40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-33863
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 3 PoCs

SerialiseValue in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. 0xffffffff is sign-extended to 0xffffffffffffffff (SIZE_MAX) and then there is an attempt to add 1.

CVE-2023-25367
Software Genérico General
9.8
CRITICAL
EPSS
4.8%
2023 1 PoC

Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS allows unfiltered user input resulting in Remote Code Execution (RCE) with SCPI interface or web server.

CVE-2023-51277
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

nbviewer-app (aka Jupyter Notebook Viewer) before 0.1.6 has the get-task-allow entitlement for release builds.

CVE-2023-24797
Software Genérico General
9.8
CRITICAL
EPSS
1.7%
2023 1 PoC

D-Link DIR882 DIR882A1_FW110B02 was discovered to contain a stack overflow in the sub_48AC20 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-24480
C300 General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-116 1 PoC

Controller DoS due to stack overflow when decoding a message from the server.  See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-25279
Software Genérico General
9.8
CRITICAL
EPSS
46.9%
2023 1 PoC

OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload.

CVE-2024-11704
Firefox General
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability affects Firefox < 133, Thunderbird < 133, Firefox ESR < 128.7, and Thunderbird < 128.7.

CVE-2023-30547
vm2 General
9.8
CRITICAL
EPSS
84.9%
2023 CWE-74 4 PoCs

vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. There exists a vulnerability in exception sanitization of vm2 for versions up to 3.9.16, allowing attackers to raise an unsanitized host exception inside `handleException()` which can be used to escape the sandbox and run arbitrary code in host context. This vulnerability was patched in the release of version `3.9.17` of `vm2`. There are no known workarounds for this vulnerability. Users are advised to upgrade.

CVE-2023-0744
answerdev/answer General
9.8
CRITICAL
EPSS
8.5%
2023 CWE-284 2 PoCs

Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4.

CVE-2023-27388
T&D Corporation and ESPEC MIC CORP. data logger products General
9.8
CRITICAL
EPSS
1.0%
2023 1 PoC

Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login to the product as a registered user. Affected products and versions are as follows: T&D Corporation data logger products (TR-71W/72W all firmware versions, RTR-5W all firmware versions, WDR-7 all firmware versions, WDR-3 all firmware versions, and WS-2 all firmware versions), and ESPEC MIC CORP. data logger products (RT-12N/RS-12N all firmware versions, RT-22BN all firmware versions, and TEU-12N all firmware versions).

CVE-2023-51958
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.

CVE-2023-29746
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2023 1 PoC

An issue found in The Thaiger v.1.2 for Android allows unauthorized apps to cause a code execution attack by manipulating the SharedPreference files.

CVE-2026-2590
Remote Desktop Manager General
9.8
CRITICAL
EPSS
0.1%
2026 1 PoC

Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.3.30 and earlier allows an authenticated user to persist credentials in vault entries, potentially exposing sensitive information to other users, by creating or editing certain connection types while password saving is disabled.

CVE-2023-34566
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/saveParentControlInfo.

CVE-2023-42000
Arcserve UDP General
9.8
CRITICAL
EPSS
1.2%
2023 CWE-22 1 PoC

Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthenticated remote attacker can exploit it to upload arbitrary files to any location on the file system where the UDP agent is installed.

CVE-2023-45498
Software Genérico General
9.8
CRITICAL
EPSS
79.5%
2023 4 PoCs

VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability.

CVE-2023-52026
Software Genérico General
9.8
CRITICAL
EPSS
3.6%
2023 1 PoC

TOTOlink EX1800T V9.1.0cu.2112_B20220316 was discovered to contain a remote command execution (RCE) vulnerability via the telnet_enabled parameter of the setTelnetCfg interface

CVE-2023-1133
InfraSuite Device Master General
9.8
CRITICAL
EPSS
86.1%
2023 1 PoC

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary code.

CVE-2023-46665
PolyEco1000 General
9.8
CRITICAL
EPSS
0.0%
2023 CWE-284 1 PoC

Sielco PolyEco1000 is vulnerable to an authentication bypass vulnerability due to an attacker modifying passwords in a POST request and gain unauthorized access to the affected device with administrative privileges.

CVE-2023-6928
ETL3100 General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-307 1 PoC

EuroTel ETL3100 versions v01c01 and v01x37 does not limit the number of attempts to guess administrative credentials in remote password attacks to gain full control of the system.