3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-32222
DSL-G256DG firmware version vBZ_1.00.27 General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

D-Link DSL-G256DG version vBZ_1.00.27 web management interface allows authentication bypass via an unspecified method.

CVE-2023-20864
VMware Aria Operations for Logs (formerly vRealize Log Insight) General ⚡ nuclei
9.8
CRITICAL
EPSS
93.0%
2023 0 PoCs

VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.

CVE-2023-24049
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges on the device via poor credential management.

CVE-2023-24720
Software Genérico General
9.8
CRITICAL
EPSS
0.9%
2023 1 PoC

An arbitrary file upload vulnerability in readium-js v0.32.0 allows attackers to execute arbitrary code via uploading a crafted EPUB file.

CVE-2023-29961
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

D-Link DIR-605L firmware version 1.17B01 BETA is vulnerable to stack overflow via /goform/formTcpipSetup,

CVE-2023-1307
froxlor/froxlor General
9.8
CRITICAL
EPSS
0.2%
2023 CWE-305 1 PoC

Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13.

CVE-2023-6229
Satera LBP670C Series General
9.8
CRITICAL
EPSS
0.5%
2023 CWE-787 2 PoCs

Buffer overflow in CPCA PDL Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.

CVE-2023-49543
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 2 PoCs

Incorrect access control in Book Store Management System v1 allows attackers to access unauthorized pages and execute administrative functions without authenticating.

CVE-2023-37999
HT Mega General ⚡ nuclei
9.8
CRITICAL
EPSS
53.8%
2023 CWE-269 0 PoCs

Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega: from n/a through 2.2.0.

CVE-2023-28504
UniData General
9.8
CRITICAL
EPSS
2.0%
2023 CWE-120 1 PoC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow that can lead to remote code execution as the root user.

CVE-2023-29736
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Keyboard Themes 1.275.1.164 for Android contains a dictionary traversal vulnerability that allows unauthorized apps to overwrite arbitrary files in its internal storage and achieve arbitrary code execution.

CVE-2023-44077
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636.

CVE-2023-6234
Satera LBP670C Series General
9.8
CRITICAL
EPSS
0.5%
2023 CWE-787 2 PoCs

Buffer overflow in CPCA Color LUT Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.

CVE-2023-45498
Software Genérico General
9.8
CRITICAL
EPSS
79.5%
2023 4 PoCs

VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability.

CVE-2023-29746
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2023 1 PoC

An issue found in The Thaiger v.1.2 for Android allows unauthorized apps to cause a code execution attack by manipulating the SharedPreference files.

CVE-2023-24762
Software Genérico General
9.8
CRITICAL
EPSS
5.5%
2023 2 PoCs

OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress parameter for the SetVirtualServerSettings to HNAP1.

CVE-2023-51961
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.

CVE-2023-25234
Software Genérico General
9.8
CRITICAL
EPSS
34.1%
2023 1 PoC

Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInterface.

CVE-2023-33864
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2023 3 PoCs

StreamReader::ReadFromExternal in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. It uses uint32_t(m_BufferSize-m_InputSize) even though m_InputSize can exceed m_BufferSize.

CVE-2023-2780
mlflow/mlflow General ⚡ nuclei
9.8
CRITICAL
EPSS
86.8%
2023 CWE-29 1 PoC

Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1.