9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-29800
Software Genérico General
9.8
CRITICAL
EPSS
14.9%
2023 1 PoC

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.

CVE-2023-51956
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv

CVE-2023-43364
Software Genérico General
9.8
CRITICAL
EPSS
29.6%
2023 1 PoC

main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.

CVE-2023-6232
Satera LBP670C Series General
9.8
CRITICAL
EPSS
0.4%
2023 CWE-787 2 PoCs

Buffer overflow in the Address Book username process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmwar

CVE-2023-32243
Essential Addons for Elementor General ⚡ nuclei
9.8
CRITICAL
EPSS
93.6%
2023 CWE-287 11 PoCs

Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1.

CVE-2023-5175
Firefox General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

During process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed from a different codepath, leading to a potentially exploitable crash. This vulnerability affects Firefox < 118.

CVE-2023-40163
ImageGear General
9.8
CRITICAL
EPSS
0.2%
2023 CWE-787 1 PoC

An out-of-bounds write vulnerability exists in the allocate_buffer_for_jpeg_decoding functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-27823
Software Genérico General
9.8
CRITICAL
EPSS
1.9%
2023 1 PoC

An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.

CVE-2023-42495
Dasan Networks General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-78 1 PoC

Dasan Networks - W-Web versions 1.22-1.27 - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVE-2023-43131
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

General Device Manager 2.5.2.2 is vulnerable to Buffer Overflow.

CVE-2023-27350
🔥 KEV NG General ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2023 CWE-284 20 PoCs

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from improper access control. An attacker can leverage this vulnerability to bypass authentication and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18987.

CVE-2023-29739
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 2 PoCs

An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the component.

CVE-2023-39169
Storage Box V1 General
9.8
CRITICAL
EPSS
0.4%
2023 CWE-798 2 PoCs

The affected devices use publicly available default credentials with administrative privileges.

CVE-2023-30280
Software Genérico General
9.8
CRITICAL
EPSS
4.5%
2023 1 PoC

Buffer Overflow vulnerability found in Netgear R6900 v.1.0.2.26, R6700v3 v.1.0.4.128, R6700 v.1.0.0.26 allows a remote attacker to execute arbitrary code and cause a denial ofservice via the getInputData parameter of the fwSchedule.cgi page.

CVE-2023-5642
R-SeeNet General
9.8
CRITICAL
EPSS
41.8%
2023 CWE-200 1 PoC

Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive information.

CVE-2023-4744
AC8 General
9.8
CRITICAL
EPSS
0.4%
2023 CWE-121 1 PoC

A vulnerability was found in Tenda AC8 16.03.34.06_cn_TDC01. It has been declared as critical. Affected by this vulnerability is the function formSetDeviceName. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-238633 was assigned to this vulnerability.

CVE-2023-1698
Compact Controller CC100 General ⚡ nuclei
9.8
CRITICAL
EPSS
93.8%
2023 CWE-78 6 PoCs

In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.

CVE-2023-0851
Canon Office/Small Office Multifunction Printers and Laser Printers General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-122 1 PoC

Buffer overflow in CPCA Resource Download process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i fir

CVE-2023-30013
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
92.4%
2023 1 PoC

TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.