3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-38743
Software Genérico General
7.2
HIGH
EPSS
21.1%
2023 1 PoC

Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine.

CVE-2023-34214
TN-5900 Series General
7.2
HIGH
EPSS
0.2%
2023 CWE-78 1 PoC

TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability stems from insufficient input validation in the certificate-generation function, which could potentially allow malicious users to execute remote code on affected devices.

CVE-2023-0640
TEW-652BRP General
7.2
HIGH
EPSS
0.9%
2023 CWE-77 1 PoC

A vulnerability was found in TRENDnet TEW-652BRP 3.04b01. It has been classified as critical. Affected is an unknown function of the file ping.ccp of the component Web Interface. The manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220020.

CVE-2023-37220
Terminals General
7.2
HIGH
EPSS
0.0%
2023 CWE-494 1 PoC

Synel Terminals - CWE-494: Download of Code Without Integrity Check

CVE-2023-33641
Software Genérico General
7.2
HIGH
EPSS
0.1%
2023 1 PoC

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the AddMacList interface at /goform/aspForm.

CVE-2023-33633
Software Genérico General
7.2
HIGH
EPSS
0.1%
2023 2 PoCs

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the UpdateWanParams interface at /goform/aspForm.

CVE-2023-24676
Software Genérico General
7.2
HIGH
EPSS
0.1%
2023 1 PoC

An issue found in ProcessWire 3.0.210 allows attackers to execute arbitrary code and install a reverse shell via the download_zip_url parameter when installing a new module. NOTE: this is disputed because exploitation requires that the attacker is able to enter requests as an admin; however, a ProcessWire admin is intentionally allowed to install any module that contains any arbitrary code.

CVE-2023-1731
LTOS General
7.2
HIGH
EPSS
0.5%
2023 CWE-434 1 PoC

In Meinbergs LTOS versions prior to V7.06.013, the configuration file upload function would not correctly validate the input, which would allow an remote authenticated attacker with high privileges to execute arbitrary commands.

CVE-2023-50239
WBR-6013 General
7.2
HIGH
EPSS
7.3%
2023 CWE-121 2 PoCs

Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This stack-based buffer overflow is related to the `interfacename` request's parameter.

CVE-2023-6336
Workforce Access General
7.2
HIGH
EPSS
0.0%
2023 CWE-59 1 PoC

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows User-Controlled Filename.This issue affects Workforce Access: before 8.7.

CVE-2023-50220
Ignition General
7.2
HIGH
EPSS
7.1%
2023 CWE-502 1 PoC

Inductive Automation Ignition Base64Element Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability. The specific flaw exists within the Base64Element class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-21801.

CVE-2023-22306
UR32L General
7.2
HIGH
EPSS
0.3%
2023 CWE-77 2 PoCs

An OS command injection vulnerability exists in the libzebra.so bridge_group functionality of Milesight UR32L v32.3.0.5. A specially crafted network packet can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-33627
Software Genérico General
7.2
HIGH
EPSS
0.1%
2023 1 PoC

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the UpdateSnat interface at /goform/aspForm.

CVE-2023-28128
Avalanche General
7.2
HIGH
EPSS
88.1%
2023 CWE-434 1 PoC

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution.

CVE-2023-0048
lirantal/daloradius General
7.2
HIGH
EPSS
2.2%
2023 CWE-94 1 PoC

Code Injection in GitHub repository lirantal/daloradius prior to master-branch.

CVE-2023-29084
Software Genérico General ⚡ nuclei
7.2
HIGH
EPSS
93.9%
2023 2 PoCs

Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.

CVE-2023-45215
WBR-6013 General
7.2
HIGH
EPSS
0.3%
2023 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in the boa setRepeaterSsid functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-26609
Software Genérico General
7.2
HIGH
EPSS
37.2%
2023 4 PoCs

ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin/mft/wireless_mft ap field.

CVE-2023-1831
Mattermost General
7.2
HIGH
EPSS
0.2%
2023 CWE-200 1 PoC

Mattermost fails to redact from audit logs the user password during user creation and the user password hash in other operations if the experimental audit logging configuration was enabled (ExperimentalAuditSettings section in config).

CVE-2023-1313
cockpit-hq/cockpit General
7.2
HIGH
EPSS
0.5%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository cockpit-hq/cockpit prior to 2.4.1.