9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-0861
NSRW General
7.2
HIGH
EPSS
2.3%
2023 CWE-77 1 PoC

NetModule NSRW web administration interface executes an OS command constructed with unsanitized user input. A successful exploit could allow an authenticated user to execute arbitrary commands with elevated privileges. This issue affects NSRW: from 4.3.0.0 before 4.3.0.119, from 4.4.0.0 before 4.4.0.118, from 4.6.0.0 before 4.6.0.105, from 4.7.0.0 before 4.7.0.103.

CVE-2023-23773
EBTS/MBTS Base Radio General
7.2
HIGH
EPSS
0.0%
2023 CWE-347 1 PoC

Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device.

CVE-2023-39171
Storage Box V1 General
7.2
HIGH
EPSS
0.2%
2023 CWE-668 2 PoCs

SENEC Storage Box V1,V2 and V3 accidentially expose a management UI accessible with publicly known admin credentials.

CVE-2023-1477
Keycloak Authenticator Extension General
7.2
HIGH
EPSS
0.4%
2023 CWE-287 1 PoC

Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak Authenticator Extension: before 7.10.2, before 8.0.3.

CVE-2023-36921
SAP Solution Manager (Diagnostic Agent) General
7.2
HIGH
EPSS
0.4%
2023 CWE-644 1 PoC

SAP Solution Manager (Diagnostics agent) - version 7.20, allows an attacker to tamper with headers in a client request. This misleads SAP Diagnostics Agent to serve poisoned content to the server. On successful exploitation, the attacker can cause a limited impact on confidentiality and availability of the application.

CVE-2023-33637
Software Genérico General
7.2
HIGH
EPSS
0.1%
2023 1 PoC

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the DelDNSHnList interface at /goform/aspForm.

CVE-2023-0640
TEW-652BRP General
7.2
HIGH
EPSS
0.9%
2023 CWE-77 1 PoC

A vulnerability was found in TRENDnet TEW-652BRP 3.04b01. It has been classified as critical. Affected is an unknown function of the file ping.ccp of the component Web Interface. The manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220020.

CVE-2023-45686
Titan MFT General
7.2
HIGH
EPSS
0.5%
2023 CWE-22 1 PoC

Insufficient path validation when writing a file via WebDAV in South River Technologies' Titan MFT and Titan SFTP servers on Linux allows an authenticated attacker to write a file to any location on the filesystem via path traversal

CVE-2023-22306
UR32L General
7.2
HIGH
EPSS
0.3%
2023 CWE-77 2 PoCs

An OS command injection vulnerability exists in the libzebra.so bridge_group functionality of Milesight UR32L v32.3.0.5. A specially crafted network packet can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-27498
Host Agent (SAPOSCOL) General
7.2
HIGH
EPSS
0.4%
2023 CWE-121 1 PoC

SAP Host Agent (SAPOSCOL) - version 7.22, allows an unauthenticated attacker with network access to a server port assigned to the SAP Start Service to submit a crafted request which results in a memory corruption error. This error can be used to reveal but not modify any technical information about the server. It can also make a particular service temporarily unavailable

CVE-2023-49978
Software Genérico General
7.2
HIGH
EPSS
0.5%
2023 2 PoCs

Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for administrators.

CVE-2023-33919
CP-8031 MASTER MODULE General
7.2
HIGH
EPSS
9.8%
2023 CWE-77 4 PoCs

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.

CVE-2023-48270
WBR-6013 General
7.2
HIGH
EPSS
0.5%
2023 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in the boa formDnsv6 functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-49593
WBR-6013 General
7.2
HIGH
EPSS
0.3%
2023 CWE-489 2 PoCs

Leftover debug code exists in the boa formSysCmd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A specially crafted network request can lead to arbitrary command execution.

CVE-2023-39201
CleanZoom General
7.2
HIGH
EPSS
0.1%
2023 CWE-426 1 PoC

Untrusted search path in CleanZoom before file date 07/24/2023 may allow a privileged user to conduct an escalation of privilege via local access.

CVE-2023-25583
UR32L General
7.2
HIGH
EPSS
0.3%
2023 CWE-78 2 PoCs

Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the code branch that manages a new vlan configuration.

CVE-2023-26609
Software Genérico General
7.2
HIGH
EPSS
37.2%
2023 4 PoCs

ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin/mft/wireless_mft ap field.

CVE-2023-2554
unilogies/bumsys General
7.2
HIGH
EPSS
2.2%
2023 CWE-73 1 PoC

External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0.

CVE-2023-45215
WBR-6013 General
7.2
HIGH
EPSS
0.3%
2023 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in the boa setRepeaterSsid functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-40289
Software Genérico General
7.2
HIGH
EPSS
2.7%
2023 2 PoCs

A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevate privileges from a user with BMC administrative privileges.