3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-24798
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_475FB0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-24800
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_495220 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-23585
Experion Server General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-787 1 PoC

Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.  See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-28504
UniData General
9.8
CRITICAL
EPSS
2.0%
2023 CWE-120 1 PoC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow that can lead to remote code execution as the root user.

CVE-2023-4373
Remote Desktop Manager General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature.

CVE-2023-49236
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

A stack-based buffer overflow was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices, leading to arbitrary command execution. This occurs because of lack of length validation during an sscanf of a user-entered scale field in the RTSP playback function of davinci.

CVE-2023-32117
Integrate Google Drive General ⚡ nuclei
9.8
CRITICAL
EPSS
89.4%
2023 CWE-862 1 PoC

Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through 1.1.99.

CVE-2023-1307
froxlor/froxlor General
9.8
CRITICAL
EPSS
0.2%
2023 CWE-305 1 PoC

Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13.

CVE-2023-46661
PolyEco1000 General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-284 1 PoC

Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests.

CVE-2023-27645
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2023 1 PoC

An issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges via the reverb and EQ preset parameters.

CVE-2023-2780
mlflow/mlflow General ⚡ nuclei
9.8
CRITICAL
EPSS
86.8%
2023 CWE-29 1 PoC

Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1.

CVE-2023-26999
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file.

CVE-2023-37214
ERO1xS-Pro Dual-Band WiFi General
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025.

CVE-2023-40890
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 2 PoCs

A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or prepare it to be physically scanned by the vulnerable scanner.

CVE-2023-29736
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Keyboard Themes 1.275.1.164 for Android contains a dictionary traversal vulnerability that allows unauthorized apps to overwrite arbitrary files in its internal storage and achieve arbitrary code execution.

CVE-2023-32224
DSL-224 firmware version 3.0.10 General
9.8
CRITICAL
EPSS
0.9%
2023 CWE-307 1 PoC

D-Link DSL-224 firmware version 3.0.10 CWE-307: Improper Restriction of Excessive Authentication Attempts

CVE-2023-20864
VMware Aria Operations for Logs (formerly vRealize Log Insight) General ⚡ nuclei
9.8
CRITICAL
EPSS
93.0%
2023 0 PoCs

VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.

CVE-2023-6928
ETL3100 General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-307 1 PoC

EuroTel ETL3100 versions v01c01 and v01x37 does not limit the number of attempts to guess administrative credentials in remote password attacks to gain full control of the system.

CVE-2023-52026
Software Genérico General
9.8
CRITICAL
EPSS
3.6%
2023 1 PoC

TOTOlink EX1800T V9.1.0cu.2112_B20220316 was discovered to contain a remote command execution (RCE) vulnerability via the telnet_enabled parameter of the setTelnetCfg interface