3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-43478
Smart Modem Gen 2 (Arcadyan LH1000) General
8.8
HIGH
EPSS
4.1%
2023 1 PoC

fake_upload.cgi on the Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, allows unauthenticated attackers to upload firmware images and configuration backups, which could allow them to alter the firmware or the configuration on the device, ultimately leading to code execution as root. 

CVE-2023-38346
Software Genérico General
8.8
HIGH
EPSS
0.9%
2023 1 PoC

An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also processes files within an archive that have relative or absolute file paths. A developer using the "tarExtract" function may expect that the function will strip leading slashes from absolute paths or stop processing when encountering relative paths that are outside of the extraction path, unless otherwise forced. This could lead to unexpected and undocumented behavior, which in general could result in a directory traversal, and associated unexpected behavior.

CVE-2023-33533
Software Genérico General
8.8
HIGH
EPSS
6.5%
2023 1 PoC

Netgear D6220 with Firmware Version 1.0.0.80, D8500 with Firmware Version 1.0.3.60, R6700 with Firmware Version 1.0.2.26, and R6900 with Firmware Version 1.0.2.26 are vulnerable to Command Injection. If an attacker gains web management privileges, they can inject commands into the post request parameters, gaining shell privileges.

CVE-2023-2575
EKI-1524 General
8.8
HIGH
EPSS
2.8%
2023 CWE-121 4 PoCs

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stack-based Buffer Overflow vulnerability, which can be triggered by authenticated users via a crafted POST request.

CVE-2023-46536
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function chkRegVeriRegister.

CVE-2023-4863
🔥 KEV Chrome General
8.8
HIGH
EPSS
94.1%
2023 14 PoCs

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

CVE-2023-51066
Software Genérico General
8.8
HIGH
EPSS
9.0%
2023 1 PoC

An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily execute commands.

CVE-2023-1532
Chrome General
8.8
HIGH
EPSS
0.6%
2023 1 PoC

Out of bounds read in GPU Video in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-33722
Software Genérico General
8.8
HIGH
EPSS
2.6%
2023 1 PoC

EDIMAX BR-6288ACL v1.12 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the pppUserName parameter.

CVE-2023-1031
MonicaHQ General
8.8
HIGH
EPSS
0.9%
2023 1 PoC

MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `settings` endpoint and first_name parameter.

CVE-2023-32221
Todo Backup General
8.8
HIGH
EPSS
0.0%
2023 1 PoC

EaseUS Todo Backup version 20220111.390 - An omission during installation may allow a local attacker to perform privilege escalation.

CVE-2023-29541
Firefox General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands. <br>*This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.*. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.

CVE-2023-53962
Impact/Pulse/First General
8.8
HIGH
EPSS
5.3%
2023 CWE-22 2 PoCs

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated directory traversal vulnerability that allows remote attackers to write arbitrary files through the 'upgfile' parameter in upload.cgi. Attackers can exploit the vulnerability by sending crafted multipart form-data POST requests with directory traversal sequences to write files to unintended system locations.

CVE-2023-46535
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function getResetVeriRegister.

CVE-2023-45312
Software Genérico General
8.8
HIGH
EPSS
4.1%
2023 2 PoCs

In the mtproto_proxy (aka MTProto proxy) component through 0.7.2 for Erlang, a low-privileged remote attacker can access an improperly secured default installation without authenticating and achieve remote command execution ability.

CVE-2023-26690
Software Genérico General
8.8
HIGH
EPSS
0.7%
2023 1 PoC

File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/Editor component in the vendor or admin menu.

CVE-2023-26122
safe-eval General
8.8
HIGH
EPSS
8.1%
2023 CWE-265 1 PoC

All versions of the package safe-eval are vulnerable to Sandbox Bypass due to improper input sanitization. The vulnerability is derived from prototype pollution exploitation. Exploiting this vulnerability might result in remote code execution ("RCE"). **Vulnerable functions:** __defineGetter__, stack(), toLocaleString(), propertyIsEnumerable.call(), valueOf().

CVE-2023-49367
Software Genérico General
8.8
HIGH
EPSS
0.1%
2023 1 PoC

An issue in user interface in Kyocera Command Center RX EXOSYS M5521cdn allows remote to obtain sensitive information via inspecting sent packages by user.

CVE-2023-22612
Software Genérico General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. A malicious host OS can invoke an Insyde SMI handler with malformed arguments, resulting in memory corruption in SMM.

CVE-2023-24217
Software Genérico General
8.8
HIGH
EPSS
4.9%
2023 1 PoC

AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability.