utilman program.

CVE-2023-43574
Desktop BIOS General
4.4
MEDIUM
EPSS
0.0%
2023 CWE-126 1 PoC

A buffer over-read was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.

CVE-2023-1374
Solidres – Hotel booking plugin for WordPress Web Windows
4.4
MEDIUM
EPSS
0.4%
2023 CWE-79 1 PoC

The Solidres plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'currency_name' parameter in versions up to, and including, 0.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator privileges to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2023-21518
Samsung SearchWidget General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control vulnerability in SearchWidget prior to version 3.3 in China models allows untrusted applications to start arbitrary activity.

CVE-2023-1486
WiseCleaner Wise Force Deleter General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

A vulnerability classified as problematic was found in Lespeed WiseCleaner Wise Force Deleter 1.5.3.54. This vulnerability affects the function 0x220004 in the library WiseUnlock64.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223372.

CVE-2023-21947
MySQL Server Database
4.4
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVE-2023-21430
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-125 1 PoC

An out-of-bound read vulnerability in mapToBuffer function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR JAN-2023 Release 1 allows attacker to cause memory access fault.

CVE-2023-22058
MySQL Server Database
4.4
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.33 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVE-2023-20579
AMD Ryzen™ 5000 Series Desktop Processor with Radeon™ Graphics General
4.4
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability.

CVE-2023-5255
Puppet Enterprise General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-404 1 PoC

For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.

CVE-2023-2612
ubuntu-linux General
4.4
MEDIUM
EPSS
0.0%
2023 CWE-667 3 PoCs

Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu Linux kernel contained a race condition when handling inode locking in some situations. A local attacker could use this to cause a denial of service (kernel deadlock).

CVE-2023-30697
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.0%
2023 1 PoC

An improper input validation in IpcTxCfgSetSimlockPayload in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.

CVE-2023-5586
gpac/gpac General
4.4
MEDIUM
EPSS
0.0%
2023 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3.0-DEV.

CVE-2023-21884
VM VirtualBox Database
4.4
MEDIUM
EPSS
0.0%
2023 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.42 and prior to 7.0.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S

CVE-2023-5621
Thumbnail Slider With Lightbox Web Windows
4.4
MEDIUM
EPSS
0.2%
2023 CWE-79 1 PoC

The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Title field in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVE-2023-1453
Anti-Virus General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-284 2 PoCs

A vulnerability was found in Watchdog Anti-Virus 1.4.214.0. It has been rated as critical. Affected by this issue is the function 0x80002008 in the library wsdk-driver.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. VDB-223298 is the identifier assigned to this vulnerability.

CVE-2023-21488
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control vulnerablility in Tips prior to SMR May-2023 Release 1 allows local attackers to launch arbitrary activity in Tips.