3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-22629
Software Genérico General
8.8
HIGH
EPSS
65.1%
2023 3 PoCs

An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the newPath parameter. An authenticated attacker can upload any file and then move it anywhere on the server's filesystem.

CVE-2023-43239
Software Genérico General
8.8
HIGH
EPSS
57.5%
2023 1 PoC

D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter flag_5G in showMACfilterMAC.

CVE-2023-1031
MonicaHQ General
8.8
HIGH
EPSS
0.9%
2023 1 PoC

MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `settings` endpoint and first_name parameter.

CVE-2023-43478
Smart Modem Gen 2 (Arcadyan LH1000) General
8.8
HIGH
EPSS
4.1%
2023 1 PoC

fake_upload.cgi on the Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, allows unauthenticated attackers to upload firmware images and configuration backups, which could allow them to alter the firmware or the configuration on the device, ultimately leading to code execution as root. 

CVE-2023-30765
Infrasuite Device Master General
8.8
HIGH
EPSS
0.9%
2023 CWE-269 1 PoC

​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contain improper access controls that could allow an attacker to alter privilege management configurations, resulting in privilege escalation.

CVE-2023-46535
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function getResetVeriRegister.

CVE-2023-28506
UniData General
8.8
HIGH
EPSS
0.5%
2023 CWE-120 1 PoC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow, where a string is copied into a buffer using a memcpy-like function and a user-provided length. This requires a valid login to exploit.

CVE-2023-24507
NX General
8.8
HIGH
EPSS
0.4%
2023 1 PoC

AgilePoint NX v8.0 SU2.2 & SU2.3 – Insecure File Upload - Vulnerability allows insecure file upload, by an unspecified request.

CVE-2023-26690
Software Genérico General
8.8
HIGH
EPSS
0.7%
2023 1 PoC

File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/Editor component in the vendor or admin menu.

CVE-2023-50233
Ignition General
8.8
HIGH
EPSS
3.7%
2023 CWE-22 1 PoC

Inductive Automation Ignition getJavaExecutable Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this vulnerability in that the target must connect to a malicious server. The specific flaw exists within the getJavaExecutable method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context

CVE-2023-47352
Software Genérico General
8.8
HIGH
EPSS
0.1%
2023 1 PoC

Technicolor TC8715D devices have predictable default WPA2 security passwords. An attacker who scans for SSID and BSSID values may be able to predict these passwords.

CVE-2023-33538
🔥 KEV Software Genérico General
8.8
HIGH
EPSS
90.6%
2023 2 PoCs

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm .

CVE-2023-46536
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function chkRegVeriRegister.

CVE-2023-25434
Software Genérico General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesBytes() at /libtiff/tools/tiffcrop.c:3215.

CVE-2023-46522
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TP-LINK device TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin and TL-WDR7660 2.0.30 were discovered to contain a stack overflow via the function deviceInfoRegister.

CVE-2023-46527
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin and TL-WDR7660 2.0.30 was discovered to contain a stack overflow via the function bindRequestHandle.

CVE-2023-3421
Chrome General
8.8
HIGH
EPSS
0.8%
2023 1 PoC

Use after free in Media in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-5217
🔥 KEV Chrome General
8.8
HIGH
EPSS
4.2%
2023 4 PoCs

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-43242
Software Genérico General
8.8
HIGH
EPSS
2.5%
2023 1 PoC

D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter removeRuleList in form2IPQoSTcDel.

CVE-2023-51025
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to an unauthorized arbitrary command execution in the ‘admuser’ parameter of the setPasswordCfg interface of the cstecgi .cgi.