9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-2574
EKI-1524 General
8.8
HIGH
EPSS
1.4%
2023 CWE-78 4 PoCs

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the device name input field, which can be triggered by authenticated users via a crafted POST request.

CVE-2023-33284
Software Genérico General
8.8
HIGH
EPSS
1.2%
2023 1 PoC

Marval MSM through 14.19.0.12476 and 15.0 has a Remote Code Execution vulnerability. A remote attacker authenticated as any user is able to execute code in context of the web server.

CVE-2023-49367
Software Genérico General
8.8
HIGH
EPSS
0.1%
2023 1 PoC

An issue in user interface in Kyocera Command Center RX EXOSYS M5521cdn allows remote to obtain sensitive information via inspecting sent packages by user.

CVE-2023-32560
Avalanche General
8.8
HIGH
EPSS
92.2%
2023 4 PoCs

An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution. Thanks to a Researcher at Tenable for finding and reporting. Fixed in version 6.4.1.

CVE-2023-50233
Ignition General
8.8
HIGH
EPSS
3.7%
2023 CWE-22 1 PoC

Inductive Automation Ignition getJavaExecutable Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this vulnerability in that the target must connect to a malicious server. The specific flaw exists within the getJavaExecutable method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context

CVE-2023-23529
🔥 KEV iOS and iPadOS General
8.8
HIGH
EPSS
0.1%
2023 1 PoC

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVE-2023-23295
Software Genérico General
8.8
HIGH
EPSS
2.3%
2023 1 PoC

Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as root.

CVE-2023-46538
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function chkResetVeriRegister.

CVE-2023-53964
Impact/Pulse/First General
8.8
HIGH
EPSS
1.2%
2023 CWE-306 2 PoCs

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configuration. Attackers can send a POST request to the endpoint with specific data to trigger a factory reset and bypass authentication, gaining full system control.

CVE-2023-24046
Software Genérico General
8.8
HIGH
EPSS
0.0%
2023 1 PoC

An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary commands via use of a crafted string in the ping utility.

CVE-2023-22629
Software Genérico General
8.8
HIGH
EPSS
65.1%
2023 3 PoCs

An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the newPath parameter. An authenticated attacker can upload any file and then move it anywhere on the server's filesystem.

CVE-2023-46521
Software Genérico General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function RegisterRegister.

CVE-2023-37213
SYnergy Fingerprint Terminals General
8.8
HIGH
EPSS
0.3%
2023 CWE-78 1 PoC

Synel SYnergy Fingerprint Terminals - CWE-78: 'OS Command Injection'

CVE-2023-48841
Software Genérico General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.

CVE-2023-1647
calcom/cal.com General
8.8
HIGH
EPSS
0.3%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository calcom/cal.com prior to 2.7.

CVE-2023-24330
Software Genérico General
8.8
HIGH
EPSS
1.0%
2023 1 PoC

Command Injection vulnerability in D-Link Dir 882 with firmware version DIR882A1_FW130B06 allows attackers to run arbitrary commands via crafted POST request to /HNAP1/.

CVE-2023-24051
Software Genérico General
8.8
HIGH
EPSS
0.1%
2023 1 PoC

A client side rate limit issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via brute force style attacks.

CVE-2023-33781
Software Genérico General
8.8
HIGH
EPSS
42.4%
2023 2 PoCs

An issue in D-Link DIR-842V2 v1.0.3 allows attackers to execute arbitrary commands via importing a crafted file.

CVE-2023-49982
Software Genérico General
8.8
HIGH
EPSS
0.5%
2023 2 PoCs

Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perform Administrative actions, including adding and deleting user accounts.

CVE-2023-0698
Chrome General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

Out of bounds read in WebRTC in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)