3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-40930
Software Genérico General
N/A
UNKNOWN
EPSS
13.2%
2023 1 PoC

An issue in the directory /system/bin/blkid of Skyworth v3.0 allows attackers to perform a directory traversal via mounting the Udisk to /mnt/.

CVE-2023-39669
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

D-Link DIR-880 A1_FW107WWb08 was discovered to contain a NULL pointer dereference in the function FUN_00010824.

CVE-2023-38829
Software Genérico General
N/A
UNKNOWN
EPSS
14.2%
2023 2 PoCs

An issue in NETIS SYSTEMS WF2409E v.3.6.42541 allows a remote attacker to execute arbitrary code via the ping and traceroute functions of the diagnostic tools component in the admin management interface.

CVE-2023-40429
iOS and iPadOS General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

A permissions issue was addressed with improved validation. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. An app may be able to access sensitive user data.

CVE-2023-36670
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

A remotely exploitable command injection vulnerability was found on the Kratos NGC-IDU 9.1.0.4. An attacker can execute arbitrary Linux commands as root by sending crafted TCP requests to the device.

CVE-2023-38840
Software Genérico General
N/A
UNKNOWN
EPSS
2.4%
2023 1 PoC

Bitwarden Desktop 2023.7.0 and below allows an attacker with local access to obtain sensitive information via the Bitwarden.exe process.

CVE-2023-41635
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A XML External Entity (XXE) vulnerability in the VerifichePeriodiche.aspx component of GruppoSCAI RealGimm v1.1.37p38 allows attackers to read any file in the filesystem via supplying a crafted XML file.

CVE-2023-26613
Software Genérico General
N/A
UNKNOWN
EPSS
63.5%
2023 1 PoC

An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorized attackers to execute arbitrary operating system commands via a crafted GET request to EXCU_SHELL.

CVE-2023-36618
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2023 2 PoCs

Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-privileged authenticated users.

CVE-2023-38354
Software Genérico General
N/A
UNKNOWN
EPSS
6.0%
2023 1 PoC

MiniTool Shadow Maker version 4.1 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

CVE-2023-51202
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

Sin descripción disponible.

CVE-2023-46387
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Incorrect Access Control via dpal_config.zml file. This vulnerability allows remote attackers to disclose sensitive information on Loytec device data point configuration.

CVE-2023-49438
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2023 1 PoC

An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspecting users to malicious sites via a crafted URL by abusing the ?next parameter on the /login and /register routes.

CVE-2023-24609
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Matrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension parsing in the TLS 1.3 server. An attacked device calculates an SHA-2 hash over at least 65 KB (in RAM). With a large number of crafted TLS messages, the CPU becomes heavily loaded. This occurs in tls13VerifyBinder and tls13TranscriptHashUpdate.

CVE-2023-43115
Software Genérico General
N/A
UNKNOWN
EPSS
21.7%
2023 1 PoC

In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the IJS server can be specified on a gs command line (the IJS device inherently must execute a command to start the IJS server).

CVE-2023-40039
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame.

CVE-2023-51199
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

Sin descripción disponible.

CVE-2023-34931
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A stack overflow in the EditWlanMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2023-36664
Software Genérico General
N/A
UNKNOWN
EPSS
6.4%
2023 4 PoCs

Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).

CVE-2023-21253
Android General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

In multiple locations, there is a possible way to crash multiple system services due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.