9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-5395
Experion Server General
8.1
HIGH
EPSS
1.2%
2023 CWE-121 1 PoC

Server receiving a malformed message that uses the hostname in an internal table may cause a stack overflow resulting in possible remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-52043
Software Genérico General
8.1
HIGH
EPSS
0.1%
2023 1 PoC

An issue in D-Link COVR 1100, 1102, 1103 AC1200 Dual-Band Whole-Home Mesh Wi-Fi System (Hardware Rev B1) truncates Wireless Access Point Passwords (WPA-PSK) allowing an attacker to gain unauthorized network access via weak authentication controls.

CVE-2023-46694
Software Genérico General
8.1
HIGH
EPSS
9.1%
2023 1 PoC

Vtenext 21.02 allows an authenticated attacker to upload arbitrary files, potentially enabling them to execute remote commands. This flaw exists due to the application's failure to enforce proper authentication controls when accessing the Ckeditor file manager functionality.

CVE-2023-2942
openemr/openemr General
8.1
HIGH
EPSS
0.5%
2023 CWE-20 1 PoC

Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.1.

CVE-2023-50807
Software Genérico General
8.1
HIGH
EPSS
0.3%
2023 2 PoCs

A vulnerability was discovered in Samsung Wearable Processor and Modems with versions Exynos 9110, Exynos Modem 5123, Exynos Modem 5300 that allows an out-of-bounds write in the heap in 2G (no auth).

CVE-2023-23464
Media Control Panel General
8.1
HIGH
EPSS
0.2%
2023 1 PoC

Media CP Media Control Panel latest version. A Permissive Flash Cross-domain Policy may allow information disclosure.

CVE-2023-34217
TN-5900 Series General
8.1
HIGH
EPSS
0.2%
2023 CWE-22 1 PoC

TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability stems from insufficient input validation in the certificate-delete function, which could potentially allow malicious users to delete arbitrary files.

CVE-2023-43608
Buildroot General
8.1
HIGH
EPSS
0.1%
2023 CWE-494 2 PoCs

A data integrity vulnerability exists in the BR_NO_CHECK_HASH_FOR functionality of Buildroot 2023.08.1 and dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.

CVE-2023-47257
Software Genérico General
8.1
HIGH
EPSS
6.4%
2023 1 PoC

ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.

CVE-2023-44857
Software Genérico General
8.1
HIGH
EPSS
0.4%
2023 1 PoC

An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_21D24 function in the acu_web component.

CVE-2023-20938
Android General
8.1
HIGH
EPSS
0.2%
2023 1 PoC

In binder_transaction_buffer_release of binder.c, there is a possible use after free due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-257685302References: Upstream kernel

CVE-2023-26067
Software Genérico General ⚡ nuclei
8.1
HIGH
EPSS
93.0%
2023 2 PoCs

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).

CVE-2023-5397
Experion Server General
8.1
HIGH
EPSS
0.3%
2023 CWE-20 1 PoC

Server receiving a malformed message to create a new connection could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-31435
Software Genérico General
8.1
HIGH
EPSS
0.6%
2023 2 PoCs

Multiple components (such as Onlinetemplate-Verwaltung, Liste aller Teilbereiche, Umfragen anzeigen, and questionnaire previews) in evasys before 8.2 Build 2286 and 9.x before 9.0 Build 2401 allow authenticated attackers to read and write to unauthorized data by accessing functions directly.

CVE-2023-5353
salesagility/suitecrm General
8.1
HIGH
EPSS
0.1%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.

CVE-2023-3314
Enterprise Security Manager General
8.1
HIGH
EPSS
0.6%
2023 CWE-78 1 PoC

A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands used to control the process execution of the .zip application allows an authorized user to obtain control of the .zip application to execute arbitrary commands or obtain elevation of system privileges.

CVE-2023-23567
ImageGear General
8.1
HIGH
EPSS
0.2%
2023 CWE-119 1 PoC

A heap-based buffer overflow vulnerability exists in the CreateDIBfromPict functionality of Accusoft ImageGear 20.1. A specially crafted file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-5403
Experion Server General
8.1
HIGH
EPSS
1.0%
2023 CWE-121 1 PoC

Server hostname translation to IP address manipulation which could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-34998
OAS Platform General
8.1
HIGH
EPSS
0.0%
2023 CWE-319 1 PoC

An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary authentication. An attacker can sniff network traffic to trigger this vulnerability.

CVE-2023-45842
Buildroot General
8.1
HIGH
EPSS
0.1%
2023 CWE-494 2 PoCs

Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `mxsldr` package.