7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-30655
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in SCEPProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

CVE-2023-53984
HotKey Clipboard General
8.5
HIGH
EPSS
0.0%
2023 CWE-428 1 PoC

Clevo HotKey Clipboard 2.1.0.6 contains an unquoted service path vulnerability in the HKClipSvc service that allows local non-privileged users to potentially execute code with system privileges. Attackers can exploit the misconfigured service path to inject and execute arbitrary code by placing malicious executables in specific file system locations.

CVE-2023-30658
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in DataProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

CVE-2023-54336
Mediconta General
8.5
HIGH
EPSS
0.0%
2023 CWE-428 1 PoC

Mediconta 3.7.27 contains an unquoted service path vulnerability in the servermedicontservice that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\medicont3\ to inject malicious code that would execute with LocalSystem permissions during service startup.

CVE-2023-21491
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.1%
2023 CWE-284 1 PoC

Improper access control vulnerability in ThemeManager prior to SMR May-2023 Release 1 allows local attackers to write arbitrary files with system privilege.

CVE-2023-32190
openSUSE Tumbleweed General
8.5
HIGH
EPSS
0.1%
2023 1 PoC

mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.

CVE-2023-30692
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.1%
2023 1 PoC

Improper input validation vulnerability in Evaluator prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.

CVE-2023-53954
ActFax General
8.5
HIGH
EPSS
0.0%
2023 CWE-428 1 PoC

ActFax 10.10 contains an unquoted service path vulnerability that allows local attackers to potentially escalate privileges by exploiting the ActiveFaxServiceNT service configuration. Attackers with write permissions to Program Files directories can inject a malicious ActSrvNT.exe executable to gain elevated system access when the service restarts.

CVE-2023-53912
USB Flash Drives Control Windows
8.5
HIGH
EPSS
0.0%
2023 CWE-428 1 PoC

USB Flash Drives Control 4.1.0.0 contains an unquoted service path vulnerability in its service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\USB Flash Drives Control\usbcs.exe' to inject malicious executables and escalate privileges on Windows systems.

CVE-2023-21480
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in CertByte prior to SMR Apr-2023 Release 1 allows local attackers to launch privileged activities.

CVE-2023-53959
FileZilla Client Web
8.5
HIGH
EPSS
0.4%
2023 CWE-427 1 PoC

FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll in the application directory. Attackers can generate a reverse shell payload using msfvenom and replace the missing DLL to achieve remote code execution when the application launches.

CVE-2023-53947
OCS Inventory NG General
8.5
HIGH
EPSS
0.0%
2023 CWE-428 1 PoC

OCS Inventory NG 2.3.0.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges to system level. Attackers can place a malicious executable in the unquoted service path and trigger the service restart to execute code with elevated system privileges.

CVE-2023-53949
AspEmail General
8.5
HIGH
EPSS
0.0%
2023 CWE-732 1 PoC

AspEmail 5.6.0.2 contains a binary permission vulnerability that allows local users to escalate privileges through the Persits Software EmailAgent service. Attackers can exploit full write permissions in the BIN directory to replace the service executable and gain elevated system access.

CVE-2023-30710
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.1%
2023 1 PoC

Improper input validation vulnerability in Knox AI prior to SMR Sep-2023 Release 1 allows local attackers to launch privileged activities.

CVE-2023-53973
Zillya Total Security General
8.5
HIGH
EPSS
0.0%
2023 CWE-59 1 PoC

Zillya Total Security 3.0.2367.0 contains a privilege escalation vulnerability that allows low-privileged users to copy files to unauthorized system locations using the quarantine module. Attackers can leverage symbolic link techniques to restore quarantined files to restricted directories, potentially enabling system-level access through techniques like DLL hijacking.

CVE-2023-3517
Pentaho Data Integration & Analytics General
8.5
HIGH
EPSS
0.1%
2023 CWE-99 1 PoC

Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.

CVE-2023-30656
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in LSOItemData prior to SMR Jul-2023 Release 1 allows attackers to launch certain activities.

CVE-2023-35157
xwiki-platform Web
8.5
HIGH
EPSS
1.4%
2023 CWE-80 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to perform an XSS by forging a request to a delete attachment action with a specific attachment name. Now this XSS can be exploited only if the attacker knows the CSRF token of the user, or if the user ignores the warning about the missing CSRF token. The vulnerability has been patched in XWiki 15.1-rc-1 and XWiki 14.10.6.

CVE-2023-41808
Pandora FMS General
8.5
HIGH
EPSS
0.1%
2023 CWE-269 1 PoC

Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability allows an unauthorised user to escalate and read sensitive files as if they were root. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-48730
AVideo Web
8.5
HIGH
EPSS
0.5%
2023 CWE-79 2 PoCs

A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.