9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-25178
C300 General
9.8
CRITICAL
EPSS
1.3%
2023 CWE-345 1 PoC

Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-51954
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv.

CVE-2023-29861
Software Genérico General
9.8
CRITICAL
EPSS
2.6%
2023 1 PoC

An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the management page of the device.

CVE-2023-23462
Libpeconv General
9.8
CRITICAL
EPSS
0.4%
2023 CWE-190 1 PoC

Libpeconv – integer overflow, before commit 75b1565 (30/11/2022).

CVE-2023-0852
Canon Office/Small Office Multifunction Printers and Laser Printers General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-121 1 PoC

Buffer overflow in the Address Book of Mobile Device function of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF

CVE-2023-31729
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2023 1 PoC

TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.

CVE-2023-29805
Software Genérico General
9.8
CRITICAL
EPSS
12.2%
2023 1 PoC

WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function.

CVE-2023-34800
Software Genérico General
9.8
CRITICAL
EPSS
63.5%
2023 1 PoC

D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main.

CVE-2023-7017
Kontrol Lux General
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low Energy service. A challenge request can be sent to the lock with a command to prepare for an update, rather than an unlock request, allowing an attacker to compromise the device.

CVE-2023-36281
Software Genérico General
9.8
CRITICAL
EPSS
62.2%
2023 3 PoCs

An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This is related to __subclasses__ or a template.

CVE-2023-32227
SYnergy Fingerprint Terminals General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-798 1 PoC

Synel SYnergy Fingerprint Terminals - CWE-798: Use of Hard-coded Credentials

CVE-2023-44353
ColdFusion General ⚡ nuclei
9.8
CRITICAL
EPSS
89.4%
2023 CWE-502 1 PoC

Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

CVE-2023-27720
Software Genérico General
9.8
CRITICAL
EPSS
1.7%
2023 1 PoC

D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_48d630 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-45911
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

An issue in WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 allows unauthenticated attackers to login as any user without a password.

CVE-2023-25220
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the add_white_node function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-25280
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
93.1%
2023 1 PoC

OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.

CVE-2023-51963
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo.

CVE-2023-46359
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
93.0%
2023 0 PoCs

An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on the system via a specifically crafted arguments passed to the connectivity check feature.

CVE-2023-48010
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

STMicroelectronics SPC58 is vulnerable to Missing Protection Mechanism for Alternate Hardware Interface. Code running as Supervisor on the SPC58 PowerPC microcontrollers may disable the System Memory Protection Unit and gain unabridged read/write access to protected assets.