5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-36645
Software Genérico Database
9.1
CRITICAL
EPSS
0.2%
2023 1 PoC

SQL injection vulnerability in ITB-GmbH TradePro v9.5, allows remote attackers to run SQL queries via oordershow component in customer function.

CVE-2023-5754
PolyEco1000 General
9.1
CRITICAL
EPSS
0.1%
2023 CWE-307 1 PoC

Sielco PolyEco1000 uses a weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system.

CVE-2023-28762
SAP BusinessObjects Intelligence Platform General
9.1
CRITICAL
EPSS
0.2%
2023 CWE-200 1 PoC

SAP BusinessObjects Business Intelligence Platform - versions 420, 430, allows an authenticated attacker with administrator privileges to get the login token of any logged-in BI user over the network without any user interaction. The attacker can impersonate any user on the platform resulting into accessing and modifying data. The attacker can also make the system partially or entirely unavailable.

CVE-2023-23459
Priority for Windows Database Windows
9.1
CRITICAL
EPSS
0.4%
2023 CWE-89 1 PoC

Priority Windows may allow Command Execution via SQL Injection using an unspecified method.

CVE-2023-29201
xwiki-commons Web
9.1
CRITICAL
EPSS
9.3%
2023 CWE-79 1 PoC

XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1, only escaped `<script>` and `<style>`-tags but neither attributes that can be used to inject scripts nor other dangerous HTML tags like `<iframe>`. As a consequence, any code relying on this "restricted" mode for security is vulnerable to JavaScript injection ("cross-site scripting"/XSS). When a privileged user with programming rights visits such a comment in XWiki, the malicious JavaScript code is executed in the con

CVE-2023-1721
Yoga Class Registration System General
9.1
CRITICAL
EPSS
0.1%
2023 CWE-434 2 PoCs

Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators.

CVE-2023-29519
xwiki-platform General
9.1
CRITICAL
EPSS
4.7%
2023 CWE-74 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A registered user can perform remote code execution leading to privilege escalation by injecting the proper code in the "property" field of an attachment selector, as a gadget of their own dashboard. Note that the vulnerability does not impact comments of a wiki. The vulnerability has been patched in XWiki 13.10.11, 14.4.8, 14.10.2, 15.0-rc-1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2023-5832
mintplex-labs/anything-llm General
9.1
CRITICAL
EPSS
0.1%
2023 CWE-20 1 PoC

Improper Input Validation in GitHub repository mintplex-labs/anything-llm prior to 0.1.0.

CVE-2023-30769
Node General
9.1
CRITICAL
EPSS
1.3%
2023 CWE-400 2 PoCs

Vulnerability discovered is related to the peer-to-peer (p2p) communications, attackers can craft consensus messages, send it to individual nodes and take them offline. An attacker can crawl the network peers using getaddr message and attack the unpatched nodes.

CVE-2023-40275
Software Genérico General
9.1
CRITICAL
EPSS
0.6%
2023 2 PoCs

An issue was discovered in OpenClinic GA 5.247.01. It allows retrieval of patient lists via queries such as findFirstname= to _common/search/searchByAjax/patientslistShow.jsp.

CVE-2023-45146
xxl-rpc General
9.1
CRITICAL
EPSS
3.6%
2023 CWE-502 1 PoC

XXL-RPC is a high performance, distributed RPC framework. With it, a TCP server can be set up using the Netty framework and the Hessian serialization mechanism. When such a configuration is used, attackers may be able to connect to the server and provide malicious serialized objects that, once deserialized, force it to execute arbitrary code. This can be abused to take control of the machine the server is running by way of remote code execution. This issue has not been fixed.

CVE-2023-46501
Software Genérico General
9.1
CRITICAL
EPSS
10.9%
2023 1 PoC

An issue in BoltWire v.6.03 allows a remote attacker to obtain sensitive information via a crafted payload to the view and change admin password function.

CVE-2023-39172
Storage Box V1 General
9.1
CRITICAL
EPSS
0.4%
2023 CWE-319 2 PoCs

The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture and modify network traffic.

CVE-2023-5841
OpenEXR General
9.1
CRITICAL
EPSS
0.8%
2023 CWE-122 1 PoC

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.

CVE-2023-31126
xwiki-commons Web
9.1
CRITICAL
EPSS
2.7%
2023 CWE-86 1 PoC

`org.xwiki.commons:xwiki-commons-xml` is an XML library used by the open-source wiki platform XWiki. The HTML sanitizer, introduced in version 14.6-rc-1, allows the injection of arbitrary HTML code and thus cross-site scripting via invalid data attributes. This vulnerability does not affect restricted cleaning in HTMLCleaner as there attributes are cleaned and thus characters like `/` and `>` are removed in all attribute names. This problem has been patched in XWiki 14.10.4 and 15.0 RC1 by making sure that data attributes only contain allowed characters. There are no known workarounds apart fr

CVE-2023-27290
Observability with Instana DevOps
9.1
CRITICAL
EPSS
8.5%
2023 CWE-306 1 PoC

Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/write access. IBM X-Force ID: 248737.

CVE-2023-45685
Titan MFT Windows
9.1
CRITICAL
EPSS
0.4%
2023 CWE-22 1 PoC

Insufficient path validation when extracting a zip archive in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux allows an authenticated attacker to write a file to any location on the filesystem via path traversal

CVE-2023-2227
modoboa/modoboa General ⚡ nuclei
9.1
CRITICAL
EPSS
90.5%
2023 CWE-285 1 PoC

Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0.

CVE-2023-1722
Yoga Class Registration System General
9.1
CRITICAL
EPSS
0.1%
2023 CWE-352 2 PoCs

Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators.

CVE-2023-25725
Software Genérico Web
9.1
CRITICAL
EPSS
20.0%
2023 2 PoCs

HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3, the impact is limited because the headers disappear before being parsed and processed, as if they had not been sent by the client. The fixed versions are 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31