5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-34213
TN-5900 Series General
8.8
HIGH
EPSS
0.5%
2023 CWE-78 1 PoC

TN-5900 Series firmware versions v3.3 and prior are vulnerable to command-injection vulnerability. This vulnerability stems from insufficient input validation and improper authentication in the key-generation function, which could potentially allow malicious users to execute remote code on affected devices.

CVE-2023-4759
Eclipse JGit General
8.8
HIGH
EPSS
1.0%
2023 CWE-59 3 PoCs

Arbitrary File Overwrite in Eclipse JGit <= 6.6.0 In Eclipse JGit, all versions <= 6.6.0.202305301015-r, a symbolic link present in a specially crafted git repository can be used to write a file to locations outside the working tree when this repository is cloned with JGit to a case-insensitive filesystem, or when a checkout from a clone of such a repository is performed on a case-insensitive filesystem. This can happen on checkout (DirCacheCheckout), merge (ResolveMerger via its WorkingTreeUpdater), pull (PullCommand using merge), and when applying a patch (PatchApplier). This can be exploi

CVE-2023-51034
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi UploadFirmwareFile interface.

CVE-2023-2240
microweber/microweber General
8.8
HIGH
EPSS
0.3%
2023 CWE-269 1 PoC

Improper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4.

CVE-2023-22493
RSSHub Web Networking
8.8
HIGH
EPSS
0.1%
2023 CWE-918 1 PoC

RSSHub is an open source RSS feed generator. RSSHub is vulnerable to Server-Side Request Forgery (SSRF) attacks. This vulnerability allows an attacker to send arbitrary HTTP requests from the server to other servers or resources on the network. An attacker can exploit this vulnerability by sending a request to the affected routes with a malicious URL. An attacker could also use this vulnerability to send requests to internal or any other servers or resources on the network, potentially gain access to sensitive information that would not normally be accessible and amplifying the impact of the a

CVE-2023-39370
Softswitch Web
8.8
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

StarTrinity Softswitch version 2023-02-16 - Persistent XSS (CWE-79)

CVE-2023-3079
🔥 KEV Chrome General
8.8
HIGH
EPSS
2.1%
2023 3 PoCs

Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-22952
🔥 KEV Software Genérico Web ⚡ nuclei
8.8
HIGH
EPSS
92.8%
2023 1 PoC

In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.

CVE-2023-4352
Chrome General
8.8
HIGH
EPSS
1.4%
2023 1 PoC

Type confusion in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-25194
Apache Kafka Connect API Web ⚡ nuclei
8.8
HIGH
EPSS
94.1%
2023 CWE-502 4 PoCs

A possible security vulnerability has been identified in Apache Kafka Connect API. This requires access to a Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and a SASL-based security protocol, which has been possible on Kafka Connect clusters since Apache Kafka Connect 2.3.0. When configuring the connector via the Kafka Connect REST API, an authenticated operator can set the `sasl.jaas.config` property for any of the connector's Kafka clients to "com.sun.security.auth.module.JndiLoginModule", which can be done via the `pro

CVE-2023-24523
Host Agent Service General
8.8
HIGH
EPSS
0.1%
2023 CWE-668 1 PoC

An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7.21, 7.22, can submit a crafted ConfigureOutsideDiscovery request with an operating system command which will be executed with administrator privileges.  The OS command can read or modify any user or system data and can make the system unavailable.

CVE-2023-0820
User Role by BestWebSoft Web Windows
8.8
HIGH
EPSS
0.1%
2023 1 PoC

The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role.

CVE-2023-5041
Track The Click Web Database Windows
8.8
HIGH
EPSS
0.3%
2023 1 PoC

The Track The Click WordPress plugin before 0.3.12 does not properly sanitize query parameters to the stats REST endpoint before using them in a database query, allowing a logged in user with an author role or higher to perform time based blind SQLi attacks on the database.

CVE-2023-27379
Foxit Reader Web
8.8
HIGH
EPSS
0.2%
2023 CWE-416 2 PoCs

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 12.1.2.15332. By prematurely deleting objects associated with pages, a specially crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

CVE-2023-0765
Gallery by BestWebSoft Web Database Windows
8.8
HIGH
EPSS
0.5%
2023 2 PoCs

The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not properly escape values used in SQL queries, leading to an Blind SQL Injection vulnerability. The attacker must have at least the privileges of an Author, and the vendor's Slider plugin (https://wordpress.org/plugins/slider-bws/) must also be installed for this vulnerability to be exploitable.

CVE-2023-36092
Software Genérico Web
8.8
HIGH
EPSS
0.4%
2023 1 PoC

Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-22629
Software Genérico General
8.8
HIGH
EPSS
65.1%
2023 3 PoCs

An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the newPath parameter. An authenticated attacker can upload any file and then move it anywhere on the server's filesystem.

CVE-2023-2017
Shopware 6 Web
8.8
HIGH
EPSS
2.3%
2023 CWE-184 1 PoC

Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows remote attackers with access to a Twig environment without the Sandbox extension to bypass the validation checks in `Shopware\Core\Framework\Adapter\Twig\SecurityExtension` and call any arbitrary PHP function and thus execute arbitrary code/commands via usage of fully-qualified names, supplied as array of strings, when referencing callables. Users are advised to upgrade to v6.4.20.1 to resolve this issue. This is a bypa

CVE-2023-4776
School Management System Web Database Windows
8.8
HIGH
EPSS
0.2%
2023 1 PoC

The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to a SQL injection exploitable by relatively low-privilege users like Teachers.

CVE-2023-32541
Hancom Office 2020 General
8.8
HIGH
EPSS
0.3%
2023 CWE-416 1 PoC

A use-after-free vulnerability exists in the footerr functionality of Hancom Office 2020 HWord 11.0.0.7520. A specially crafted .doc file can lead to a use-after-free. An attacker can trick a user into opening a malformed file to trigger this vulnerability.