3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-4744
AC8 General
9.8
CRITICAL
EPSS
0.4%
2023 CWE-121 1 PoC

A vulnerability was found in Tenda AC8 16.03.34.06_cn_TDC01. It has been declared as critical. Affected by this vulnerability is the function formSetDeviceName. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-238633 was assigned to this vulnerability.

CVE-2023-39979
MXsecurity Series General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-334 1 PoC

There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication. A remote attacker might access the system if the web service authenticator has insufficient random values.  

CVE-2023-27648
Software Genérico General
9.8
CRITICAL
EPSS
6.0%
2023 1 PoC

Directory Traversal vulnerability found in T-ME Studios Change Color of Keypad v.1.275.1.277 allows a remote attacker to execute arbitrary code via the dex file in the internal storage.

CVE-2023-27650
Software Genérico General
9.8
CRITICAL
EPSS
3.6%
2023 1 PoC

An issue found in APUS Group Launcher v.3.10.73 and v.3.10.88 allows a remote attacker to execute arbitrary code via the FONT_FILE parameter.

CVE-2023-27388
T&D Corporation and ESPEC MIC CORP. data logger products General
9.8
CRITICAL
EPSS
1.0%
2023 1 PoC

Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login to the product as a registered user. Affected products and versions are as follows: T&D Corporation data logger products (TR-71W/72W all firmware versions, RTR-5W all firmware versions, WDR-7 all firmware versions, WDR-3 all firmware versions, and WS-2 all firmware versions), and ESPEC MIC CORP. data logger products (RT-12N/RS-12N all firmware versions, RT-22BN all firmware versions, and TEU-12N all firmware versions).

CVE-2023-46485
Software Genérico General
9.8
CRITICAL
EPSS
4.6%
2023 1 PoC

An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setTracerouteCfg function of the stecgi.cgi component.

CVE-2023-37999
HT Mega General ⚡ nuclei
9.8
CRITICAL
EPSS
53.8%
2023 CWE-269 0 PoCs

Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega: from n/a through 2.2.0.

CVE-2023-51968
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function getIptvInfo.

CVE-2023-32225
Sysaid General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-434 1 PoC

Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type -  A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method.

CVE-2023-26068
Software Genérico General
9.8
CRITICAL
EPSS
81.3%
2023 1 PoC

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).

CVE-2023-42374
Software Genérico General
9.8
CRITICAL
EPSS
2.8%
2023 3 PoCs

An issue in mystenlabs Sui Blockchain before v.1.6.3 allow a remote attacker to execute arbitrary code and cause a denial of service via a crafted compressed script to the Sui node component.

CVE-2023-26999
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file.

CVE-2023-25178
C300 General
9.8
CRITICAL
EPSS
1.3%
2023 CWE-345 1 PoC

Controller may be loaded with malicious firmware which could enable remote code execution. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-1133
InfraSuite Device Master General
9.8
CRITICAL
EPSS
86.1%
2023 1 PoC

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary code.

CVE-2023-28879
Software Genérico General
9.8
CRITICAL
EPSS
34.2%
2023 2 PoCs

In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.

CVE-2023-29739
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 2 PoCs

An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the component.

CVE-2023-30945
com.palantir.gotham:clips2 General
9.8
CRITICAL
EPSS
0.4%
2023 CWE-287 1 PoC

Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vulnerability due to missing input validation on filenames. A malicious attacker could read sensitive files from the filesystem or write/delete arbitrary files on the filesystem as well.

CVE-2023-24800
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_495220 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-24331
Software Genérico General
9.8
CRITICAL
EPSS
5.6%
2023 1 PoC

Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands via the urlAdd parameter.