3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-46661
PolyEco1000 General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-284 1 PoC

Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests.

CVE-2023-29741
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause an escalation of privileges attack by manipulating the database.

CVE-2023-25367
Software Genérico General
9.8
CRITICAL
EPSS
4.8%
2023 1 PoC

Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS allows unfiltered user input resulting in Remote Code Execution (RCE) with SCPI interface or web server.

CVE-2023-51954
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv.

CVE-2023-51952
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.

CVE-2023-42000
Arcserve UDP General
9.8
CRITICAL
EPSS
1.2%
2023 CWE-22 1 PoC

Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthenticated remote attacker can exploit it to upload arbitrary files to any location on the file system where the UDP agent is installed.

CVE-2023-46484
Software Genérico General
9.8
CRITICAL
EPSS
4.6%
2023 1 PoC

An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setLedCfg function.

CVE-2023-38389
JupiterX Core General
9.8
CRITICAL
EPSS
11.8%
2023 CWE-863 1 PoC

Incorrect Authorization vulnerability in Artbees JupiterX Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JupiterX Core: from n/a through 3.3.8.

CVE-2023-39453
ImageGear General
9.8
CRITICAL
EPSS
0.4%
2023 CWE-416 1 PoC

A use-after-free vulnerability exists in the tif_parse_sub_IFD functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can deliver this file to trigger this vulnerability.

CVE-2023-33669
Software Genérico General
9.8
CRITICAL
EPSS
30.9%
2023 1 PoC

Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the timeZone parameter in the sub_44db3c function.

CVE-2023-33443
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attackers to execute arbitrary administrative commands via a crafted payload sent to the desired endpoints.

CVE-2023-25770
C300 General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-502 1 PoC

Controller DoS may occur due to buffer overflow when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-3638
GV-ADR2701 General
9.8
CRITICAL
EPSS
0.2%
2023 CWE-287 1 PoC

In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application.

CVE-2023-23461
Libpeconv General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

Libpeconv – access violation, before commit b076013 (30/11/2022).

CVE-2023-29861
Software Genérico General
9.8
CRITICAL
EPSS
2.6%
2023 1 PoC

An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the management page of the device.

CVE-2023-46980
Software Genérico General
9.8
CRITICAL
EPSS
7.5%
2023 3 PoCs

An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the userID parameter.

CVE-2023-51965
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function setIptvInfo.

CVE-2023-51957
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv.

CVE-2023-49693
NETGEAR ProSAFE Network Management System General
9.8
CRITICAL
EPSS
0.7%
2023 CWE-306 2 PoCs

NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticated users, allowing attackers to execute arbitrary code.

CVE-2023-28501
UniData General
9.8
CRITICAL
EPSS
2.0%
2023 CWE-190 1 PoC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based buffer overflow in the unirpcd daemon that, if successfully exploited, can lead to remote code execution as the root user.