5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-24344
Software Genérico Networking
8.8
HIGH
EPSS
0.6%
2023 1 PoC

D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWlanGuestSetup.

CVE-2023-24346
Software Genérico Networking
8.8
HIGH
EPSS
0.8%
2023 1 PoC

D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the wan_connected parameter at /goform/formEasySetupWizard3.

CVE-2023-6140
Essential Real Estate Web Windows
8.8
HIGH
EPSS
3.9%
2023 1 PoC

The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentarily uploading malicious PHP files disguised as ZIP archives, which may lead to remote code execution.

CVE-2023-22299
UR32L General
8.8
HIGH
EPSS
0.5%
2023 CWE-78 1 PoC

An OS command injection vulnerability exists in the vtysh_ubus _get_fw_logs functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.

CVE-2023-1714
Bitrix24 Web
8.8
HIGH
EPSS
2.8%
2023 CWE-502 2 PoCs

Unsafe variable extraction in bitrix/modules/main/classes/general/user_options.php in Bitrix24 22.0.300 allows remote authenticated attackers to execute arbitrary code via (1) appending arbitrary content to existing PHP files or (2) PHAR deserialization.

CVE-2023-33284
Software Genérico General
8.8
HIGH
EPSS
1.2%
2023 1 PoC

Marval MSM through 14.19.0.12476 and 15.0 has a Remote Code Execution vulnerability. A remote attacker authenticated as any user is able to execute code in context of the web server.

CVE-2023-22952
🔥 KEV Software Genérico Web ⚡ nuclei
8.8
HIGH
EPSS
92.8%
2023 1 PoC

In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.

CVE-2023-2674
openemr/openemr General
8.8
HIGH
EPSS
0.3%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.

CVE-2023-38543
Secure Access Client Windows Windows
8.8
HIGH
EPSS
0.2%
2023 1 PoC

A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine.

CVE-2023-48171
Software Genérico General
8.8
HIGH
EPSS
1.1%
2023 1 PoC

An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.

CVE-2023-50232
Ignition General
8.8
HIGH
EPSS
2.2%
2023 CWE-88 1 PoC

Inductive Automation Ignition getParams Argument Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this vulnerability in that the target must connect to a malicious server. The specific flaw exists within the getParams method. The issue results from the lack of proper validation of a user-supplied string before using it to prepare an argument for a system call. An attacker can leverage this vulnerability to execute code in the co

CVE-2023-32073
AVideo Web
8.8
HIGH
EPSS
5.6%
2023 CWE-77 1 PoC

WWBN AVideo is an open source video platform. In versions 12.4 and prior, a command injection vulnerability exists at `plugin/CloneSite/cloneClient.json.php` which allows Remote Code Execution if you CloneSite Plugin. This is a bypass to the fix for CVE-2023-30854, which affects WWBN AVideo up to version 12.3. This issue is patched in commit 1df4af01f80d56ff2c4c43b89d0bac151e7fb6e3.

CVE-2023-33538
🔥 KEV Software Genérico General
8.8
HIGH
EPSS
90.6%
2023 2 PoCs

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm .

CVE-2023-46478
Software Genérico General
8.8
HIGH
EPSS
2.2%
2023 2 PoCs

An issue in minCal v.1.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the customer_data parameter.

CVE-2023-6580
DIR-846 General
8.8
HIGH
EPSS
0.2%
2023 CWE-502 1 PoC

A vulnerability, which was classified as critical, was found in D-Link DIR-846 FW100A53DBR. This affects an unknown part of the file /HNAP1/ of the component QoS POST Handler. The manipulation of the argument smartqos_express_devices/smartqos_normal_devices leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247161 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-24269
Software Genérico General
8.8
HIGH
EPSS
0.4%
2023 1 PoC

An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Zip file.

CVE-2023-49502
Software Genérico Networking
8.8
HIGH
EPSS
0.2%
2023 1 PoC

Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the ff_bwdif_filter_intra_c function in the libavfilter/bwdifdsp.c:125:5 component.

CVE-2023-6700
Cookie Information | Free GDPR Consent Solution Web Windows
8.8
HIGH
EPSS
29.2%
2023 CWE-862 1 PoC

The Cookie Information | Free GDPR Consent Solution plugin for WordPress is vulnerable to arbitrary option updates due to a missing capability check on its AJAX request handler in versions up to, and including, 2.0.22. This makes it possible for authenticated attackers, with subscriber-level access or higher, to edit arbitrary site options which can be used to create administrator accounts.

CVE-2023-4223
Chamilo Web
8.8
HIGH
EPSS
2.6%
2023 CWE-434 1 PoC

Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.