14993 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-51968
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function getIptvInfo.

CVE-2023-28503
UniData General
9.8
CRITICAL
EPSS
64.8%
2023 CWE-798 2 PoCs

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user.

CVE-2023-25218
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the form_fast_setting_wifi_set function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-27396
Multiple OMRON products which implement FINS protocol General
9.8
CRITICAL
EPSS
1.7%
2023 2 PoCs

FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation) networks, and is used in FA networks composed of OMRON products. Multiple OMRON products that implement FINS protocol contain following security issues -- (1)Plaintext communication, and (2)No authentication required. When FINS messages are intercepted, the contents may be retrieved. When arbitrary FINS messages are injected, any commands may be executed on, or the system information may be retrieved from, the affected device. Affected products and versio

CVE-2023-51812
Software Genérico General
9.8
CRITICAL
EPSS
2.6%
2023 1 PoC

Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList.

CVE-2023-26802
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
83.6%
2023 0 PoCs

An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass authentication and execute arbitrary commands via a crafted request.

CVE-2023-25078
Experion Server General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-787 1 PoC

Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.  See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-49235
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

An issue was discovered in libremote_dbg.so on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Filtering of debug information is mishandled during use of popen. Consequently, an attacker can bypass validation and execute a shell command.

CVE-2023-27168
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.

CVE-2023-37903
vm2 General
9.8
CRITICAL
EPSS
36.1%
2023 CWE-78 1 PoC

vm2 is an open source vm/sandbox for Node.js. In vm2 for versions up to and including 3.9.19, Node.js custom inspect function allows attackers to escape the sandbox and run arbitrary code. This may result in Remote Code Execution, assuming the attacker has arbitrary code execution primitive inside the context of vm2 sandbox. There are no patches and no known workarounds. Users are advised to find an alternative software.

CVE-2023-51953
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.

CVE-2023-28489
CP-8031 MASTER MODULE General
9.8
CRITICAL
EPSS
2.7%
2023 CWE-77 2 PoCs

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). Affected devices are vulnerable to command injection via the web server port 443/tcp, if the parameter “Remote Operation” is enabled. The parameter is disabled by default. The vulnerability could allow an unauthenticated remote attacker to perform arbitrary code execution on the device.

CVE-2023-39453
ImageGear General
9.8
CRITICAL
EPSS
0.4%
2023 CWE-416 1 PoC

A use-after-free vulnerability exists in the tif_parse_sub_IFD functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can deliver this file to trigger this vulnerability.

CVE-2023-31902
Software Genérico General
9.8
CRITICAL
EPSS
64.2%
2023 2 PoCs

RPA Technology Mobile Mouse 3.6.0.4 is vulnerable to Remote Code Execution (RCE).

CVE-2023-43208
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2023 6 PoCs

NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.

CVE-2023-30967
com.palantir.meta:orbital-simulator General
9.8
CRITICAL
EPSS
0.5%
2023 CWE-22 1 PoC

Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbitrary files on the file system.

CVE-2023-51966
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo.

CVE-2023-32653
ImageGear General
9.8
CRITICAL
EPSS
0.2%
2023 CWE-191 1 PoC

An out-of-bounds write vulnerability exists in the dcm_pixel_data_decode functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

CVE-2023-28765
BusinessObjects Business Intelligence Platform (Promotion Management) General
9.8
CRITICAL
EPSS
0.8%
2023 CWE-200 1 PoC

An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to lcmbiar file and further decrypt the file. After this attacker can gain access to BI user’s passwords and depending on the privileges of the BI user, the attacker can perform operations that can completely compromise the application.

CVE-2023-26918
Software Genérico General
9.8
CRITICAL
EPSS
7.2%
2023 1 PoC

Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as LocalSystem. This occurs because %ProgramFiles%\FileReplicationPro allows Everyone:(F) access.