5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-30145
Software Genérico Web
9.8
CRITICAL
EPSS
53.3%
2023 2 PoCs

Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter.

CVE-2023-46954
Software Genérico Database
9.8
CRITICAL
EPSS
3.9%
2023 1 PoC

SQL Injection vulnerability in Relativity ODA LLC RelativityOne v.12.1.537.3 Patch 2 and earlier allows a remote attacker to execute arbitrary code via the name parameter.

CVE-2023-38389
JupiterX Core General
9.8
CRITICAL
EPSS
11.8%
2023 CWE-863 1 PoC

Incorrect Authorization vulnerability in Artbees JupiterX Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JupiterX Core: from n/a through 3.3.8.

CVE-2023-0310
thorsten/phpmyfaq Web
9.8
CRITICAL
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

CVE-2023-29985
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Sourcecodester Student Study Center Desk Management System v1.0 admin\reports\index.php#date_from has a SQL Injection vulnerability.

CVE-2023-51961
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.

CVE-2023-6329
iDSecure General ⚡ nuclei
9.8
CRITICAL
EPSS
92.5%
2023 CWE-287 1 PoC

An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll contains a "passwordCustom" option that allows an unauthenticated attacker to compute valid credentials that can be used to bypass authentication and act as an administrative user.

CVE-2023-32117
Integrate Google Drive General ⚡ nuclei
9.8
CRITICAL
EPSS
89.4%
2023 CWE-862 1 PoC

Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through 1.1.99.

CVE-2023-46747
🔥 KEV BIG-IP General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2023 CWE-288 15 PoCs

Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2023-24798
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_475FB0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-25207
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php.

CVE-2023-20864
VMware Aria Operations for Logs (formerly vRealize Log Insight) General ⚡ nuclei
9.8
CRITICAL
EPSS
93.0%
2023 0 PoCs

VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.

CVE-2023-23076
Software Genérico General
9.8
CRITICAL
EPSS
49.3%
2023 1 PoC

OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.

CVE-2023-5688
modoboa/modoboa Web
9.8
CRITICAL
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository modoboa/modoboa prior to 2.2.2.

CVE-2023-6553
BackupBliss – Backup & Migration with Free Cloud Storage Web Cloud Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.5%
2023 CWE-94 7 PoCs

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated attackers to easily execute code on the server.

CVE-2023-0224
GiveWP Web Database Windows
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

The GiveWP WordPress plugin before 2.24.1 does not properly escape user input before it reaches SQL queries, which could let unauthenticated attackers perform SQL Injection attacks

CVE-2023-6230
Satera LBP670C Series General
9.8
CRITICAL
EPSS
0.4%
2023 CWE-787 2 PoCs

Buffer overflow in the Address Book password process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmwar

CVE-2023-4474
NAS326 firmware Cloud
9.8
CRITICAL
EPSS
16.3%
2023 CWE-78 1 PoC

The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device.

CVE-2023-24201
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at get_ticket.php.

CVE-2023-34753
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
33.2%
2023 1 PoC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit.