7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-21488
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control vulnerablility in Tips prior to SMR May-2023 Release 1 allows local attackers to launch arbitrary activity in Tips.

CVE-2023-3013
gpac/gpac General
4.4
MEDIUM
EPSS
0.0%
2023 CWE-252 1 PoC

Unchecked Return Value in GitHub repository gpac/gpac prior to 2.2.2.

CVE-2023-22031
WebLogic Server Database
4.4
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows high privileged attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVE-2023-21435
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-200 1 PoC

Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address information via log.

CVE-2023-21460
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2023 CWE-287 1 PoC

Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting.

CVE-2023-20812
MT6761, MT6762, MT6765, MT6768, MT6769, MT6781, MT6783, MT6785, MT6789, MT6833, MT6853, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6889, MT6891, MT6893, MT6895, MT6896, MT6983, MT6985, MT8365 General
4.4
MEDIUM
EPSS
0.0%
2023 1 PoC

In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07944987; Issue ID: ALPS07944987.

CVE-2023-21859
Access Manager Database
4.4
MEDIUM
EPSS
0.2%
2023 1 PoC

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Access Manager executes to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U

CVE-2023-20813
MT6580, MT6739, MT6761, MT6765, MT6768, MT6779, MT6781, MT6833, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6891, MT6893, MT6895, MT6983, MT6985 General
4.4
MEDIUM
EPSS
0.0%
2023 1 PoC

In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453549; Issue ID: ALPS07453549.

CVE-2023-21947
MySQL Server Database
4.4
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVE-2023-21940
MySQL Server Database
4.4
MEDIUM
EPSS
0.1%
2023 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVE-2023-42756
Red Hat Enterprise Linux 9 General
4.4
MEDIUM
EPSS
0.0%
2023 CWE-362 1 PoC

A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP can lead to a kernel panic due to the invocation of `__ip_set_put` on a wrong `set`. This issue may allow a local user to crash the system.

CVE-2023-5995
GitLab DevOps
4.4
MEDIUM
EPSS
0.0%
2023 CWE-863 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the policy bot to gain access to internal projects.

CVE-2023-30681
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.0%
2023 1 PoC

An improper input validation vulnerability within initialize function in HAL VaultKeeper prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.

CVE-2023-43572
Desktop BIOS General
4.4
MEDIUM
EPSS
0.0%
2023 CWE-126 1 PoC

A buffer over-read was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.

CVE-2023-0677
phpipam/phpipam Web
4.4
MEDIUM
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to v1.5.1.

CVE-2023-1836
GitLab DevOps Web
4.4
MEDIUM
EPSS
1.0%
2023 1 PoC

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. When viewing an XML file in a repository in "raw" mode, it can be made to render as HTML if viewed under specific circumstances

CVE-2023-4636
File Sharing & Download Manager – User Private Files Web Windows
4.4
MEDIUM
EPSS
3.3%
2023 CWE-79 1 PoC

The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVE-2023-2485
GitLab DevOps
4.4
MEDIUM
EPSS
0.2%
2023 CWE-266 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A malicious maintainer in a project can escalate other users to Owners in that project if they import members from another project that those other users are Owners of.

CVE-2023-21492
🔥 KEV Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.3%
2023 CWE-532 1 PoC

Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.

CVE-2023-30721
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2023 1 PoC

Insertion of sensitive information into log vulnerability in Locksettings prior to SMR Sep-2023 Release 1 allows a privileged local attacker to get lock screen match information from the log.