3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-1531
Chrome General
8.8
HIGH
EPSS
0.9%
2023 1 PoC

Use after free in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-50219
Ignition General
8.8
HIGH
EPSS
8.9%
2023 CWE-502 1 PoC

Inductive Automation Ignition RunQuery Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability. The specific flaw exists within the RunQuery class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-21625.

CVE-2023-33533
Software Genérico General
8.8
HIGH
EPSS
6.5%
2023 1 PoC

Netgear D6220 with Firmware Version 1.0.0.80, D8500 with Firmware Version 1.0.3.60, R6700 with Firmware Version 1.0.2.26, and R6900 with Firmware Version 1.0.2.26 are vulnerable to Command Injection. If an attacker gains web management privileges, they can inject commands into the post request parameters, gaining shell privileges.

CVE-2023-41993
🔥 KEV macOS General
8.8
HIGH
EPSS
24.2%
2023 4 PoCs

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CVE-2023-5178
Red Hat Enterprise Linux 8 General
8.8
HIGH
EPSS
8.6%
2023 CWE-416 1 PoC

A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation.

CVE-2023-29048
OX App Suite General
8.8
HIGH
EPSS
0.4%
2023 CWE-78 1 PoC

A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user. Users and attackers could run system commands with limited privilege to gain unauthorized access to confidential information and potentially violate integrity by modifying resources. The template engine has been reconfigured to deny execution of harmful commands on a system level. No publicly available exploits are known.

CVE-2023-33722
Software Genérico General
8.8
HIGH
EPSS
2.6%
2023 1 PoC

EDIMAX BR-6288ACL v1.12 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the pppUserName parameter.

CVE-2023-51066
Software Genérico General
8.8
HIGH
EPSS
9.0%
2023 1 PoC

An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily execute commands.

CVE-2023-22613
Software Genérico General
8.8
HIGH
EPSS
0.1%
2023 1 PoC

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI handler with a malformed pointer in RCX that overlaps SMRAM, resulting in SMM memory corruption.

CVE-2023-33131
Microsoft Office 2019 General
8.8
HIGH
EPSS
2.7%
2023 1 PoC

Microsoft Outlook Remote Code Execution Vulnerability

CVE-2023-1031
MonicaHQ General
8.8
HIGH
EPSS
0.9%
2023 1 PoC

MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `settings` endpoint and first_name parameter.

CVE-2023-6702
Chrome General
8.8
HIGH
EPSS
57.9%
2023 1 PoC

Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-0611
TEW-652BRP General
8.8
HIGH
EPSS
2.9%
2023 CWE-77 1 PoC

A vulnerability, which was classified as critical, has been found in TRENDnet TEW-652BRP 3.04B01. This issue affects some unknown processing of the file get_set.ccp of the component Web Management Interface. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-219935.

CVE-2023-46892
Software Genérico General
8.8
HIGH
EPSS
0.0%
2023 1 PoC

The radio frequency communication protocol being used by Meross MSH30Q 4.5.23 is vulnerable to replay attacks, allowing attackers to record and replay previously captured communication to execute unauthorized commands or actions (e.g., thermostat's temperature).

CVE-2023-6078
BIOVIA Materials Studio products General
8.8
HIGH
EPSS
0.3%
2023 CWE-78 1 PoC

An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023. Upload of a specially crafted perl script can lead to arbitrary command execution.

CVE-2023-25434
Software Genérico General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesBytes() at /libtiff/tools/tiffcrop.c:3215.

CVE-2023-36899
Microsoft .NET Framework 4.8 General
8.8
HIGH
EPSS
70.0%
2023 CWE-20 2 PoCs

ASP.NET Elevation of Privilege Vulnerability

CVE-2023-23583
Intel(R) Processors General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access.

CVE-2023-46539
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function registerRequestHandle.

CVE-2023-47992
Software Genérico General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

An integer overflow vulnerability in FreeImageIO.cpp::_MemoryReadProc in FreeImage 3.18.0 allows attackers to obtain sensitive information, cause a denial-of-service attacks and/or run arbitrary code.