9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-3638
GV-ADR2701 General
9.8
CRITICAL
EPSS
0.2%
2023 CWE-287 1 PoC

In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application.

CVE-2023-29736
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Keyboard Themes 1.275.1.164 for Android contains a dictionary traversal vulnerability that allows unauthorized apps to overwrite arbitrary files in its internal storage and achieve arbitrary code execution.

CVE-2023-51018
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘opmode’ parameter of the setWiFiApConfig interface of the cstecgi .cgi.

CVE-2023-42115
Exim General
9.8
CRITICAL
EPSS
70.7%
2023 CWE-787 3 PoCs

Exim AUTH Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of a buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. . Was ZDI-CAN-17434.

CVE-2023-2479
appium/appium-desktop General ⚡ nuclei
9.8
CRITICAL
EPSS
92.9%
2023 CWE-78 0 PoCs

OS Command Injection in GitHub repository appium/appium-desktop prior to v1.22.3-4.

CVE-2023-40890
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 2 PoCs

A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner.

CVE-2023-38203
🔥 KEV ColdFusion General ⚡ nuclei
9.8
CRITICAL
EPSS
94.2%
2023 CWE-502 1 PoC

Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

CVE-2023-24797
Software Genérico General
9.8
CRITICAL
EPSS
1.7%
2023 1 PoC

D-Link DIR882 DIR882A1_FW110B02 was discovered to contain a stack overflow in the sub_48AC20 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-27648
Software Genérico General
9.8
CRITICAL
EPSS
6.0%
2023 1 PoC

Directory Traversal vulnerability found in T-ME Studios Change Color of Keypad v.1.275.1.277 allows a remote attacker to execute arbitrary code via the dex file in the internal storage.

CVE-2023-46485
Software Genérico General
9.8
CRITICAL
EPSS
4.6%
2023 1 PoC

An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setTracerouteCfg function of the stecgi.cgi component.

CVE-2023-28502
UniData General
9.8
CRITICAL
EPSS
69.3%
2023 CWE-120 2 PoCs

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "udadmin" service that can lead to remote code execution as the root user.

CVE-2023-1133
InfraSuite Device Master General
9.8
CRITICAL
EPSS
86.1%
2023 1 PoC

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary code.

CVE-2023-52031
Software Genérico General
9.8
CRITICAL
EPSS
14.8%
2023 1 PoC

TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the UploadFirmwareFile function.

CVE-2023-22741
sofia-sip General
9.8
CRITICAL
EPSS
1.4%
2023 CWE-120 2 PoCs

Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. In affected versions Sofia-SIP **lacks both message length and attributes length checks** when it handles STUN packets, leading to controllable heap-over-flow. For example, in stun_parse_attribute(), after we get the attribute's type and length value, the length will be used directly to copy from the heap, regardless of the message's left size. Since network users control the overflowed length, and the data is written to heap chunks later, attackers may achieve remote code execution by heap groom

CVE-2023-34365
YF325 General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the libutils.so nvram_restore functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a buffer overflow. An attacker can send a network request to trigger this vulnerability.

CVE-2023-29728
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of privilege attack.

CVE-2023-50488
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2023 2 PoCs

An issue in Blurams Lumi Security Camera (A31C) v23.0406.435.4120 allows attackers to execute arbitrary code.

CVE-2023-30945
com.palantir.gotham:clips2 General
9.8
CRITICAL
EPSS
0.4%
2023 CWE-287 1 PoC

Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vulnerability due to missing input validation on filenames. A malicious attacker could read sensitive files from the filesystem or write/delete arbitrary files on the filesystem as well.

CVE-2023-24331
Software Genérico General
9.8
CRITICAL
EPSS
5.6%
2023 1 PoC

Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands via the urlAdd parameter.