9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-4354
Chrome General
8.8
HIGH
EPSS
2.0%
2023 1 PoC

Heap buffer overflow in Skia in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-24520
UR32L General
8.8
HIGH
EPSS
0.5%
2023 CWE-77 1 PoC

Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the trace tool utility.

CVE-2023-24269
Software Genérico General
8.8
HIGH
EPSS
0.4%
2023 1 PoC

An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Zip file.

CVE-2023-27893
Solution Manager and ABAP managed systems General
8.8
HIGH
EPSS
5.1%
2023 CWE-94 1 PoC

An attacker authenticated as a user with a non-administrative role and a common remote execution authorization in SAP Solution Manager and ABAP managed systems (ST-PI) - versions 2088_1_700, 2008_1_710, 740, can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform.  Depending on the function executed, the attack can read or modify any user or application data and can make the application unavailable.

CVE-2023-32541
Hancom Office 2020 General
8.8
HIGH
EPSS
0.3%
2023 CWE-416 1 PoC

A use-after-free vulnerability exists in the footerr functionality of Hancom Office 2020 HWord 11.0.0.7520. A specially crafted .doc file can lead to a use-after-free. An attacker can trick a user into opening a malformed file to trigger this vulnerability.

CVE-2023-2258
alfio-event/alf.io General
8.8
HIGH
EPSS
0.4%
2023 CWE-1236 1 PoC

Improper Neutralization of Formula Elements in a CSV File in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.

CVE-2023-32223
DSL-224 firmware version 3.0.10 General
8.8
HIGH
EPSS
0.1%
2023 1 PoC

D-Link DSL-224 firmware version 3.0.10 allows post authentication command execution via an unspecified method.

CVE-2023-4697
usememos/memos General
8.8
HIGH
EPSS
0.1%
2023 CWE-269 1 PoC

Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.

CVE-2023-4759
Eclipse JGit General
8.8
HIGH
EPSS
1.0%
2023 CWE-59 3 PoCs

Arbitrary File Overwrite in Eclipse JGit <= 6.6.0 In Eclipse JGit, all versions <= 6.6.0.202305301015-r, a symbolic link present in a specially crafted git repository can be used to write a file to locations outside the working tree when this repository is cloned with JGit to a case-insensitive filesystem, or when a checkout from a clone of such a repository is performed on a case-insensitive filesystem. This can happen on checkout (DirCacheCheckout), merge (ResolveMerger via its WorkingTreeUpdater), pull (PullCommand using merge), and when applying a patch (PatchApplier). This can be exploi

CVE-2023-46520
Software Genérico General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function uninstallPluginReqHandle.

CVE-2023-33782
Software Genérico General
8.8
HIGH
EPSS
52.2%
2023 2 PoCs

D-Link DIR-842V2 v1.0.3 was discovered to contain a command injection vulnerability via the iperf3 diagnostics function.

CVE-2023-27369
RAX30 General
8.8
HIGH
EPSS
0.1%
2023 CWE-121 1 PoC

NETGEAR RAX30 soap_serverd Stack-based Buffer Overflow Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30. Authentication is not required to exploit this vulnerability. The specific flaw exists within the soap_serverd binary. When parsing the request headers, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-1984

CVE-2023-1531
Chrome General
8.8
HIGH
EPSS
0.9%
2023 1 PoC

Use after free in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-49223
Software Genérico General
8.8
HIGH
EPSS
0.5%
2023 1 PoC

Precor touchscreen console P62, P80, and P82 could allow a remote attacker to obtain sensitive information because the root password is stored in /etc/passwd. An attacker could exploit this to extract files and obtain sensitive information.

CVE-2023-4125
answerdev/answer General
8.8
HIGH
EPSS
0.2%
2023 CWE-521 1 PoC

Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0.

CVE-2023-2935
Chrome General
8.8
HIGH
EPSS
9.4%
2023 1 PoC

Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-5217
🔥 KEV Chrome General
8.8
HIGH
EPSS
4.2%
2023 4 PoCs

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-25729
Firefox General
8.8
HIGH
EPSS
0.1%
2023 1 PoC

Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them without user interaction via <code>ExpandedPrincipals</code>. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVE-2023-1534
Chrome General
8.8
HIGH
EPSS
0.4%
2023 2 PoCs

Out of bounds read in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-4863
🔥 KEV Chrome General
8.8
HIGH
EPSS
94.1%
2023 14 PoCs

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)