3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-33745
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Privilege Management: from the shell available after an adb connection, simply entering the su command provides root access (without requiring a password).

CVE-2023-4051
Firefox General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2.

CVE-2023-31716
Software Genérico General
N/A
UNKNOWN
EPSS
37.1%
2023 1 PoC

FUXA <= 1.1.12 has a Local File Inclusion vulnerability via file=fuxa.log

CVE-2023-46384
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. Cleartext storage of credentials allows remote attackers to disclose admin password and bypass an authentication to login Loytec device.

CVE-2023-24698
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Insufficient parameter validation in the Foswiki::Sandbox component of Foswiki v2.1.7 and below allows attackers to perform a directory traversal via supplying a crafted web request.

CVE-2023-21288
Android General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

In visitUris of Notification.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-45879
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

GibbonEdu Gibbon version 25.0.0 allows HTML Injection via an IFRAME element to the Messager component.

CVE-2023-45867
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

ILIAS (2013-09-12 release) contains a medium-criticality Directory Traversal local file inclusion vulnerability in the ScormAicc module. An attacker with a privileged account, typically holding the tutor role, can exploit this to gain unauthorized access to and potentially retrieve confidential files stored on the web server. The attacker can access files that are readable by the web server user www-data; this may include sensitive configuration files and documents located outside the documentRoot. The vulnerability is exploited by an attacker who manipulates the file parameter in a URL, inser

CVE-2023-33768
Software Genérico General
N/A
UNKNOWN
EPSS
2.1%
2023 2 PoCs

Incorrect signature verification of the firmware during the Device Firmware Update process of Belkin Wemo Smart Plug WSP080 v1.2 allows attackers to cause a Denial of Service (DoS) via a crafted firmware file.

CVE-2023-6204
Firefox General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on the canvas element. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

CVE-2023-33568
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.8%
2023 1 PoC

An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.

CVE-2023-20565
Ryzen™ 5000 Series Desktop Processor with Radeon™ Graphics “Cezanne” General
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.

CVE-2023-2989
Globalscape EFT General
N/A
UNKNOWN
EPSS
0.1%
2023 CWE-125 2 PoCs

Fortra Globalscape EFT versions before 8.1.0.16 suffer from an out of bounds memory read in their administration server, which can allow an attacker to crash the service or bypass authentication if successfully exploited

CVE-2023-48799
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2023 2 PoCs

TOTOLINK-X6000R Firmware-V9.4.0cu.852_B20230719 is vulnerable to Command Execution.

CVE-2023-44008
Software Genérico General
N/A
UNKNOWN
EPSS
9.4%
2023 1 PoC

File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.

CVE-2023-34625
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

ShowMojo MojoBox Digital Lockbox 1.4 is vulnerable to Authentication Bypass. The implementation of the lock opening mechanism via Bluetooth Low Energy (BLE) is vulnerable to replay attacks. A malicious user is able to intercept BLE requests and replicate them to open the lock at any time. Alternatively, an attacker with physical access to the device on which the Android app is installed, can obtain the latest BLE messages via the app logs and use them for opening the lock.

CVE-2023-40817
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

OpenCRX version 5.2.0 is vulnerable to HTML injection via the Product Configuration Name Field.

CVE-2023-50495
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().

CVE-2023-25261
Software Genérico General
N/A
UNKNOWN
EPSS
11.4%
2023 2 PoCs

Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023.1.4 and Stimulsoft Designer (Web) 2023.1.3 and Stimulsoft Viewer (Web) 2023.1.3. Access to the local file system is not prohibited in any way. Therefore, an attacker may include source code which reads or writes local directories and files. It is also possible for the attacker to prepare a report which has a variable that holds the gathered data and render it in the report.

CVE-2023-46574
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2023 0 PoCs

An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.