3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-38378
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2023 2 PoCs

The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to execute arbitrary code via shell metacharacters in pass1 to the webcontrol changepwd.cgi application.

CVE-2023-42428
CubeCart General
N/A
UNKNOWN
EPSS
1.7%
2023 1 PoC

Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to delete directories and files in the system.

CVE-2023-51013
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanNetmask parameter’ of the setLanConfig interface of the cstecgi .cgi.

CVE-2023-34936
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

A stack overflow in the UpdateMacClone function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2023-49314
Software Genérico General
N/A
UNKNOWN
EPSS
17.6%
2023 2 PoCs

Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and EnableNodeCliInspectArguments, and thus r3ggi/electroniz3r can be used to perform an attack.

CVE-2023-1576
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Sin descripción disponible.

CVE-2023-33684
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Weak session management in DB Elettronica Telecomunicazioni SpA SFT DAB 600/C Firmware: 1.9.3 Bios firmware: 7.1 (Apr 19 2021) Gui: 2.46 FPGA: 169.55 uc: 6.15 allows attackers on the same network to bypass authentication by re-using the IP address assigned to the device by the NAT protocol.

CVE-2023-34932
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A stack overflow in the UpdateWanMode function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2023-40998
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2023 1 PoC

Buffer Overflow vulnerability in O-RAN Software Community ric-plt-lib-rmr v.4.9.0 allows a remote attacker to cause a denial of service via the packet size component.

CVE-2023-43240
Software Genérico General
N/A
UNKNOWN
EPSS
58.0%
2023 1 PoC

D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter sip_address in ipportFilter.

CVE-2023-26756
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

The login page of Revive Adserver v5.4.1 is vulnerable to brute force attacks. NOTE: The vendor's position is that this is effectively mitigated by rate limits and password-quality features.

CVE-2023-39076
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 2 PoCs

Injecting random data into the USB memory area on a General Motors (GM) Chevrolet Equinox 2021 Software. 2021.03.26 (build version) vehicle causes a Denial of Service (DoS) in the in-car infotainment system.

CVE-2023-32364
macOS General
N/A
UNKNOWN
EPSS
7.4%
2023 1 PoC

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Ventura 13.5. A sandboxed process may be able to circumvent sandbox restrictions.

CVE-2023-27655
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

Sin descripción disponible.

CVE-2023-29799
Software Genérico General
N/A
UNKNOWN
EPSS
14.9%
2023 1 PoC

TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.

CVE-2023-36499
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2023 1 PoC

Netgear XR300 v1.0.3.78 was discovered to contain multiple buffer overflows via the wla_ssid and wlg_ssid parameters at genie_ap_wifi_change.cgi.

CVE-2023-40869
Software Genérico General
N/A
UNKNOWN
EPSS
5.6%
2023 1 PoC

Cross Site Scripting vulnerability in mooSocial mooSocial Software 3.1.6 and 3.1.7 allows a remote attacker to execute arbitrary code via a crafted script to the edit_menu, copuon, and group_categorias functions.

CVE-2023-20918
Android General
N/A
UNKNOWN
EPSS
1.4%
2023 2 PoCs

In getPendingIntentLaunchFlags of ActivityOptions.java, there is a possible elevation of privilege due to a confused deputy with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-20790
MT2713, MT2735, MT2737, MT6739, MT6761, MT6762, MT6763, MT6765, MT6768, MT6769, MT6771, MT6779, MT6781, MT6785, MT6789, MT6833, MT6835, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6980, MT6983, MT6985, MT6990, MT8167, MT8167S, MT8168, MT8173, MT8175, MT8185, MT8188, MT8195, MT8321, MT8362A, MT8365, MT8385, MT8395, MT8666, MT8667, MT8673, MT8675, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8797 General
N/A
UNKNOWN
EPSS
0.0%
2023 1 PoC

In nvram, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07740194; Issue ID: ALPS07740194.

CVE-2023-33272
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2023 1 PoC

An issue was discovered in DTS Monitoring 3.57.0. The parameter ip within the Ping check function is vulnerable to OS command injection (blind).