33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-2024
OpenBlue Enterprise Manager Data Collector General
10.0
CRITICAL
EPSS
0.3%
2023 CWE-287 2 PoCs

Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances.

CVE-2023-51409
AI Engine: ChatGPT Chatbot General ⚡ nuclei
10.0
CRITICAL
EPSS
92.9%
2023 CWE-434 4 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 1.9.98.

CVE-2023-7309
Smart Park Integrated Management Platform General
10.0
CRITICAL
EPSS
2.1%
2023 CWE-434 2 PoCs

A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated Management Platform), affecting the SOAP-based GIS bitmap upload interface. The flaw allows unauthenticated remote attackers to upload arbitrary files to the server via crafted SOAP requests, including executable JSP payloads. Successful exploitation may lead to remote code execution (RCE) and full compromise of the affected system. The vulnerability is presumed to affect builds released prior to September 2023 and is said to be remediated in newer

CVE-2023-2564
sbs20/scanservjs General
10.0
CRITICAL
EPSS
29.3%
2023 CWE-78 1 PoC

OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0.

CVE-2023-7028
🔥 KEV GitLab DevOps ⚡ nuclei
10.0
CRITICAL
EPSS
93.8%
2023 CWE-640 19 PoCs

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

CVE-2023-4309
Internet Election Service Networking Database
10.0
CRITICAL
EPSS
0.6%
2023 CWE-89 1 PoC

Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. These vulnerabilities allow an unauthenticated, remote attacker to read or modify data for any elections that share the same backend database. ESC deactivated older and unused elections and enabled web application firewall (WAF) protection for current and future elections on or around 2023-08-12.

CVE-2023-2583
jsreport/jsreport General
10.0
CRITICAL
EPSS
0.1%
2023 CWE-94 1 PoC

Code Injection in GitHub repository jsreport/jsreport prior to 3.11.3.

CVE-2023-1523
snapd General
10.0
CRITICAL
EPSS
0.1%
2023 1 PoC

Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed outside of the snap sandbox after the snap exits. Graphical terminal emulators like xterm, gnome-terminal and others are not affected - this can only be exploited when snaps are run on a virtual console.

CVE-2023-29205
xwiki-platform Web
10.0
CRITICAL
EPSS
2.1%
2023 CWE-79 1 PoC

XWiki Commons are technical libraries common to several other top level XWiki projects. The HTML macro does not systematically perform a proper neutralization of script-related html tags. As a result, any user able to use the html macro in XWiki, is able to introduce an XSS attack. This can be particularly dangerous since in a standard wiki, any user is able to use the html macro directly in their own user profile page. The problem has been patched in XWiki 14.8RC1. The patch involves the HTML macros and are systematically cleaned up whenever the user does not have the script correct.

CVE-2023-29384
WordPress Job Board and Recruitment Plugin – JobWP Web Windows
10.0
CRITICAL
EPSS
4.1%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in HM Plugin WordPress Job Board and Recruitment Plugin – JobWP.This issue affects WordPress Job Board and Recruitment Plugin – JobWP: from n/a through 2.0.

CVE-2023-6269
OpenScape Session Border Controller (SBC) Networking
10.0
CRITICAL
EPSS
0.5%
2023 CWE-88 3 PoCs

An argument injection vulnerability has been identified in the administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" before versions V10R10.12.00 and V10R11.05.02. This allows an unauthenticated attacker to gain root access to the appliance via SSH (scope change) and also bypass authentication for the administrative interface and gain access as an arbitrary (administrative) user.

CVE-2023-22621
Software Genérico Web ⚡ nuclei
10.0
CRITICAL
EPSS
91.0%
2023 3 PoCs

Strapi through 4.5.5 allows authenticated Server-Side Template Injection (SSTI) that can be exploited to execute arbitrary code on the server. A remote attacker with access to the Strapi admin panel can inject a crafted payload that executes code on the server into an email template that bypasses the validation checks that should prevent code execution.

CVE-2023-2138
nuxtlabs/github-module General
10.0
CRITICAL
EPSS
0.4%
2023 CWE-798 1 PoC

Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2.

CVE-2023-49103
🔥 KEV Software Genérico DevOps Web Cloud ⚡ nuclei
10.0
CRITICAL
EPSS
94.3%
2023 5 PoCs

An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo). This information includes all the environment variables of the webserver. In containerized deployments, these environment variables may include sensitive data such as the ownCloud admin password, mail server credentials, and license key. Simply disabling the graphapi app does not eliminate the vulnerability. Additional

CVE-2023-6016
h2oai/h2o-3 General
10.0
CRITICAL
EPSS
68.2%
2023 CWE-94 1 PoC

An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature.

CVE-2023-35082
🔥 KEV EPMM General ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2023 1 PoC

An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

CVE-2023-3765
mlflow/mlflow General ⚡ nuclei
10.0
CRITICAL
EPSS
91.5%
2023 CWE-36 1 PoC

Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.

CVE-2023-40044
🔥 KEV WS_FTP Server General ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2023 CWE-502 6 PoCs

In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.

CVE-2023-20198
🔥 KEV Cisco IOS XE Software Networking ⚡ nuclei
10.0
CRITICAL
EPSS
94.0%
2023 CWE-420 33 PoCs

Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new local

CVE-2023-42770
ST-IPm-8460 General
10.0
CRITICAL
EPSS
0.2%
2023 CWE-288 1 PoC

Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message is received over TCP/IP the RTU will simply accept the message with no authentication challenge.