3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-46747
🔥 KEV BIG-IP General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2023 CWE-288 15 PoCs

Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2023-34566
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/saveParentControlInfo.

CVE-2023-42282
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2023 2 PoCs

The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.

CVE-2023-2231
MAX-G866ac General
9.8
CRITICAL
EPSS
0.2%
2023 CWE-306 2 PoCs

A vulnerability, which was classified as critical, was found in MAXTECH MAX-G866ac 0.4.1_TBRO_20160314. This affects an unknown part of the component Remote Management. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227001 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-24798
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_475FB0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-23076
Software Genérico General
9.8
CRITICAL
EPSS
49.3%
2023 1 PoC

OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.

CVE-2023-32117
Integrate Google Drive General ⚡ nuclei
9.8
CRITICAL
EPSS
89.4%
2023 CWE-862 1 PoC

Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through 1.1.99.

CVE-2023-6233
Satera LBP670C Series General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-787 2 PoCs

Buffer overflow in SLP attribute request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.

CVE-2023-6928
ETL3100 General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-307 1 PoC

EuroTel ETL3100 versions v01c01 and v01x37 does not limit the number of attempts to guess administrative credentials in remote password attacks to gain full control of the system.

CVE-2023-33735
Software Genérico General
9.8
CRITICAL
EPSS
53.2%
2023 1 PoC

D-Link DIR-846 v1.00A52 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in the /HNAP1 interface.

CVE-2023-38389
JupiterX Core General
9.8
CRITICAL
EPSS
11.8%
2023 CWE-863 1 PoC

Incorrect Authorization vulnerability in Artbees JupiterX Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JupiterX Core: from n/a through 3.3.8.

CVE-2023-6231
Satera LBP670C Series General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-787 2 PoCs

Buffer overflow in WSD probe request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.

CVE-2023-26119
net.sourceforge.htmlunit:htmlunit General
9.8
CRITICAL
EPSS
4.0%
2023 CWE-94 1 PoC

Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage.

CVE-2023-24049
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges on the device via poor credential management.

CVE-2023-26999
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file.

CVE-2023-27388
T&D Corporation and ESPEC MIC CORP. data logger products General
9.8
CRITICAL
EPSS
1.0%
2023 1 PoC

Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login to the product as a registered user. Affected products and versions are as follows: T&D Corporation data logger products (TR-71W/72W all firmware versions, RTR-5W all firmware versions, WDR-7 all firmware versions, WDR-3 all firmware versions, and WS-2 all firmware versions), and ESPEC MIC CORP. data logger products (RT-12N/RS-12N all firmware versions, RT-22BN all firmware versions, and TEU-12N all firmware versions).

CVE-2023-6329
iDSecure General ⚡ nuclei
9.8
CRITICAL
EPSS
92.5%
2023 CWE-287 1 PoC

An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll contains a "passwordCustom" option that allows an unauthenticated attacker to compute valid credentials that can be used to bypass authentication and act as an administrative user.

CVE-2023-29732
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

SoLive 1.6.14 thru 1.6.20 for Android exists exposed component, the component provides the method to modify the SharedPreference file. The attacker can use the method to modify the data in any SharedPreference file, these data will be loaded into the memory when the application is opened. Depending on how the data is used, this can result in various attack consequences, such as ad display exceptions.

CVE-2023-37214
ERO1xS-Pro Dual-Band WiFi General
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025.

CVE-2023-46661
PolyEco1000 General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-284 1 PoC

Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests.