5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-27367
RAX30 Web Networking
8.0
HIGH
EPSS
0.4%
2023 CWE-78 1 PoC

NETGEAR RAX30 libcms_cli Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the libcms_cli module. The issue results from the lack of proper validation of a user-supplied command before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was Z

CVE-2023-21476
Samsung Mobile Devices General
8.0
HIGH
EPSS
0.0%
2023 1 PoC

Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.

CVE-2023-49501
Software Genérico Networking
8.0
HIGH
EPSS
0.0%
2023 2 PoCs

Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component.

CVE-2023-0741
answerdev/answer Web
8.0
HIGH
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4.

CVE-2023-51148
Software Genérico General
8.0
HIGH
EPSS
0.1%
2023 1 PoC

An issue in TRENDnet Trendnet AC1200 Dual Band PoE Indoor Wireless Access Point TEW-821DAP v.3.00b06 allows an attacker to execute arbitrary code via the 'mycli' command-line interface component.

CVE-2023-0742
answerdev/answer Web
8.0
HIGH
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.

CVE-2023-3491
fossbilling/fossbilling General
8.0
HIGH
EPSS
0.1%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository fossbilling/fossbilling prior to 0.5.3.

CVE-2023-47564
Qsync Central General
8.0
HIGH
EPSS
8.0%
2023 CWE-732 1 PoC

An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.15 ( 2024/01/04 ) and later Qsync Central 4.3.0.11 ( 2024/01/11 ) and later

CVE-2023-26218
TIBCO Nimbus Web
8.0
HIGH
EPSS
0.2%
2023 CWE-79 1 PoC

The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim's local system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Nimbus: versions 10.6.0 and below.

CVE-2023-28909
Volkswagen MIB3 infotainment system MIB3 OI MQB General
8.0
HIGH
EPSS
0.2%
2023 CWE-190 2 PoCs

A specific flaw exists within the Bluetooth stack of the MIB3 unit. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow when receiving fragmented HCI packets on a channel. An attacker can leverage this vulnerability to bypass the MTU check on a channel with enabled fragmentation. Consequently, this can lead to a buffer overflow in upper layer profiles, which can be used to obtain remote code execution. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The lis

CVE-2023-36541
Zoom Desktop Client for Windows Windows
8.0
HIGH
EPSS
0.4%
2023 CWE-345 1 PoC

Insufficient verification of data authenticity in Zoom Desktop Client for Windows before 5.14.5 may allow an authenticated user to enable an escalation of privilege via network access.

CVE-2023-51795
Software Genérico General
8.0
HIGH
EPSS
0.1%
2023 2 PoCs

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showspectrum.c:1789:52 component in showspectrumpic_request_frame

CVE-2023-1094
MonicaHQ General
8.0
HIGH
EPSS
0.8%
2023 1 PoC

MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/food` endpoint and food parameter.

CVE-2023-21475
Samsung Mobile Devices General
8.0
HIGH
EPSS
0.0%
2023 1 PoC

Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.

CVE-2023-24334
Software Genérico General
8.0
HIGH
EPSS
0.1%
2023 1 PoC

A stack overflow vulnerability in Tenda AC23 with firmware version US_AC23V1.0re_V16.03.07.45_cn_TDC01 allows attackers to run arbitrary commands via schedStartTime parameter.

CVE-2023-49528
Software Genérico Networking
8.0
HIGH
EPSS
0.0%
2023 1 PoC

Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.

CVE-2023-28905
Volkswagen MIB3 infotainment system MIB3 OI MQB General
8.0
HIGH
EPSS
0.3%
2023 CWE-122 2 PoCs

A heap buffer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker to execute arbitrary code on it. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources.

CVE-2023-30709
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.1%
2023 1 PoC

Improper access control in Dual Messenger prior to SMR Sep-2023 Release 1 allows local attackers launch activity with system privilege.

CVE-2023-39212
Zoom Rooms for Windows Windows
7.9
HIGH
EPSS
0.0%
2023 CWE-144 1 PoC

Untrusted search path in Zoom Rooms for Windows before version 5.15.5 may allow an authenticated user to enable a denial of service via local access.

CVE-2023-21477
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.0%
2023 1 PoC

Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.