3282 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2023-53941
EasyPHP Webserver Web
9.3
CRITICAL
EPSS
70.5%
2023 CWE-78 1 PoC

EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by injecting malicious payloads through the app_service_control parameter. Attackers can send POST requests to /index.php?zone=settings with crafted app_service_control values to execute commands with administrative privileges.

CVE-2023-53969
Screen SFT DAB 600/C Web
9.3
CRITICAL
EPSS
0.4%
2023 CWE-306 2 PoCs

Screen SFT DAB 600/C firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to change user passwords without proper authentication.

CVE-2023-53894
phpfm Web
9.3
CRITICAL
EPSS
0.5%
2023 CWE-1390 1 PoC

phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e or 00e to bypass authentication and upload malicious PHP files to the server.

CVE-2023-54339
Webgrind Web
9.3
CRITICAL
EPSS
0.7%
2023 CWE-78 1 PoC

Webgrind 1.1 contains a remote command execution vulnerability that allows unauthenticated attackers to inject OS commands via the dataFile parameter in index.php. Attackers can execute arbitrary system commands by manipulating the dataFile parameter, such as using payload '0%27%26calc.exe%26%27' to execute commands on the target system.

CVE-2023-53960
Impact/Pulse/First Web Database
9.3
CRITICAL
EPSS
0.3%
2023 CWE-89 2 PoCs

SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mechanism that allows attackers to manipulate login credentials. Attackers can inject malicious SQL code through the 'password' POST parameter to bypass authentication and potentially gain unauthorized access to the system.

CVE-2023-53968
Screen SFT DAB 600/C Web
9.3
CRITICAL
EPSS
0.6%
2023 CWE-306 2 PoCs

Screen SFT DAB 600/C Firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to remove user accounts without proper authentication.

CVE-2023-53963
Impact/Pulse/First Web
9.3
CRITICAL
EPSS
2.9%
2023 CWE-78 2 PoCs

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands through the 'password' parameter. Attackers can exploit the login.php and index.php scripts by injecting shell commands via the 'password' POST parameter to execute commands with web server privileges.

CVE-2023-2507
Cordova Plugin Web
9.3
CRITICAL
EPSS
0.1%
2023 CWE-79 1 PoC

CleverTap Cordova Plugin version 2.6.2 allows a remote attacker to execute JavaScript code in any application that is opened via a specially constructed deeplink by an attacker. This is possible because the plugin does not correctly validate the data coming from the deeplinks before using them.

CVE-2023-53895
PimpMyLog Web
9.3
CRITICAL
EPSS
0.7%
2023 CWE-285 1 PoC

PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts without authorization through the configuration endpoint. Attackers can exploit the unsanitized username field to inject malicious JavaScript, create a hidden backdoor account, and potentially access sensitive server-side log information and environmental variables.

CVE-2023-42789
FortiOS Web Networking
9.3
CRITICAL
EPSS
30.0%
2023 CWE-787 2 PoCs

A out-of-bounds write in Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.

CVE-2023-7304
RG-UAC Web
9.3
CRITICAL
EPSS
2.5%
2023 CWE-78 1 PoC

Ruijie RG-UAC Application Management Gateway contains a command injection vulnerability via the 'nmc_sync.php' interface. An unauthenticated attacker able to reach the affected endpoint can inject shell commands via crafted request data, causing the application to execute arbitrary commands on the host. Successful exploitation can yield full control of the application process and may lead to system-level access depending on the service privileges. VulnCheck has observed this vulnerability being targeted by the RondoDox botnet campaign.

CVE-2023-54335
eXtplorer Web
9.3
CRITICAL
EPSS
0.6%
2023 CWE-306 1 PoC

eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this flaw to upload malicious PHP files and execute remote commands on the vulnerable file management system.

CVE-2023-54327
LAN Controller Web
9.3
CRITICAL
EPSS
2.0%
2023 CWE-862 2 PoCs

Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request. Attackers can exploit the /stm.cgi endpoint with a specially crafted authentication parameter to disable access controls and modify administrative credentials.

CVE-2023-53914
Ulicms Web
9.3
CRITICAL
EPSS
1.8%
2023 CWE-639 1 PoC

UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in the UserController. Attackers can send a crafted POST request to the admin index.php endpoint with specific parameters to generate an administrative account with full system access.

CVE-2023-53872
Wp2Fac Web
9.3
CRITICAL
EPSS
0.9%
2023 CWE-78 1 PoC

Wp2Fac 1.0 contains an OS command injection vulnerability in the send.php endpoint that allows remote attackers to execute arbitrary system commands. Attackers can inject shell commands through the 'numara' parameter by appending shell commands with '&' operators to execute malicious code.

CVE-2023-53923
Ulicms Web
9.3
CRITICAL
EPSS
0.2%
2023 CWE-862 1 PoC

UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrative accounts through the UserController endpoint. Attackers can send a crafted POST request to /dist/admin/index.php with specific parameters to generate a new admin user with full system access.

CVE-2023-6013
h2oai/h2o-3 Web
9.3
CRITICAL
EPSS
0.2%
2023 CWE-79 1 PoC

H2O is vulnerable to stored XSS vulnerability which can lead to a Local File Include attack.

CVE-2023-1244
answerdev/answer Web
9.3
CRITICAL
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2023-53881
ReyeeOS Web Cloud
9.2
CRITICAL
EPSS
0.1%
2023 CWE-319 1 PoC

ReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manipulate device communication through a man-in-the-middle attack. Attackers can create a fake CWMP server to inject and execute arbitrary commands on Ruijie Reyee Cloud devices by exploiting the unprotected HTTP polling requests.

CVE-2023-23465
Media Control Panel Web
9.1
CRITICAL
EPSS
0.1%
2023 CWE-352 1 PoC

Media CP Media Control Panel latest version. CSRF possible through unspecified endpoint.