3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-51035
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

TOTOLINK EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution on the cstecgi.cgi NTPSyncWithHost interface.

CVE-2023-48121
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2023 1 PoC

An authentication bypass vulnerability in the Direct Connection Module in Ezviz CS-C6N-xxx prior to v5.3.x build 20230401, Ezviz CS-CV310-xxx prior to v5.3.x build 20230401, Ezviz CS-C6CN-xxx prior to v5.3.x build 20230401, Ezviz CS-C3N-xxx prior to v5.3.x build 20230401 allows remote attackers to obtain sensitive information by sending crafted messages to the affected devices.

CVE-2023-51028
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

TOTOLINK EX1800T 9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the apcliChannel parameter of the setWiFiExtenderConfig interface of the cstecgi.cgi.

CVE-2023-31923
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Suprema BioStar 2 before 2022 Q4, v2.9.1 has Insecure Permissions. A vulnerability in the web application allows an authenticated attacker with "User Operator" privileges to create a highly privileged user account. The vulnerability is caused by missing server-side validation, which can be exploited to gain full administrator privileges on the system.

CVE-2023-20810
MT5221, MT5583, MT5691, MT5695, MT9010, MT9011, MT9012, MT9016, MT9020, MT9021, MT9022, MT9030, MT9031, MT9032, MT9216, MT9218, MT9220, MT9221, MT9222, MT9255, MT9256, MT9266, MT9269, MT9286, MT9288, MT9602, MT9610, MT9611, MT9612, MT9613, MT9615, MT9617, MT9618, MT9629, MT9630, MT9631, MT9632, MT9636, MT9638, MT9639, MT9649, MT9650, MT9652, MT9653, MT9666, MT9667, MT9669, MT9671, MT9675, MT9685, MT9686, MT9688 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In IOMMU, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03692061; Issue ID: DTV03692061.

CVE-2023-3732
Chrome General
N/A
UNKNOWN
EPSS
0.9%
2023 1 PoC

Out of bounds memory access in Mojo in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-39321
crypto/tls General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Processing an incomplete post-handshake message for a QUIC connection can cause a panic.

CVE-2023-20519
3rd Gen AMD EPYC™ Processors General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's migration agent resulting in a potential loss of guest integrity.

CVE-2023-28871
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry information of the operating system by creating a symbolic link.

CVE-2023-39584
Software Genérico General
N/A
UNKNOWN
EPSS
4.1%
2023 1 PoC

Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability.

CVE-2023-39637
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2023 1 PoC

D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis.

CVE-2023-41444
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

An issue in Binalyze IREC.sys v.3.11.0 and before allows a local attacker to execute arbitrary code and escalate privileges via the fun_1400084d0 function in IREC.sys driver.

CVE-2023-21272
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 3 PoCs

In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-29537
Firefox for Android General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

CVE-2023-38334
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 4 PoCs

Omnis Studio 10.22.00 has incorrect access control. It advertises an irreversible feature for locking classes within Omnis libraries: it should be no longer possible to delete, view, change, copy, rename, duplicate, or print a locked class. Due to implementation issues, locked classes in Omnis libraries can be unlocked, and thus further analyzed and modified by Omnis Studio. This allows for further analyzing and also deleting, viewing, changing, copying, renaming, duplicating, or printing previously locked Omnis classes. This violates the expected behavior of an "irreversible operation."

CVE-2023-4047
Firefox General
N/A
UNKNOWN
EPSS
0.6%
2023 2 PoCs

A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVE-2023-29975
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.

CVE-2023-26258
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
79.4%
2023 5 PoCs

Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be used to execute any task as administrator.

CVE-2023-35687
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In MtpPropertyValue of MtpProperty.h, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-35826
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in cedrus_remove in drivers/staging/media/sunxi/cedrus/cedrus.c.