5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-2507
Cordova Plugin Web
9.3
CRITICAL
EPSS
0.1%
2023 CWE-79 1 PoC

CleverTap Cordova Plugin version 2.6.2 allows a remote attacker to execute JavaScript code in any application that is opened via a specially constructed deeplink by an attacker. This is possible because the plugin does not correctly validate the data coming from the deeplinks before using them.

CVE-2023-53963
Impact/Pulse/First Web
9.3
CRITICAL
EPSS
2.9%
2023 CWE-78 2 PoCs

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands through the 'password' parameter. Attackers can exploit the login.php and index.php scripts by injecting shell commands via the 'password' POST parameter to execute commands with web server privileges.

CVE-2023-42662
Artifactory General
9.3
CRITICAL
EPSS
0.3%
2023 CWE-287 1 PoC

JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO integration.

CVE-2023-53881
ReyeeOS Web Cloud
9.2
CRITICAL
EPSS
0.1%
2023 CWE-319 1 PoC

ReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manipulate device communication through a man-in-the-middle attack. Attackers can create a fake CWMP server to inject and execute arbitrary commands on Ruijie Reyee Cloud devices by exploiting the unprotected HTTP polling requests.

CVE-2023-27997
🔥 KEV FortiOS-6K7K Networking
9.2
CRITICAL
EPSS
90.2%
2023 CWE-122 17 PoCs

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.

CVE-2023-25581
pac4j General
9.2
CRITICAL
EPSS
19.0%
2023 CWE-502 1 PoC

pac4j is a security framework for Java. `pac4j-core` prior to version 4.0.0 is affected by a Java deserialization vulnerability. The vulnerability affects systems that store externally controlled values in attributes of the `UserProfile` class from pac4j-core. It can be exploited by providing an attribute that contains a serialized Java object with a special prefix `{#sb64}` and Base64 encoding. This issue may lead to Remote Code Execution (RCE) in the worst case. Although a `RestrictedObjectInputStream` is in place, that puts some restriction on what classes can be deserialized, it still allo

CVE-2023-7305
SmartBI General
9.2
CRITICAL
EPSS
0.2%
2023 CWE-434 2 PoCs

SmartBI V8, V9, and V10 contain an unrestricted file upload vulnerability via the RMIServlet request handling logic. Under certain configurations or usage patterns, attackers can send specially crafted requests that cause the application to perform sensitive operations or execute arbitrary code on the host. The vendor released a fix in July 2023 to address the underlying flaw. VulnCheck has observed this vulnerability being exploited in the wild.

CVE-2023-26216
TIBCO EBX Add-ons General
9.1
CRITICAL
EPSS
0.3%
2023 1 PoC

The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an exploitable vulnerability that allows an attacker to upload files to a directory accessible by the web server. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.5.16 and below.

CVE-2023-32071
xwiki-platform Web Networking
9.1
CRITICAL
EPSS
46.8%
2023 CWE-116 1 PoC

XWiki Platform is a generic wiki platform. Starting in versions 2.2-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, it's possible to execute javascript with the right of any user by leading him to a special URL on the wiki targeting a page which contains an attachment. This has been patched in XWiki 15.0-rc-1, 14.10.4, and 14.4.8. The easiest possible workaround is to edit file `<xwiki app>/templates/importinline.vm` and apply the modification described in commit 28905f7f518cc6f21ea61fe37e9e1ed97ef36f01.

CVE-2023-31056
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2023 1 PoC

CloverDX before 5.17.3 writes passwords to the audit log in certain situations, if the audit log is enabled and single sign-on is not employed. The fixed versions are 5.15.4, 5.16.2, 5.17.3, and 6.0.x.

CVE-2023-0587
Trend Micro Apex One Web
9.1
CRITICAL
EPSS
14.5%
2023 1 PoC

A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length header in an HTTP PUT message sent to URL /officescan/console/html/cgi/fcgiOfcDDA.exe, an unauthenticated remote attacker can upload arbitrary files to the SampleSubmission directory (i.e., \PCCSRV\TEMP\SampleSubmission) on the server. The attacker can upload a large number of large files to fill up the file system on which the Apex One server is installed.

CVE-2023-36471
xwiki-commons General
9.1
CRITICAL
EPSS
0.9%
2023 CWE-74 1 PoC

Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki since version 14.6RC1 allowed form and input HTML tags. In the context of XWiki, this allows an attacker without script right to either create forms that can be used for phishing attacks or also in the context of a sheet, the attacker could add an input like `{{html}}<input type="hidden" name="content" value="{{groovy}}println(&quot;Hello from Groovy!&quot;)" />{{/html}}` that would allow remote code execution when it is submitted by an admin (the sheet is rendered as part o

CVE-2023-41807
Pandora FMS General
9.1
CRITICAL
EPSS
0.0%
2023 CWE-269 1 PoC

Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability allows a user to escalate permissions on the system shell. This issue affects Pandora FMS: from 700 through 773.

CVE-2023-29386
Manager for Icomoon General
9.1
CRITICAL
EPSS
0.3%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Julien Crego Manager for Icomoon.This issue affects Manager for Icomoon: from n/a through 2.0.

CVE-2023-7006
Kontrol Lux General
9.1
CRITICAL
EPSS
0.1%
2023 1 PoC

The unlockKey character in a lock using Sciener firmware can be brute forced through repeated challenge requests, compromising the locks integrity.

CVE-2023-48023
Software Genérico General ⚡ nuclei
9.1
CRITICAL
EPSS
89.2%
2023 0 PoCs

Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment

CVE-2023-49785
NextChat Web ⚡ nuclei
9.1
CRITICAL
EPSS
90.4%
2023 CWE-918 1 PoC

NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 and prior are vulnerable to server-side request forgery and cross-site scripting. This vulnerability enables read access to internal HTTP endpoints but also write access using HTTP POST, PUT, and other methods. Attackers can also use this vulnerability to mask their source IP by forwarding malicious traffic intended for other Internet targets through these open proxies. As of time of publication, no patch is available, but other mitigation strategies are available. Users may

CVE-2023-23465
Media Control Panel Web
9.1
CRITICAL
EPSS
0.1%
2023 CWE-352 1 PoC

Media CP Media Control Panel latest version. CSRF possible through unspecified endpoint.

CVE-2023-3551
nilsteampassnet/teampass General
9.1
CRITICAL
EPSS
0.2%
2023 CWE-94 1 PoC

Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10.