40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-2583
jsreport/jsreport General
10.0
CRITICAL
EPSS
0.1%
2023 CWE-94 1 PoC

Code Injection in GitHub repository jsreport/jsreport prior to 3.11.3.

CVE-2023-2024
OpenBlue Enterprise Manager Data Collector General
10.0
CRITICAL
EPSS
0.3%
2023 CWE-287 2 PoCs

Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances.

CVE-2023-28100
flatpak General
10.0
CRITICAL
EPSS
0.7%
2023 CWE-20 1 PoC

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. Versions prior to 1.10.8, 1.12.8, 1.14.4, and 1.15.4 contain a vulnerability similar to CVE-2017-5226, but using the `TIOCLINUX` ioctl command instead of `TIOCSTI`. If a Flatpak app is run on a Linux virtual console such as `/dev/tty1`, it can copy text from the virtual console and paste it into the command buffer, from which the command might be run after the Flatpak app has exited. Ordinary graphical terminal emulators like xterm, gnome-terminal and Konsole are unaffected. This vulnerability

CVE-2023-41094
Ember ZNet General
10.0
CRITICAL
EPSS
0.1%
2023 CWE-940 1 PoC

TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing duration This issue affects Ember ZNet 7.1.x from 7.1.3 through 7.1.5; 7.2.x from 7.2.0 through 7.2.3; Version 7.3 and later are unaffected

CVE-2023-48418
Pixel Watch General
10.0
CRITICAL
EPSS
0.0%
2023 CWE-269 1 PoC

In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a     possible way to access adb before SUW completion due to an insecure default     value. This could lead to local escalation of privilege with no additional     execution privileges needed. User interaction is not needed for     exploitation

CVE-2014-125124
Pandora FMS General
10.0
CRITICAL
EPSS
36.0%
2014 CWE-78 2 PoCs

An unauthenticated remote command execution vulnerability exists in Pandora FMS versions up to and including 5.0RC1 via the Anyterm web interface, which listens on TCP port 8023. The anyterm-module endpoint accepts unsanitized user input via the p parameter and directly injects it into a shell command, allowing arbitrary command execution as the pandora user. In certain versions (notably 4.1 and 5.0RC1), the pandora user can elevate privileges to root without a password using a chain involving the artica user account. This account is typically installed without a password and is configured to

CVE-2023-2138
nuxtlabs/github-module General
10.0
CRITICAL
EPSS
0.4%
2023 CWE-798 1 PoC

Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2.

CVE-2023-5572
vriteio/vrite General
10.0
CRITICAL
EPSS
0.3%
2023 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository vriteio/vrite prior to 0.3.0.

CVE-2026-28409
WeGIA General ⚡ nuclei
10.0
CRITICAL
EPSS
1.4%
2026 CWE-78 0 PoCs

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database restoration functionality. An attacker with administrative access (which can be obtained via the previously reported Authentication Bypass) can execute arbitrary OS commands on the server by uploading a backup file with a specifically crafted filename. Version 3.6.5 fixes the issue.

CVE-2024-45409
ruby-saml General
10.0
CRITICAL
EPSS
42.4%
2024 CWE-347 1 PoC

The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Assertion with arbitrary contents. This would allow the attacker to log in as arbitrary user within the vulnerable system. This vulnerability is fixed in 1.17.0 and 1.12.3.

CVE-2023-22527
🔥 KEV Confluence Data Center General ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2023 27 PoCs

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.

CVE-2023-6977
mlflow/mlflow General ⚡ nuclei
10.0
CRITICAL
EPSS
83.0%
2023 CWE-29 1 PoC

This vulnerability enables malicious users to read sensitive files on the server.

CVE-2014-0787
KingSCADA General
10.0
UNKNOWN
EPSS
50.9%
2014 CWE-121 1 PoC

Stack-based buffer overflow in WellinTech KingSCADA before 3.1.2.13 allows remote attackers to execute arbitrary code via a crafted packet.

CVE-2024-9478
upKeeper Instant Privilege Access General
10.0
CRITICAL
EPSS
0.2%
2024 CWE-266 1 PoC

Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2.

CVE-2024-39700
extension-template General
10.0
CRITICAL
EPSS
3.9%
2024 CWE-94 1 PoC

JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension authors hosting their code on GitHub are urged to upgrade the template to the latest version. Users who made changes to `update-integration-tests.yml`, accept overwriting of this file and re-apply your changes later. Users may wish to temporarily disable GitHub Actions while working on the upgrade. We recommend rebasing all open pull requests from untrusted users as

CVE-2024-7591
LoadMaster General ⚡ nuclei
10.0
CRITICAL
EPSS
31.5%
2024 CWE-78 1 PoC

Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above

CVE-2023-1283
builderio/qwik General
10.0
CRITICAL
EPSS
0.3%
2023 CWE-94 1 PoC

Code Injection in GitHub repository builderio/qwik prior to 0.21.0.

CVE-2023-7163
D-View 8 General
10.0
CRITICAL
EPSS
3.4%
2023 CWE-20 1 PoC

A security issue exists in D-Link D-View 8 v2.0.2.89 and prior that could allow an attacker to manipulate the probe inventory of the D-View service. This could result in the disclosure of information from other probes, denial of service conditions due to the probe inventory becoming full, or the execution of tasks on other probes.

CVE-2023-40151
ST-IPm-8460 General
10.0
CRITICAL
EPSS
0.4%
2023 CWE-749 1 PoC

When user authentication is not enabled the shell can execute commands with the highest privileges. Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message comes over TCP/IP the RTU will simply accept the message with no authentication challenge.

CVE-2023-29017
vm2 General
10.0
CRITICAL
EPSS
75.0%
2023 CWE-913 3 PoCs

vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Prior to version 3.9.15, vm2 was not properly handling host objects passed to `Error.prepareStackTrace` in case of unhandled async errors. A threat actor could bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.15 of vm2. There are no known workarounds.