3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-47321
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control via the "Porlet Deployer" which allows administrators to deploy .WAR portlets.

CVE-2023-20796
MT2735, MT2737, MT6789, MT6833, MT6835, MT6853, MT6855, MT6873, MT6877, MT6879, MT6880, MT6886, MT6890, MT6893, MT6895, MT6980, MT6983, MT6985, MT6990, MT8168, MT8321, MT8768, MT8781, MT8786 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In power, there is a possible memory corruption due to an incorrect bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929790; Issue ID: ALPS07929790.

CVE-2023-6350
Chrome General
N/A
UNKNOWN
EPSS
1.2%
2023 1 PoC

Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)

CVE-2023-33570
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).

CVE-2023-20789
MT6789, MT6835, MT6855, MT6879, MT6886, MT6895, MT6983, MT6985, MT8188, MT8195, MT8195Z General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In jpeg, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07693193; Issue ID: ALPS07693193.

CVE-2023-37306
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.

CVE-2023-28868
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operating system by creating a symbolic link.

CVE-2023-43861
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2023 1 PoC

D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanPPPoE function.

CVE-2023-45252
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

DLL Hijacking vulnerability in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, due to the installation of the service in a directory that grants write privileges to standard users, allows attackers to manipulate files, execute arbitrary code, and escalate privileges.

CVE-2023-36109
Software Genérico General
N/A
UNKNOWN
EPSS
20.4%
2023 2 PoCs

Buffer Overflow vulnerability in JerryScript version 3.0, allows remote attackers to execute arbitrary code via ecma_stringbuilder_append_raw component at /jerry-core/ecma/base/ecma-helpers-string.c.

CVE-2023-42334
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

An Indirect Object Reference (IDOR) in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to escalate privileges via the user parameter.

CVE-2023-43868
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via websGetVar function.

CVE-2023-38412
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Netgear R6900P v1.3.3.154 was discovered to contain multiple buffer overflows via the wla_ssid and wlg_ssid parameters at ia_ap_setting.cgi.

CVE-2023-51198
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

Sin descripción disponible.

CVE-2023-22956
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 4 PoCs

An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to decrypt encrypted configuration files and retrieve sensitive information.

CVE-2023-39320
cmd/go General
N/A
UNKNOWN
EPSS
0.8%
2023 2 PoCs

The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command from the module proxy, as well as modules downloaded directly using VCS software.

CVE-2023-39668
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the inet_ntoa() function.

CVE-2023-27253
Software Genérico General
N/A
UNKNOWN
EPSS
77.7%
2023 1 PoC

A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.

CVE-2023-34836
Software Genérico General
N/A
UNKNOWN
EPSS
2.1%
2023 2 PoCs

A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Dtltyp and ListName parameters.

CVE-2023-38970
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the Name of member parameter in the add new member function.