7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-21990
VM VirtualBox Database
8.2
HIGH
EPSS
0.1%
2023 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Int

CVE-2023-22893
Software Genérico Web Cloud ⚡ nuclei
8.2
HIGH
EPSS
76.7%
2023 2 PoCs

Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for authentication. A remote attacker could forge an ID token that is signed using the 'None' type algorithm to bypass authentication and impersonate any user that use AWS Cognito for authentication.

CVE-2023-45539
Software Genérico General
8.2
HIGH
EPSS
0.0%
2023 1 PoC

HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unspecified other impact upon misinterpretation of a path_end rule, such as routing index.html#.png to a static server.

CVE-2023-26114
code-server General
8.2
HIGH
EPSS
0.2%
2023 CWE-1385 1 PoC

Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.

CVE-2023-3486
PaperCut NG General
8.2
HIGH
EPSS
2.3%
2023 CWE-434 1 PoC

An authentication bypass exists in PaperCut NG versions 22.0.12 and prior that could allow a remote, unauthenticated attacker to upload arbitrary files to the PaperCut NG host’s file storage. This could exhaust system resources and prevent the service from operating as expected.

CVE-2023-34119
Zoom Rooms for Windows Windows
8.2
HIGH
EPSS
0.1%
2023 CWE-426 1 PoC

Insecure temporary file in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.

CVE-2023-41806
Pandora FMS General
8.2
HIGH
EPSS
0.1%
2023 CWE-269 1 PoC

Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability causes that a bad privilege assignment could cause a DOS attack that affects the availability of the Pandora FMS server. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-33244
Software Genérico Web
8.2
HIGH
EPSS
0.1%
2023 1 PoC

Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an embedded web page.

CVE-2023-5948
teamamaze/amazefileutilities General
8.2
HIGH
EPSS
0.0%
2023 CWE-285 1 PoC

Improper Authorization in GitHub repository teamamaze/amazefileutilities prior to 1.91.

CVE-2023-2110
Obsidian Windows
8.2
HIGH
EPSS
0.1%
2023 CWE-22 1 PoC

Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/<absolute-path>". This vulnerability can be exploited if a user opens a malicious markdown file in Obsidian, or copies text from a malicious webpage and paste it into Obsidian.

CVE-2023-0740
answerdev/answer Web
8.2
HIGH
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.

CVE-2023-26133
progressbar.js General
8.2
HIGH
EPSS
0.1%
2023 CWE-1321 1 PoC

All versions of the package progressbar.js are vulnerable to Prototype Pollution via the function extend() in the file utils.js.

CVE-2023-5760
Avast/Avg Antivirus General
8.2
HIGH
EPSS
0.1%
2023 CWE-367 1 PoC

A time-of-check to time-of-use (TOCTOU) bug in handling of IOCTL (input/output control) requests. This TOCTOU bug leads to an out-of-bounds write vulnerability which can be further exploited, allowing an attacker to gain full local privilege escalation on the system.This issue affects Avast/Avg Antivirus: 23.8.

CVE-2023-43017
Security Verify Access Appliance General
8.2
HIGH
EPSS
0.0%
2023 CWE-295 1 PoC

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. IBM X-Force ID: 266155.

CVE-2023-31027
NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver Cloud Windows
8.2
HIGH
EPSS
0.0%
2023 CWE-427 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability that allows Windows users with low levels of privilege to escalate privileges when an administrator is updating GPU drivers, which may lead to escalation of privileges.

CVE-2023-7007
Gateway G2 General
8.2
HIGH
EPSS
0.1%
2023 1 PoC

Sciener server does not validate connection requests from the GatewayG2, allowing an impersonation attack that provides the attacker the unlockKey field.

CVE-2023-0743
answerdev/answer Web
8.2
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository answerdev/answer prior to 1.0.4.

CVE-2023-30845
esp-v2 Web
8.2
HIGH
EPSS
0.2%
2023 CWE-287 1 PoC

ESPv2 is a service proxy that provides API management capabilities using Google Service Infrastructure. ESPv2 2.20.0 through 2.42.0 contains an authentication bypass vulnerability. API clients can craft a malicious `X-HTTP-Method-Override` header value to bypass JWT authentication in specific cases. ESPv2 allows malicious requests to bypass authentication if both the conditions are true: The requested HTTP method is **not** in the API service definition (OpenAPI spec or gRPC `google.api.http` proto annotations, and the specified `X-HTTP-Method-Override` is a valid HTTP method in the API servi

CVE-2023-26573
IDWeb General
8.2
HIGH
EPSS
0.2%
2023 CWE-306 1 PoC

Missing authentication in the SetDB method in IDAttend’s IDWeb application 3.1.052 and earlier allows denial of service or theft of database login credentials.

CVE-2023-21501
Samsung Mobile Devices General
8.2
HIGH
EPSS
0.1%
2023 CWE-20 1 PoC

Improper input validation vulnerability in mPOS fiserve trustlet prior to SMR May-2023 Release 1 allows local attackers to execute arbitrary code.