5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-3224
nuxt/nuxt General
8.1
HIGH
EPSS
2.1%
2023 CWE-94 1 PoC

Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3.

CVE-2023-34216
TN-5900 Series General
8.1
HIGH
EPSS
0.3%
2023 CWE-22 1 PoC

TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability derives from insufficient input validation in the key-delete function, which could potentially allow malicious users to delete arbitrary files.

CVE-2023-6254
OTRS General
8.1
HIGH
EPSS
0.2%
2023 CWE-522 1 PoC

A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are send back to the client in the server response- This issue affects OTRS: from 8.0.X through 8.0.37.

CVE-2023-31178
NX General
8.1
HIGH
EPSS
0.2%
2023 1 PoC

AgilePoint NX v8.0 SU2.2 & SU2.3 – Arbitrary File Delete Vulnerability allows arbitrary file deletion, by an unspecified request.

CVE-2023-47130
yii Web
8.1
HIGH
EPSS
3.3%
2023 CWE-502 1 PoC

Yii is an open source PHP web framework. yiisoft/yii before version 1.1.29 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. An attacker may leverage this vulnerability to compromise the host system. A fix has been developed for the 1.1.29 release. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2023-47320
Software Genérico General
8.1
HIGH
EPSS
0.3%
2023 1 PoC

Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes the application unavailable to all users. This affects Silverpeas Core 6.3.1 and below.

CVE-2023-50009
Software Genérico Networking
8.0
HIGH
EPSS
0.0%
2023 2 PoCs

FFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gaussian_blur_8 function in libavfilter/edge_template.c:116:5 component.

CVE-2023-24047
Software Genérico General
8.0
HIGH
EPSS
0.0%
2023 1 PoC

An Insecure Credential Management issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via use of weak hashing algorithm.

CVE-2023-22726
act General
8.0
HIGH
EPSS
1.5%
2023 CWE-434 1 PoC

act is a project which allows for local running of github actions. The artifact server that stores artifacts from Github Action runs does not sanitize path inputs. This allows an attacker to download and overwrite arbitrary files on the host from a Github Action. This issue may lead to privilege escalation. The /upload endpoint is vulnerable to path traversal as filepath is user controlled, and ultimately flows into os.Mkdir and os.Open. The /artifact endpoint is vulnerable to path traversal as the path is variable is user controlled, and the specified file is ultimately returned by the server

CVE-2023-28910
Volkswagen MIB3 infotainment system MIB3 OI MQB General
8.0
HIGH
EPSS
0.1%
2023 CWE-754 2 PoCs

A specific flaw exists within the Bluetooth stack of the MIB3 infotainment system. The issue results from the disabled abortion flag eventually leading to bypassing assertion functions. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources.

CVE-2023-51147
Software Genérico General
8.0
HIGH
EPSS
0.1%
2023 1 PoC

Buffer Overflow vulnerability in TRENDnet Trendnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via the adm_mod_pwd action.

CVE-2023-50231
ProSAFE Network Management System Web
8.0
HIGH
EPSS
26.3%
2023 CWE-79 1 PoC

NETGEAR ProSAFE Network Management System saveNodeLabel Cross-Site Scripting Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Minimal user interaction is required to exploit this vulnerability. The specific flaw exists within the saveNodeLabel method. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to escalate privileges to resources normally

CVE-2023-21125
Android General
8.0
HIGH
EPSS
0.1%
2023 2 PoCs

In btif_hh_hsdata_rpt_copy_cb of bta_hh.cc, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-36745
Microsoft Exchange Server 2019 Cumulative Update 13 Windows
8.0
HIGH
EPSS
73.6%
2023 CWE-502 1 PoC

Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2023-51146
Software Genérico General
8.0
HIGH
EPSS
0.1%
2023 1 PoC

Buffer Overflow vulnerability in TRENDnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via the adm_add_user action.

CVE-2023-30860
AVideo General
8.0
HIGH
EPSS
3.6%
2023 CWE-79 1 PoC

WWBN AVideo is an open source video platform. In AVideo prior to version 12.4, a normal user can make a Meeting Schedule where the user can invite another user in that Meeting, but it does not properly sanitize the malicious characters when creating a Meeting Room. This allows attacker to insert malicious scripts. Since any USER including the ADMIN can see the meeting room that was created by the attacker this can lead to cookie hijacking and takeover of any accounts. Version 12.4 contains a patch for this issue.

CVE-2023-3393
fossbilling/fossbilling General
8.0
HIGH
EPSS
0.1%
2023 CWE-94 1 PoC

Code Injection in GitHub repository fossbilling/fossbilling prior to 0.5.1.

CVE-2023-49224
Software Genérico Networking
8.0
HIGH
EPSS
0.5%
2023 1 PoC

Precor touchscreen console P62, P80, and P82 contains a default SSH public key in the authorized_keys file. A remote attacker could use this key to gain root privileges.

CVE-2023-28310
Microsoft Exchange Server 2016 Cumulative Update 23 Windows
8.0
HIGH
EPSS
10.0%
2023 CWE-502 1 PoC

Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2023-1242
answerdev/answer Web
8.0
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.