7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-32190
openSUSE Tumbleweed General
8.5
HIGH
EPSS
0.1%
2023 1 PoC

mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.

CVE-2023-53949
AspEmail General
8.5
HIGH
EPSS
0.0%
2023 CWE-732 1 PoC

AspEmail 5.6.0.2 contains a binary permission vulnerability that allows local users to escalate privileges through the Persits Software EmailAgent service. Attackers can exploit full write permissions in the BIN directory to replace the service executable and gain elevated system access.

CVE-2023-30664
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in RegisteredMSISDN prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

CVE-2023-54336
Mediconta General
8.5
HIGH
EPSS
0.0%
2023 CWE-428 1 PoC

Mediconta 3.7.27 contains an unquoted service path vulnerability in the servermedicontservice that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\medicont3\ to inject malicious code that would execute with LocalSystem permissions during service startup.

CVE-2023-53957
Kimai Web
8.5
HIGH
EPSS
0.2%
2023 CWE-1275 1 PoC

Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.

CVE-2023-53946
PhotoStudio Windows
8.5
HIGH
EPSS
0.0%
2023 CWE-428 1 PoC

Arcsoft PhotoStudio 6.0.0.172 contains an unquoted service path vulnerability in the ArcSoft Exchange Service that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted path and trigger the service to execute arbitrary code with system-level permissions.

CVE-2023-22062
Hyperion Financial Reporting Web Database
8.5
HIGH
EPSS
0.3%
2023 1 PoC

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported version that is affected is 11.2.13.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. While the vulnerability is in Oracle Hyperion Financial Reporting, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Repor

CVE-2023-30655
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in SCEPProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

CVE-2023-53959
FileZilla Client Web
8.5
HIGH
EPSS
0.4%
2023 CWE-427 1 PoC

FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll in the application directory. Attackers can generate a reverse shell payload using msfvenom and replace the missing DLL to achieve remote code execution when the application launches.

CVE-2023-2141
DELMIA Apriso General
8.5
HIGH
EPSS
3.5%
2023 CWE-502 1 PoC

An unsafe .NET object deserialization in DELMIA Apriso Release 2017 through Release 2022 could lead to post-authentication remote code execution.

CVE-2023-53912
USB Flash Drives Control Windows
8.5
HIGH
EPSS
0.0%
2023 CWE-428 1 PoC

USB Flash Drives Control 4.1.0.0 contains an unquoted service path vulnerability in its service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\USB Flash Drives Control\usbcs.exe' to inject malicious executables and escalate privileges on Windows systems.

CVE-2023-53937
Hubstaff General
8.5
HIGH
EPSS
0.0%
2023 CWE-427 1 PoC

Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious library. Attackers can generate a custom DLL using Metasploit and place it in the system32 directory to obtain a reverse shell during application startup.

CVE-2023-1837
HYPR Server Web
8.5
HIGH
EPSS
0.1%
2023 CWE-306 1 PoC

Missing Authentication for critical function vulnerability in HYPR Server allows Authentication Bypass when using Legacy APIs.This issue affects HYPR Server: before 8.0 (with enabled Legacy APIs)

CVE-2023-53984
HotKey Clipboard General
8.5
HIGH
EPSS
0.0%
2023 CWE-428 1 PoC

Clevo HotKey Clipboard 2.1.0.6 contains an unquoted service path vulnerability in the HKClipSvc service that allows local non-privileged users to potentially execute code with system privileges. Attackers can exploit the misconfigured service path to inject and execute arbitrary code by placing malicious executables in specific file system locations.

CVE-2023-45358
Software Genérico Web
8.5
HIGH
EPSS
0.2%
2023 1 PoC

Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application. 6.14 (6.14.0) is also a fixed release.

CVE-2023-53954
ActFax General
8.5
HIGH
EPSS
0.0%
2023 CWE-428 1 PoC

ActFax 10.10 contains an unquoted service path vulnerability that allows local attackers to potentially escalate privileges by exploiting the ActiveFaxServiceNT service configuration. Attackers with write permissions to Program Files directories can inject a malicious ActSrvNT.exe executable to gain elevated system access when the service restarts.

CVE-2023-41808
Pandora FMS General
8.5
HIGH
EPSS
0.1%
2023 CWE-269 1 PoC

Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability allows an unauthorised user to escalate and read sensitive files as if they were root. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-35157
xwiki-platform Web
8.5
HIGH
EPSS
1.4%
2023 CWE-80 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to perform an XSS by forging a request to a delete attachment action with a specific attachment name. Now this XSS can be exploited only if the attacker knows the CSRF token of the user, or if the user ignores the warning about the missing CSRF token. The vulnerability has been patched in XWiki 15.1-rc-1 and XWiki 14.10.6.

CVE-2023-3532
outline/outline Web
8.5
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to 0.70.1.

CVE-2023-30656
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2023 1 PoC

Improper input validation vulnerability in LSOItemData prior to SMR Jul-2023 Release 1 allows attackers to launch certain activities.