3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-42882
macOS General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2. Processing an image may lead to arbitrary code execution.

CVE-2023-47271
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

PKP-WAL (aka PKP Web Application Library or pkp-lib) before 3.3.0-16, as used in Open Journal Systems (OJS) and other products, does not verify that the file named in an XML document (used for the native import/export plugin) is an image file, before trying to use it for an issue cover image.

CVE-2023-26510
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Ghost 5.35.0 allows authorization bypass: contributors can view draft posts of other users, which is arguably inconsistent with a security policy in which a contributor's draft can only be read by editors until published by an editor. NOTE: the vendor's position is that this behavior has no security impact.

CVE-2023-6206
Firefox General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

CVE-2023-36095
Software Genérico General
N/A
UNKNOWN
EPSS
3.1%
2023 1 PoC

An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affected functions include from_math_prompt and from_colored_object_prompt.

CVE-2023-37605
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Weak Exception Handling vulnerability in baramundi software GmbH EMM Agent 23.1.50 and before allows an attacker to cause a denial of service via a crafted request to the password parameter.

CVE-2023-37621
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Sin descripción disponible.

CVE-2023-34930
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A stack overflow in the EditMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2023-24127
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey1 parameter at /goform/WifiBasicSet.

CVE-2023-36355
Software Genérico General
N/A
UNKNOWN
EPSS
34.3%
2023 1 PoC

TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

CVE-2023-51011
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanPriDns parameter’ of the setLanConfig interface of the cstecgi .cgi

CVE-2023-24132
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a stack overflow via the wepkey3_5g parameter at /goform/WifiBasicSet.

CVE-2023-45208
Software Genérico General
N/A
UNKNOWN
EPSS
1.6%
2023 1 PoC

A command injection in the parsing_xml_stasurvey function inside libcgifunc.so of the D-Link DAP-X1860 repeater 1.00 through 1.01b05-01 allows attackers (within range of the repeater) to run shell commands as root during the setup process of the repeater, via a crafted SSID. Also, network names containing single quotes (in the range of the repeater) can result in a denial of service.

CVE-2023-39141
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
85.6%
2023 2 PoCs

webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.

CVE-2023-36266
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

An issue was discovered in Keeper Password Manager for Desktop version 16.10.2 (fixed in 17.2), and the KeeperFill Browser Extensions version 16.5.4 (fixed in 17.2), allows local attackers to gain sensitive information via plaintext password storage in memory after the user is already logged in, and may persist after logout. NOTE: the vendor disputes this for two reasons: the information is inherently available during a logged-in session when the attacker can read from arbitrary memory locations, and information only remains available after logout because of memory-management limitations of we

CVE-2023-34569
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list at /goform/SetNetControlList.

CVE-2023-23294
Software Genérico General
N/A
UNKNOWN
EPSS
2.9%
2023 1 PoC

Korenix JetWave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection. An attacker can modify the file_name parameter to execute commands as root.

CVE-2023-43252
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow via a crafted image file.

CVE-2023-40123
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In updateActionViews of PipMenuView.java, there is a possible bypass of a multi user security boundary due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-45540
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

An issue in Jorani Leave Management System 1.0.3 allows a remote attacker to execute arbitrary HTML code via a crafted script to the comment field of the List of Leave requests page.