5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-22306
UR32L General
7.2
HIGH
EPSS
0.3%
2023 CWE-77 2 PoCs

An OS command injection vulnerability exists in the libzebra.so bridge_group functionality of Milesight UR32L v32.3.0.5. A specially crafted network packet can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-27498
Host Agent (SAPOSCOL) General
7.2
HIGH
EPSS
0.4%
2023 CWE-121 1 PoC

SAP Host Agent (SAPOSCOL) - version 7.22, allows an unauthenticated attacker with network access to a server port assigned to the SAP Start Service to submit a crafted request which results in a memory corruption error. This error can be used to reveal but not modify any technical information about the server. It can also make a particular service temporarily unavailable

CVE-2023-25100
UR32L Web
7.2
HIGH
EPSS
0.2%
2023 CWE-121 2 PoCs

Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_qos function with the default_class variable.

CVE-2023-2655
Contact Form by WD Web Database Windows
7.2
HIGH
EPSS
0.7%
2023 1 PoC

The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2023-49978
Software Genérico General
7.2
HIGH
EPSS
0.5%
2023 2 PoCs

Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for administrators.

CVE-2023-27380
Surf SOHO HW1 Web
7.2
HIGH
EPSS
0.4%
2023 CWE-78 1 PoC

An OS command injection vulnerability exists in the admin.cgi USSD_send functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2023-1762
thorsten/phpmyfaq Web
7.2
HIGH
EPSS
0.4%
2023 CWE-269 1 PoC

Improper Privilege Management in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2023-33919
CP-8031 MASTER MODULE General
7.2
HIGH
EPSS
9.8%
2023 CWE-77 4 PoCs

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.

CVE-2023-48270
WBR-6013 General
7.2
HIGH
EPSS
0.5%
2023 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in the boa formDnsv6 functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-25081
UR32L Web Networking
7.2
HIGH
EPSS
0.1%
2023 CWE-121 2 PoCs

Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the firewall_handler_set function with the src and dmz variables.

CVE-2023-4238
Prevent files / folders access Web Windows
7.2
HIGH
EPSS
24.7%
2023 2 PoCs

The Prevent files / folders access WordPress plugin before 2.5.2 does not validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.

CVE-2023-49593
WBR-6013 General
7.2
HIGH
EPSS
0.3%
2023 CWE-489 2 PoCs

Leftover debug code exists in the boa formSysCmd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A specially crafted network request can lead to arbitrary command execution.

CVE-2023-39201
CleanZoom General
7.2
HIGH
EPSS
0.1%
2023 CWE-426 1 PoC

Untrusted search path in CleanZoom before file date 07/24/2023 may allow a privileged user to conduct an escalation of privilege via local access.

CVE-2023-25583
UR32L General
7.2
HIGH
EPSS
0.3%
2023 CWE-78 2 PoCs

Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the code branch that manages a new vlan configuration.

CVE-2023-1347
Customizer Export/Import Web Windows
7.2
HIGH
EPSS
5.9%
2023 1 PoC

The Customizer Export/Import WordPress plugin before 0.9.6 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present

CVE-2023-26609
Software Genérico General
7.2
HIGH
EPSS
37.2%
2023 4 PoCs

ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin/mft/wireless_mft ap field.

CVE-2023-6222
Quttera Web Malware Scanner Web Windows
7.2
HIGH
EPSS
0.4%
2023 2 PoCs

IThe Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 does not validate user input used in a path, which could allow users with an admin role to perform path traversal attacks

CVE-2023-53888
Zomplog Web
7.2
HIGH
EPSS
0.9%
2023 CWE-94 1 PoC

Zomplog 3.9 contains a remote code execution vulnerability that allows authenticated attackers to inject and execute arbitrary PHP code through file manipulation endpoints. Attackers can upload malicious JavaScript files, rename them to PHP, and execute system commands by exploiting the saveE and rename actions in the application.

CVE-2023-49867
WBR-6013 Web
7.2
HIGH
EPSS
7.3%
2023 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send a series of HTTP requests to trigger this vulnerability.

CVE-2023-5957
Ni Purchase Order(PO) For WooCommerce Web Windows
7.2
HIGH
EPSS
0.6%
2023 1 PoC

The Ni Purchase Order(PO) For WooCommerce WordPress plugin through 1.2.1 does not validate logo and signature image files uploaded in the settings, allowing high privileged user to upload arbitrary files to the web server, triggering an RCE vulnerability by uploading a web shell.