3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-34836
Software Genérico General
N/A
UNKNOWN
EPSS
2.1%
2023 2 PoCs

A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Dtltyp and ListName parameters.

CVE-2023-38970
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the Name of member parameter in the add new member function.

CVE-2023-38998
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

An open redirect in the Login page of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL.

CVE-2023-28864
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Progress Chef Infra Server before 15.7 allows a local attacker to exploit a /var/opt/opscode/local-mode-cache/backup world-readable temporary backup path to access sensitive information, resulting in the disclosure of all indexed node data, because OpenSearch credentials are exposed. (The data typically includes credentials for additional systems.) The attacker must wait for an admin to run the "chef-server-ctl reconfigure" command.

CVE-2023-40138
Android General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-4053
Firefox General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2.

CVE-2023-20784
MT6580, MT6731, MT6735, MT6737, MT6739, MT6753, MT6757, MT6757C, MT6757CD, MT6757CH, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6891, MT6893, MT6895, MT6983, MT6985, MT8185, MT8321, MT8385, MT8666, MT8673, MT8675, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8797 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In keyinstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07826989; Issue ID: ALPS07826989.

CVE-2023-43864
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2023 1 PoC

D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard55 function.

CVE-2023-49328
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2023 1 PoC

On a Wolters Kluwer B.POINT 23.70.00 server running Linux on premises, during the authentication phase, a validated system user can achieve remote code execution via Argument Injection in the server-to-server module.

CVE-2023-43235
Software Genérico General
N/A
UNKNOWN
EPSS
2.2%
2023 1 PoC

D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter StartTime and EndTime in SetWifiDownSettings.

CVE-2023-46052
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

Sane 1.2.1 heap bounds overwrite in init_options() from backend/test.c via a long init_mode string in a configuration file. NOTE: this is disputed because there is no expectation that test.c code should be executed with an attacker-controlled configuration file.

CVE-2023-26966
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

libtiff 4.5.0 is vulnerable to Buffer Overflow in uv_encode() when libtiff reads a corrupted little-endian TIFF file and specifies the output to be big-endian.

CVE-2023-36167
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Sin descripción disponible.

CVE-2023-4427
Chrome General
N/A
UNKNOWN
EPSS
79.3%
2023 2 PoCs

Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

CVE-2023-43960
Software Genérico General
N/A
UNKNOWN
EPSS
6.2%
2023 3 PoCs

An issue in DLINK DPH-400SE FRU 2.2.15.8 allows a remote attacker to escalate privileges via the User Modify function in the Maintenance/Access function component.

CVE-2023-39726
Software Genérico General
N/A
UNKNOWN
EPSS
1.6%
2023 1 PoC

An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the terminal.

CVE-2023-38378
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2023 2 PoCs

The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to execute arbitrary code via shell metacharacters in pass1 to the webcontrol changepwd.cgi application.

CVE-2023-42428
CubeCart General
N/A
UNKNOWN
EPSS
1.7%
2023 1 PoC

Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to delete directories and files in the system.

CVE-2023-51013
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanNetmask parameter’ of the setLanConfig interface of the cstecgi .cgi.

CVE-2023-34936
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A stack overflow in the UpdateMacClone function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.