1450 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-29017
vm2 General
10.0
CRITICAL
EPSS
75.0%
2023 CWE-913 3 PoCs

vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Prior to version 3.9.15, vm2 was not properly handling host objects passed to `Error.prepareStackTrace` in case of unhandled async errors. A threat actor could bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.15 of vm2. There are no known workarounds.

CVE-2023-48418
Pixel Watch General
10.0
CRITICAL
EPSS
0.0%
2023 CWE-269 1 PoC

In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a     possible way to access adb before SUW completion due to an insecure default     value. This could lead to local escalation of privilege with no additional     execution privileges needed. User interaction is not needed for     exploitation

CVE-2023-6977
mlflow/mlflow General ⚡ nuclei
10.0
CRITICAL
EPSS
83.0%
2023 CWE-29 1 PoC

This vulnerability enables malicious users to read sensitive files on the server.

CVE-2023-3765
mlflow/mlflow General ⚡ nuclei
10.0
CRITICAL
EPSS
91.5%
2023 CWE-36 1 PoC

Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.

CVE-2023-7309
Smart Park Integrated Management Platform General
10.0
CRITICAL
EPSS
2.1%
2023 CWE-434 2 PoCs

A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated Management Platform), affecting the SOAP-based GIS bitmap upload interface. The flaw allows unauthenticated remote attackers to upload arbitrary files to the server via crafted SOAP requests, including executable JSP payloads. Successful exploitation may lead to remote code execution (RCE) and full compromise of the affected system. The vulnerability is presumed to affect builds released prior to September 2023 and is said to be remediated in newer

CVE-2023-35082
🔥 KEV EPMM General ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2023 1 PoC

An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

CVE-2023-22527
🔥 KEV Confluence Data Center General ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2023 27 PoCs

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.

CVE-2023-2356
mlflow/mlflow General ⚡ nuclei
10.0
CRITICAL
EPSS
90.5%
2023 CWE-23 1 PoC

Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1.

CVE-2023-2564
sbs20/scanservjs General
10.0
CRITICAL
EPSS
29.3%
2023 CWE-78 1 PoC

OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0.

CVE-2023-2583
jsreport/jsreport General
10.0
CRITICAL
EPSS
0.1%
2023 CWE-94 1 PoC

Code Injection in GitHub repository jsreport/jsreport prior to 3.11.3.

CVE-2023-40044
🔥 KEV WS_FTP Server General ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2023 CWE-502 6 PoCs

In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.

CVE-2023-41094
Ember ZNet General
10.0
CRITICAL
EPSS
0.1%
2023 CWE-940 1 PoC

TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing duration This issue affects Ember ZNet 7.1.x from 7.1.3 through 7.1.5; 7.2.x from 7.2.0 through 7.2.3; Version 7.3 and later are unaffected

CVE-2023-42770
ST-IPm-8460 General
10.0
CRITICAL
EPSS
0.2%
2023 CWE-288 1 PoC

Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message is received over TCP/IP the RTU will simply accept the message with no authentication challenge.

CVE-2023-6016
h2oai/h2o-3 General
10.0
CRITICAL
EPSS
68.2%
2023 CWE-94 1 PoC

An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature.

CVE-2023-2138
nuxtlabs/github-module General
10.0
CRITICAL
EPSS
0.4%
2023 CWE-798 1 PoC

Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2.

CVE-2023-4804
Quantum HD Unity Compressor General
10.0
CRITICAL
EPSS
0.1%
2023 CWE-489 1 PoC

An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.

CVE-2023-6018
mlflow/mlflow General ⚡ nuclei
10.0
CRITICAL
EPSS
91.3%
2023 CWE-78 0 PoCs

An attacker can overwrite any file on the server hosting MLflow without any authentication.

CVE-2023-1523
snapd General
10.0
CRITICAL
EPSS
0.1%
2023 1 PoC

Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed outside of the snap sandbox after the snap exits. Graphical terminal emulators like xterm, gnome-terminal and others are not affected - this can only be exploited when snaps are run on a virtual console.

CVE-2023-51409
AI Engine: ChatGPT Chatbot General ⚡ nuclei
10.0
CRITICAL
EPSS
92.9%
2023 CWE-434 4 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 1.9.98.

CVE-2023-2024
OpenBlue Enterprise Manager Data Collector General
10.0
CRITICAL
EPSS
0.3%
2023 CWE-287 2 PoCs

Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances.