5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-4724
Export any WordPress data to XML/CSV Web Windows
7.2
HIGH
EPSS
1.0%
2023 1 PoC

The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not validate and sanitise the `wp_query` parameter which allows an attacker to run arbitrary command on the remote server

CVE-2023-0771
ampache/ampache Database
7.2
HIGH
EPSS
0.3%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository ampache/ampache prior to 5.5.7,develop.

CVE-2023-25122
UR32L Web Networking
7.2
HIGH
EPSS
0.2%
2023 CWE-121 2 PoCs

Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_openvpn_client function with the old_remote_subnet and the old_remote_mask variables.

CVE-2023-31740
Software Genérico Networking
7.2
HIGH
EPSS
0.6%
2023 1 PoC

There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, they can inject commands into the post request parameters WL_atten_bb, WL_atten_radio, and WL_atten_ctl in the apply.cgi interface, thereby gaining shell privileges.

CVE-2023-0900
Pricing Table Builder Web Database Windows ⚡ nuclei
7.2
HIGH
EPSS
6.4%
2023 1 PoC

The Pricing Table Builder WordPress plugin through 1.1.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high-privilege users such as admins.

CVE-2023-49073
WBR-6013 Web
7.2
HIGH
EPSS
0.5%
2023 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in the boa formFilter functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2023-1549
Ad Inserter Web Windows
7.2
HIGH
EPSS
18.1%
2023 1 PoC

The Ad Inserter WordPress plugin before 2.7.27 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present

CVE-2023-25121
UR32L Web
7.2
HIGH
EPSS
0.2%
2023 CWE-121 2 PoCs

Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_ike_profile function with the secrets_local variable.

CVE-2023-31741
Software Genérico Web Networking
7.2
HIGH
EPSS
0.6%
2023 1 PoC

There is a command injection vulnerability in the Linksys E2000 router with firmware version 1.0.06. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ssid, wl_ant, wl_rate, WL_atten_ctl, ttcp_num, ttcp_size in the httpd s Start_EPI() function, thereby gaining shell privileges.

CVE-2023-49912
AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) Web
7.2
HIGH
EPSS
0.9%
2023 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.This vulnerability refers specifically to the overflow that occurs via the `profile` parameter at offset `0x4224b0` of the `httpd` binary shipped with v5.0.4 Build 20220216 of the EAP115.

CVE-2023-0046
lirantal/daloradius General
7.2
HIGH
EPSS
0.4%
2023 CWE-641 1 PoC

Improper Restriction of Names for Files and Other Resources in GitHub repository lirantal/daloradius prior to master-branch.

CVE-2023-42661
Artifactory General
7.2
HIGH
EPSS
1.3%
2023 CWE-20 1 PoC

JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution when a specially crafted series of requests is sent by an authenticated user. This is due to insufficient validation of artifacts.

CVE-2023-4259
Zephyr General
7.1
HIGH
EPSS
0.2%
2023 CWE-120 1 PoC

Two potential buffer overflow vulnerabilities at the following locations in the Zephyr eS-WiFi driver source code.

CVE-2023-0519
modoboa/modoboa Web
7.1
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository modoboa/modoboa prior to 2.0.4.

CVE-2023-45896
Software Genérico Cloud
7.1
HIGH
EPSS
0.1%
2023 1 PoC

ntfs3 in the Linux kernel through 6.8.0 allows a physically proximate attacker to read kernel memory by mounting a filesystem (e.g., if a Linux distribution is configured to allow unprivileged mounts of removable media) and then leveraging local access to trigger an out-of-bounds read. A length value can be larger than the amount of memory allocated. NOTE: the supplier's perspective is that there is no vulnerability when an attack requires an attacker-modified filesystem image.

CVE-2023-0793
thorsten/phpmyfaq Web
7.1
HIGH
EPSS
0.2%
2023 CWE-521 1 PoC

Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

CVE-2023-21750
Windows 10 Version 1809 Windows
7.1
HIGH
EPSS
2.7%
2023 CWE-284 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-7174
aBitGone CommentSafe Web Windows
7.1
HIGH
EPSS
0.1%
2023 1 PoC

The aBitGone CommentSafe WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2023-0108
usememos/memos Web
7.1
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

CVE-2023-3268
Kernel General
7.1
HIGH
EPSS
0.0%
2023 CWE-125 1 PoC

An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs. This flaw could allow a local attacker to crash the system or leak kernel internal information.