3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-37755
Software Genérico General
N/A
UNKNOWN
EPSS
1.4%
2023 4 PoCs

i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or prompt to ask users to change the default password and account name. Unauthenticated attackers can exploit this vulnerability to obtain Administrator privileges, resulting in them being able to perform arbitrary system operations or cause a Denial of Service (DoS).

CVE-2023-39750
Software Genérico General
N/A
UNKNOWN
EPSS
50.5%
2023 1 PoC

D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the f_ipv6_enable parameter at /bsc_ipv6. This vulnerability is exploited via a crafted POST request.

CVE-2023-31704
Software Genérico General
N/A
UNKNOWN
EPSS
1.6%
2023 2 PoCs

Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate privileges to the administrator's role.

CVE-2023-51765
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2023 2 PoCs

sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports <LF>.<CR><LF> but some other popular e-mail servers do not. This is resolved in 8.18 and later versions with 'o' in srv_features.

CVE-2023-34843
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2023 3 PoCs

Traggo Server 0.3.0 is vulnerable to directory traversal via a crafted GET request.

CVE-2023-37790
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 2 PoCs

Jaspersoft Clarity PPM version 14.3.0.298 was discovered to contain an arbitrary file upload vulnerability via the Profile Picture Upload function.

CVE-2023-48835
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.

CVE-2023-38909
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the IV component in the AES128-CBC function.

CVE-2023-42469
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The com.full.dialer.top.secure.encrypted application through 1.0.1 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.full.dialer.top.secure.encrypted.activities.DialerActivity component.

CVE-2023-45852
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2023 0 PoCs

In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell metacharacters in the ipaddr params JSON data for the put method.

CVE-2023-32522
Trend Micro Moibile Security for Enterprise General
N/A
UNKNOWN
EPSS
0.9%
2023 1 PoC

A path traversal exists in a specific dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an authenticated remote attacker to delete arbitrary files. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

CVE-2023-40296
Software Genérico General
N/A
UNKNOWN
EPSS
2.6%
2023 1 PoC

async-sockets-cpp through 0.3.1 has a stack-based buffer overflow in ReceiveFrom and Receive in udpsocket.hpp when processing malformed UDP packets.

CVE-2023-35671
Android General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read the full card number and expiry details when the device is in locked screen mode due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-37754
Software Genérico General
N/A
UNKNOWN
EPSS
59.6%
2023 1 PoC

PowerJob v4.3.3 was discovered to contain a remote command execution (RCE) vulnerability via the instanceId parameter at /instance/detail.

CVE-2023-37800
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Sin descripción disponible.

CVE-2023-46916
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Maxima Max Pro Power 1.0 486A devices allow BLE traffic replay. An attacker can use GATT characteristic handle 0x0012 to perform potentially disruptive actions such as starting a Heart Rate monitor.

CVE-2023-47321
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control via the "Porlet Deployer" which allows administrators to deploy .WAR portlets.

CVE-2023-20796
MT2735, MT2737, MT6789, MT6833, MT6835, MT6853, MT6855, MT6873, MT6877, MT6879, MT6880, MT6886, MT6890, MT6893, MT6895, MT6980, MT6983, MT6985, MT6990, MT8168, MT8321, MT8768, MT8781, MT8786 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In power, there is a possible memory corruption due to an incorrect bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929790; Issue ID: ALPS07929790.

CVE-2023-6350
Chrome General
N/A
UNKNOWN
EPSS
1.2%
2023 1 PoC

Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)

CVE-2023-33570
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).