3387 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-50220
Ignition General
7.2
HIGH
EPSS
7.1%
2023 CWE-502 1 PoC

Inductive Automation Ignition Base64Element Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability. The specific flaw exists within the Base64Element class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-21801.

CVE-2023-33642
Software Genérico General
7.2
HIGH
EPSS
0.1%
2023 1 PoC

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the Edit_BasicSSID interface at /goform/aspForm.

CVE-2023-28128
Avalanche General
7.2
HIGH
EPSS
88.1%
2023 CWE-434 1 PoC

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution.

CVE-2023-33636
Software Genérico General
7.2
HIGH
EPSS
0.1%
2023 1 PoC

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the ipqos_lanip_editlist interface at /goform/aspForm.

CVE-2023-48270
WBR-6013 General
7.2
HIGH
EPSS
0.5%
2023 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in the boa formDnsv6 functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-33632
Software Genérico General
7.2
HIGH
EPSS
0.1%
2023 2 PoCs

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the ipqos_lanip_dellist interface at /goform/aspForm.

CVE-2023-1731
LTOS General
7.2
HIGH
EPSS
0.5%
2023 CWE-434 1 PoC

In Meinbergs LTOS versions prior to V7.06.013, the configuration file upload function would not correctly validate the input, which would allow an remote authenticated attacker with high privileges to execute arbitrary commands.

CVE-2023-26262
Software Genérico General
7.2
HIGH
EPSS
17.5%
2023 1 PoC

An issue was discovered in Sitecore XP/XM 10.3. As an authenticated Sitecore user, a unrestricted language file upload vulnerability exists the can lead to direct code execution on the content management (CM) server.

CVE-2023-38056
OTRS General
7.2
HIGH
EPSS
0.4%
2023 CWE-78 1 PoC

Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows any authenticated attacker with admin privileges local execution of Code.This issue affects OTRS: from 7.0.X before 7.0.45, from 8.0.X before 8.0.35; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.

CVE-2023-33627
Software Genérico General
7.2
HIGH
EPSS
0.1%
2023 1 PoC

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the UpdateSnat interface at /goform/aspForm.

CVE-2023-6336
Workforce Access General
7.2
HIGH
EPSS
0.0%
2023 CWE-59 1 PoC

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows User-Controlled Filename.This issue affects Workforce Access: before 8.7.

CVE-2023-1477
Keycloak Authenticator Extension General
7.2
HIGH
EPSS
0.4%
2023 CWE-287 1 PoC

Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak Authenticator Extension: before 7.10.2, before 8.0.3.

CVE-2023-26609
Software Genérico General
7.2
HIGH
EPSS
37.2%
2023 4 PoCs

ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin/mft/wireless_mft ap field.

CVE-2023-33635
Software Genérico General
7.2
HIGH
EPSS
0.1%
2023 1 PoC

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the UpdateMacClone interface at /goform/aspForm.

CVE-2023-2554
unilogies/bumsys General
7.2
HIGH
EPSS
2.2%
2023 CWE-73 1 PoC

External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0.

CVE-2023-33238
TN-5900 Series General
7.2
HIGH
EPSS
0.3%
2023 CWE-78 1 PoC

TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnerability. This vulnerability stems from inadequate input validation in the certificate management function, which could potentially allow malicious users to execute remote code on affected devices.

CVE-2023-39171
Storage Box V1 General
7.2
HIGH
EPSS
0.2%
2023 CWE-668 2 PoCs

SENEC Storage Box V1,V2 and V3 accidentially expose a management UI accessible with publicly known admin credentials.

CVE-2023-49978
Software Genérico General
7.2
HIGH
EPSS
0.5%
2023 2 PoCs

Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for administrators.

CVE-2023-47856
WBR-6013 General
7.2
HIGH
EPSS
7.3%
2023 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in the boa set_RadvdPrefixParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.