9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2026-1420
AC23 General
8.7
HIGH
EPSS
0.0%
2026 CWE-120 1 PoC

A flaw has been found in Tenda AC23 16.03.07.52. This impacts an unknown function of the file /goform/WifiExtraSet. This manipulation of the argument wpapsk_crypto causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.

CVE-2026-27745
interface_traduction_objets General
8.7
HIGH
EPSS
0.2%
2026 CWE-94 2 PoCs

The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated remote code execution vulnerability in the translation interface workflow. The plugin incorporates untrusted request data into a hidden form field that is rendered without SPIP output filtering. Because fields prefixed with an underscore bypass protection mechanisms and the hidden content is rendered with filtering disabled, an authenticated attacker with editor-level privileges can inject crafted content that is evaluated through SPIP's template processing chain, resulting in execution of code in the

CVE-2023-4897
mintplex-labs/anything-llm General
8.7
HIGH
EPSS
0.1%
2023 CWE-23 1 PoC

Relative Path Traversal in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.

CVE-2023-53908
HiSecOS General
8.7
HIGH
EPSS
0.0%
2023 CWE-269 1 PoC

HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access role through XML-based NETCONF configuration. Attackers can send crafted XML payloads to the /mops_data endpoint with a specific role value to elevate their user privileges to administrative level.

CVE-2023-27501
NetWeaver AS for ABAP and ABAP Platform General
8.7
HIGH
EPSS
0.6%
2023 CWE-22 1 PoC

SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, allows an attacker to exploit insufficient validation of path information provided by users, thus exploiting a directory traversal flaw in an available service to delete system files. In this attack, no data can be read but potentially critical OS files can be deleted making the system unavailable, causing significant impact on both availability and integrity

CVE-2023-53773
MiniDVBLinux General
8.7
HIGH
EPSS
0.4%
2023 CWE-306 2 PoCs

MiniDVBLinux 5.4 contains an unauthenticated vulnerability in the tv_action.sh script that allows remote attackers to generate live stream snapshots through the Simple VDR Protocol. Attackers can request /tpl/tv_action.sh to create and retrieve a live TV screenshot stored in /var/www/images/tv.jpg without authentication.

CVE-2023-5422
OTRS General
8.7
HIGH
EPSS
0.2%
2023 CWE-295 1 PoC

The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication. As the SSL_get_verify_result() function is not used the certificated is trusted always and it can not be ensured that the certificate satisfies all necessary security requirements. This could allow an attacker to use an invalid certificate to claim to be a trusted host, use expired certificates, or conduct other attacks that could be detected if the certificate is properly validated. This issue affects OTRS: from 7.0.X before 7.0.47, from 8.0.X before

CVE-2023-33989
SAP NetWeaver (BI CONT ADD ON) General
8.7
HIGH
EPSS
0.3%
2023 CWE-22 1 PoC

An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can exploit a directory traversal flaw to over-write system files. Data from confidential files cannot be read but potentially some OS files can be over-written leading to system compromise.

CVE-2023-53772
MiniDVBLinux General
8.7
HIGH
EPSS
0.9%
2023 CWE-22 2 PoCs

MiniDVBLinux 5.4 contains an arbitrary file disclosure vulnerability that allows attackers to read sensitive system files through the 'file' GET parameter. Attackers can exploit the about page by supplying file paths to disclose arbitrary file contents on the affected device.

CVE-2023-53770
MiniDVBLinux(TM) Distribution (MLD) General
8.7
HIGH
EPSS
0.3%
2023 CWE-260 2 PoCs

MiniDVBLinux 5.4 contains an unauthenticated configuration download vulnerability that allows remote attackers to access sensitive system configuration files through a direct object reference. Attackers can exploit the backup download endpoint by sending a GET request with 'action=getconfig' to retrieve a complete system configuration archive containing sensitive credentials.

CVE-2023-29186
NetWeaver (BI CONT ADDON) General
8.7
HIGH
EPSS
0.8%
2023 CWE-22 1 PoC

In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a report to upload and overwrite files on the SAP server. Data cannot be read but if a remote attacker has sufficient (administrative) privileges then potentially critical OS files can be overwritten making the system unavailable.

CVE-2023-53896
DAP-1325 General
8.7
HIGH
EPSS
0.4%
2023 CWE-306 1 PoC

D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows unauthenticated attackers to download device configuration settings without authentication. Attackers can exploit the /cgi-bin/ExportSettings.sh endpoint to retrieve sensitive configuration information by directly accessing the export settings script.

CVE-2023-54348
ERPGo SaaS General
8.7
HIGH
EPSS
0.1%
2023 CWE-1236 1 PoC

ERPGo SaaS 3.9 contains a CSV injection vulnerability that allows authenticated attackers to execute arbitrary code by injecting formula payloads into vendor name fields. Attackers can add malicious formulas like =10+20+cmd|' /C calc'!A0 in the vendor creation form, which execute when the exported CSV file is opened in spreadsheet applications.

CVE-2023-53934
Xperience General
8.7
HIGH
EPSS
0.3%
2023 CWE-97 1 PoC

A denial of service vulnerability in Kentico Xperience allows attackers to launch DoS attacks via specially crafted requests to the GetResource handler. Improper input validation enables remote attackers to potentially disrupt service availability through maliciously constructed requests.

CVE-2023-7326
Epson Stylus SX510W General
8.7
HIGH
EPSS
0.3%
2023 CWE-400 1 PoC

The Epson Stylus SX510W embedded web management service fails to properly handle consecutive ampersand characters in query parameters when accessing /PRESENTATION/HTML/TOP/INDEX.HTML. A remote attacker can send a malformed request that triggers improper input parsing or memory handling, resulting in the printer process shutting down or powering off, causing a denial of service condition.

CVE-2023-7327
Ozeki SMS Gateway General
8.7
HIGH
EPSS
0.8%
2023 CWE-22 1 PoC

Ozeki SMS Gateway versions up to and including 10.3.208 contain a path traversal vulnerability. Successful exploitation allows an unauthenticated attacker to use URL-encoded traversal sequences to read arbitrary files from the underlying filesystem with the privileges of the gateway service, leading to disclosure of sensitive information.

CVE-2023-34873
P3 General
8.7
HIGH
EPSS
0.5%
2023 CWE-78 1 PoC

On MOBOTIX P3 cameras before MX-V4.7.2.18 and Mx6 cameras before MX-V5.2.0.61, the tcpdump feature does not properly validate input, which allows authenticated users to execute code.

CVE-2023-7335
EduSoho General
8.7
HIGH
EPSS
0.2%
2023 CWE-22 1 PoC

EduSoho versions prior to 22.4.7 contain an arbitrary file read vulnerability in the classroom-course-statistics export functionality. A remote, unauthenticated attacker can supply crafted path traversal sequences in the fileNames[] parameter to read arbitrary files from the server filesystem, including application configuration files such as config/parameters.yml that may contain secrets and database credentials. Exploitation evidence was observed by the Shadowserver Foundation on 2026-01-19 (UTC).

CVE-2023-7307
Sangfor Behavior Management System (DC Management System) General
8.7
HIGH
EPSS
0.2%
2023 CWE-611 2 PoCs

Sangfor Behavior Management System (also referred to as DC Management System in Chinese-language documentation) contains an XML external entity (XXE) injection vulnerability in the /src/sangforindex endpoint. A remote unauthenticated attacker can submit crafted XML data containing external entity definitions, leading to potential disclosure of internal files, server-side request forgery (SSRF), or other impacts depending on parser behavior. The vulnerability is due to improper configuration of the XML parser, which allows resolution of external entities without restriction. This product is now

CVE-2023-7329
Lan Controller General
8.7
HIGH
EPSS
0.5%
2023 CWE-306 2 PoCs

Tinycontrol LAN Controller v3 (LK3) firmware versions up to 1.58a (hardware v3.8) contain a missing authentication vulnerability in the stm.cgi endpoint. A remote, unauthenticated attacker can send crafted requests to forcibly reboot the device or restore factory settings, leading to a denial of service and configuration loss.