5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-2935
Chrome General
8.8
HIGH
EPSS
9.4%
2023 1 PoC

Type Confusion in V8 in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-46525
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function loginRegister.

CVE-2023-52042
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parameter.

CVE-2023-0220
Pinpoint Booking System Web Database Windows
8.8
HIGH
EPSS
0.7%
2023 1 PoC

The Pinpoint Booking System WordPress plugin before 2.9.9.2.9 does not validate and escape one of its shortcode attributes before using it in a SQL statement, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks.

CVE-2023-0234
SiteGround Security Web Database Windows
8.8
HIGH
EPSS
6.7%
2023 1 PoC

The SiteGround Security WordPress plugin before 1.3.1 does not properly sanitize user input before using it in an SQL query, leading to an authenticated SQL injection issue.

CVE-2023-38120
SR400ac Networking
8.8
HIGH
EPSS
2.1%
2023 CWE-78 1 PoC

Adtran SR400ac ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adtran SR400ac routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ping command, which is available over JSON-RPC. A crafted host parameter can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-

CVE-2023-32073
AVideo Web
8.8
HIGH
EPSS
5.6%
2023 CWE-77 1 PoC

WWBN AVideo is an open source video platform. In versions 12.4 and prior, a command injection vulnerability exists at `plugin/CloneSite/cloneClient.json.php` which allows Remote Code Execution if you CloneSite Plugin. This is a bypass to the fix for CVE-2023-30854, which affects WWBN AVideo up to version 12.3. This issue is patched in commit 1df4af01f80d56ff2c4c43b89d0bac151e7fb6e3.

CVE-2023-33782
Software Genérico General
8.8
HIGH
EPSS
52.2%
2023 2 PoCs

D-Link DIR-842V2 v1.0.3 was discovered to contain a command injection vulnerability via the iperf3 diagnostics function.

CVE-2023-6528
Slider Revolution Web Windows
8.8
HIGH
EPSS
15.8%
2023 1 PoC

The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.

CVE-2023-27216
Software Genérico General
8.8
HIGH
EPSS
27.8%
2023 3 PoCs

An issue found in D-Link DSL-3782 v.1.03 allows remote authenticated users to execute arbitrary code as root via the network settings page.

CVE-2023-46526
Software Genérico Cloud
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function resetCloudPwdRegister.

CVE-2023-31272
YF325 Web
8.8
HIGH
EPSS
0.2%
2023 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the httpd do_wds functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to stack-based buffer overflow. An attacker can send a network request to trigger this vulnerability.

CVE-2023-4033
mlflow/mlflow General
8.8
HIGH
EPSS
0.2%
2023 CWE-78 1 PoC

OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0.

CVE-2023-1389
🔥 KEV TP-Link Archer AX21 (AX1800) General ⚡ nuclei
8.8
HIGH
EPSS
93.5%
2023 5 PoCs

TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface. Specifically, the country parameter of the write operation was not sanitized before being used in a call to popen(), allowing an unauthenticated attacker to inject commands, which would be run as root, with a simple POST request.

CVE-2023-5798
Assistant Web Windows
8.8
HIGH
EPSS
0.2%
2023 1 PoC

The Assistant WordPress plugin before 1.4.4 does not validate a parameter before making a request to it via wp_remote_get(), which could allow users with a role as low as Editor to perform SSRF attacks

CVE-2023-32031
Microsoft Exchange Server 2019 Cumulative Update 12 Windows
8.8
HIGH
EPSS
42.1%
2023 CWE-502 1 PoC

Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2023-21529
🔥 KEV Microsoft Exchange Server 2019 Cumulative Update 12 Windows
8.8
HIGH
EPSS
29.3%
2023 CWE-502 1 PoC

Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2023-0080
Customer Reviews for WooCommerce Web Windows
8.8
HIGH
EPSS
1.4%
2023 1 PoC

The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also be achieved if the attacker manage to upload a malicious image containing PHP code, and then include it via the affected attribute, on a default WP install, authors could easily achieve that given that they have the upload_file capability.

CVE-2023-4354
Chrome General
8.8
HIGH
EPSS
2.0%
2023 1 PoC

Heap buffer overflow in Skia in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-35155
xwiki-platform Web ⚡ nuclei
8.8
HIGH
EPSS
47.0%
2023 CWE-79 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). For instance, the following URL execute an `alter` on the browser: `<xwiki-host>/xwiki/bin/view/Main/?viewer=share&send=1&target=&target=%3Cimg+src+onerror%3Dalert%28document.domain%29%3E+%3Cimg+src+onerror%3Dalert%28document.domain%29%3E+%3Crenniepak%40intigriti.me%3E&includeDocument=inline&message=I+wanted+to+share+this+page+with+you.`, where `<xwiki-host>` is the URL of your XWiki installation.