9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-39979
MXsecurity Series General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-334 1 PoC

There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication. A remote attacker might access the system if the web service authenticator has insufficient random values.  

CVE-2023-25366
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

In Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS, insecure SCPI interface discloses web password.

CVE-2023-0744
answerdev/answer General
9.8
CRITICAL
EPSS
8.5%
2023 CWE-284 2 PoCs

Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4.

CVE-2023-7227
NVR 504 General
9.8
CRITICAL
EPSS
0.7%
2023 CWE-77 1 PoC

SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command injection vulnerability in the dynamic domain name system (DDNS) settings that could allow an attacker to execute arbitrary commands with root privileges.

CVE-2023-32225
Sysaid General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-434 1 PoC

Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type -  A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method.

CVE-2023-26068
Software Genérico General
9.8
CRITICAL
EPSS
81.3%
2023 1 PoC

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).

CVE-2023-5347
JetNet Series General
9.8
CRITICAL
EPSS
0.2%
2023 CWE-347 3 PoCs

An Improper Verification of Cryptographic Signature vulnerability in the update process of Korenix JetNet Series allows replacing the whole operating system including Trusted Executables. This issue affects JetNet devices older than firmware version 2024/01.

CVE-2023-51972
Software Genérico General
9.8
CRITICAL
EPSS
3.8%
2023 1 PoC

Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp.

CVE-2023-4696
usememos/memos General
9.8
CRITICAL
EPSS
1.3%
2023 CWE-284 2 PoCs

Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.

CVE-2023-30869
Easy Digital Downloads General ⚡ nuclei
9.8
CRITICAL
EPSS
50.1%
2023 CWE-287 0 PoCs

Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue affects Easy Digital Downloads: from 3.1 through 3.1.1.4.1.

CVE-2023-23461
Libpeconv General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

Libpeconv – access violation, before commit b076013 (30/11/2022).

CVE-2023-46665
PolyEco1000 General
9.8
CRITICAL
EPSS
0.0%
2023 CWE-284 1 PoC

Sielco PolyEco1000 is vulnerable to an authentication bypass vulnerability due to an attacker modifying passwords in a POST request and gain unauthorized access to the affected device with administrative privileges.

CVE-2023-42000
Arcserve UDP General
9.8
CRITICAL
EPSS
1.2%
2023 CWE-22 1 PoC

Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthenticated remote attacker can exploit it to upload arbitrary files to any location on the file system where the UDP agent is installed.

CVE-2023-46484
Software Genérico General
9.8
CRITICAL
EPSS
4.6%
2023 1 PoC

An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setLedCfg function.

CVE-2023-25770
C300 General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-502 1 PoC

Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-33443
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attackers to execute arbitrary administrative commands via a crafted payload sent to the desired endpoints.

CVE-2023-42769
Analog FM transmitter General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-284 2 PoCs

The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.