7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-30716
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper access control vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows attackers to trigger certain commands.

CVE-2023-42541
Samsung Push Service General
4.0
MEDIUM
EPSS
0.3%
2023 1 PoC

Improper authorization in PushClientProvider of Samsung Push Service prior to version 3.4.10 allows attacker to access unique id.

CVE-2023-30711
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to insert arbitrary data to the provider.

CVE-2023-21505
Samsung Core Service General
4.0
MEDIUM
EPSS
0.3%
2023 CWE-285 1 PoC

Improper access control in Samsung Core Service prior to version 2.1.00.36 allows attacker to write arbitrary file in sandbox.

CVE-2023-45864
Software Genérico General
4.0
MEDIUM
EPSS
0.0%
2023 1 PoC

A race condition issue discovered in Samsung Mobile Processor Exynos 9820, 980, 1080, 2100, 2200, 1280, and 1380 allows unintended modifications of values within certain areas.

CVE-2023-5344
vim/vim General
4.0
MEDIUM
EPSS
0.1%
2023 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.

CVE-2023-21470
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2023 1 PoC

Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.NETWORK_LOCATION action.

CVE-2023-41810
Pandora FMS Web
4.0
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed Javascript code to be executed in some Widgets' text box. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-21463
MyFiles General
4.0
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control vulnerability in MyFiles application prior to versions 12.2.09.0 in Android 11, 13.1.03.501 in Android 12 and 14.1.03.0 in Android 13 allows local attacker to get sensitive information of secret mode in Samsung Internet application with specific conditions.

CVE-2023-2327
pimcore/pimcore Web
4.0
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.21.

CVE-2023-5873
pimcore/pimcore Web
4.0
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 11.1.0.

CVE-2023-21449
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2023 CWE-200 1 PoC

Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive information without proper permission.

CVE-2023-23003
Software Genérico General
4.0
MEDIUM
EPSS
0.1%
2023 1 PoC

In the Linux kernel before 5.16, tools/perf/util/expr.c lacks a check for the hashmap__new return value.

CVE-2023-1701
pimcore/pimcore Web
4.0
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.20.

CVE-2023-21428
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2023 CWE-20 1 PoC

Improper input validation vulnerability in TelephonyUI prior to SMR Jan-2023 Release 1 allows attackers to configure Preferred Call. The patch removes unused code.

CVE-2023-21464
Samsung Calendar General
4.0
MEDIUM
EPSS
0.1%
2023 CWE-281 1 PoC

Improper access control in Samsung Calendar prior to versions 12.4.02.9000 in Android 13 and 12.3.08.2000 in Android 12 allows local attacker to configure improper status.

CVE-2023-21447
Samsung Cloud Cloud
4.0
MEDIUM
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control vulnerabilities in Samsung Cloud prior to version 5.3.0.32 allows local attackers to access information with Samsung Cloud's privilege via implicit intent.

CVE-2023-5520
gpac/gpac General
4.0
MEDIUM
EPSS
0.0%
2023 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.

CVE-2023-4720
gpac/gpac General
4.0
MEDIUM
EPSS
0.0%
2023 CWE-1077 1 PoC

Floating Point Comparison with Incorrect Operator in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2023-1517
pimcore/pimcore Web
4.0
MEDIUM
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository pimcore/pimcore prior to 10.5.19.