5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-27893
Solution Manager and ABAP managed systems General
8.8
HIGH
EPSS
5.1%
2023 CWE-94 1 PoC

An attacker authenticated as a user with a non-administrative role and a common remote execution authorization in SAP Solution Manager and ABAP managed systems (ST-PI) - versions 2088_1_700, 2008_1_710, 740, can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform.  Depending on the function executed, the attack can read or modify any user or application data and can make the application unavailable.

CVE-2023-38346
Software Genérico General
8.8
HIGH
EPSS
0.9%
2023 1 PoC

An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also processes files within an archive that have relative or absolute file paths. A developer using the "tarExtract" function may expect that the function will strip leading slashes from absolute paths or stop processing when encountering relative paths that are outside of the extraction path, unless otherwise forced. This could lead to unexpected and undocumented behavior, which in general could result in a directory traversal, and associated unexpected behavior.

CVE-2023-4980
librenms/librenms Web
8.8
HIGH
EPSS
0.0%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 23.9.0.

CVE-2023-25732
Firefox General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

When encoding data from an <code>inputStream</code> in <code>xpcom</code> the size of the input being encoded was not correctly calculated potentially leading to an out of bounds memory write. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVE-2023-38043
Secure Access Client Windows Windows
8.8
HIGH
EPSS
0.2%
2023 1 PoC

A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine and, in some cases, resulting in a full compromise of the system.

CVE-2023-32541
Hancom Office 2020 General
8.8
HIGH
EPSS
0.3%
2023 CWE-416 1 PoC

A use-after-free vulnerability exists in the footerr functionality of Hancom Office 2020 HWord 11.0.0.7520. A specially crafted .doc file can lead to a use-after-free. An attacker can trick a user into opening a malformed file to trigger this vulnerability.

CVE-2023-35744
DAP-2622 Networking
8.8
HIGH
EPSS
7.6%
2023 CWE-121 1 PoC

D-Link DAP-2622 DDP Configuration Restore Server IPv6 Address Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DDP service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of roo

CVE-2023-30765
Infrasuite Device Master General
8.8
HIGH
EPSS
0.9%
2023 CWE-269 1 PoC

​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contain improper access controls that could allow an attacker to alter privilege management configurations, resulting in privilege escalation.

CVE-2023-21707
Microsoft Exchange Server 2016 Cumulative Update 23 Windows
8.8
HIGH
EPSS
72.0%
2023 CWE-502 1 PoC

Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2023-24343
Software Genérico Networking
8.8
HIGH
EPSS
2.6%
2023 1 PoC

D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSchedule.

CVE-2023-29804
Software Genérico Windows
8.8
HIGH
EPSS
19.9%
2023 1 PoC

WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the sys_smb_pwdmod function.

CVE-2023-0184
NVIDIA GPU Display Driver Windows
8.8
HIGH
EPSS
0.1%
2023 CWE-822 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler which may lead to denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2023-50223
Ignition General
8.8
HIGH
EPSS
49.0%
2023 CWE-502 1 PoC

Inductive Automation Ignition ExtendedDocumentCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability. The specific flaw exists within the ExtendedDocumentCodec class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI

CVE-2023-40194
Foxit Reader Web
8.8
HIGH
EPSS
0.0%
2023 CWE-73 2 PoCs

An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to mistreatment of whitespace characters. A specially crafted malicious file can create files at arbitrary locations, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

CVE-2023-43478
Smart Modem Gen 2 (Arcadyan LH1000) General
8.8
HIGH
EPSS
4.1%
2023 1 PoC

fake_upload.cgi on the Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, allows unauthenticated attackers to upload firmware images and configuration backups, which could allow them to alter the firmware or the configuration on the device, ultimately leading to code execution as root. 

CVE-2023-0259
WP Google Review Slider Web Database Windows
8.8
HIGH
EPSS
0.5%
2023 1 PoC

The WP Google Review Slider WordPress plugin before 11.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as subscriber.

CVE-2023-38543
Secure Access Client Windows Windows
8.8
HIGH
EPSS
0.2%
2023 1 PoC

A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine.

CVE-2023-0234
SiteGround Security Web Database Windows
8.8
HIGH
EPSS
6.7%
2023 1 PoC

The SiteGround Security WordPress plugin before 1.3.1 does not properly sanitize user input before using it in an SQL query, leading to an authenticated SQL injection issue.

CVE-2023-49440
Software Genérico Database
8.8
HIGH
EPSS
0.0%
2023 2 PoCs

AhnLab EPP 1.0.15 is vulnerable to SQL Injection via the "preview parameter."