33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-51717
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass.

CVE-2023-24198
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Raffle Draw System v1.0 was discovered to contain multiple SQL injection vulnerabilities at save_winner.php via the ticket_id and draw parameters.

CVE-2023-34039
Aria Operations for Networks Networking
9.8
CRITICAL
EPSS
93.2%
2023 7 PoCs

Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI.

CVE-2023-32222
DSL-G256DG firmware version vBZ_1.00.27 General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

D-Link DSL-G256DG version vBZ_1.00.27 web management interface allows authentication bypass via an unspecified method.

CVE-2023-46661
PolyEco1000 General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-284 1 PoC

Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests.

CVE-2023-28504
UniData General
9.8
CRITICAL
EPSS
2.0%
2023 CWE-120 1 PoC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow that can lead to remote code execution as the root user.

CVE-2023-2732
MStore API – Create Native Android & iOS Apps On The Cloud Web Cloud Windows ⚡ nuclei
9.8
CRITICAL
EPSS
90.3%
2023 CWE-288 5 PoCs

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.

CVE-2023-49543
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 2 PoCs

Incorrect access control in Book Store Management System v1 allows attackers to access unauthorized pages and execute administrative functions without authenticating.

CVE-2023-39667
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the FUN_0000acb4 function.

CVE-2023-1650
AI ChatBot Web Windows
9.8
CRITICAL
EPSS
48.8%
2023 1 PoC

The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could allow them to perform PHP Object Injection when a suitable gadget is present on the blog

CVE-2023-23902
UR32L Web
9.8
CRITICAL
EPSS
2.3%
2023 CWE-121 1 PoC

A buffer overflow vulnerability exists in the uhttpd login functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to remote code execution. An attacker can send a network request to trigger this vulnerability.

CVE-2023-24800
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_495220 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-24202
Software Genérico Web
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php.

CVE-2023-48022
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
92.2%
2023 4 PoCs

Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment. (Also, within that environment, customers at version 2.52.0 and later can choose to use token authentication.)

CVE-2023-34752
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
30.2%
2023 1 PoC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.

CVE-2023-46980
Software Genérico General
9.8
CRITICAL
EPSS
7.5%
2023 3 PoCs

An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the userID parameter.

CVE-2023-33584
Software Genérico Database
9.8
CRITICAL
EPSS
30.7%
2023 4 PoCs

Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the username and password fields during the login process, enabling an attacker to inject malicious SQL code.

CVE-2023-29268
TIBCO Spotfire Statistics Services General
9.8
CRITICAL
EPSS
0.8%
2023 1 PoC

The Splus Server component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that allows an unauthenticated remote attacker to upload or modify arbitrary files within the web server directory on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Statistics Services: versions 11.4.10 and below, versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, and 12.0.2, versions 12.1.0 and 12.2.0.

CVE-2023-0856
Canon Office/Small Office Multifunction Printers and Laser Printers General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-121 1 PoC

Buffer overflow in IPP sides attribute process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i firmwa

CVE-2023-2780
mlflow/mlflow General ⚡ nuclei
9.8
CRITICAL
EPSS
86.8%
2023 CWE-29 1 PoC

Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1.