5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-1650
AI ChatBot Web Windows
9.8
CRITICAL
EPSS
48.8%
2023 1 PoC

The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could allow them to perform PHP Object Injection when a suitable gadget is present on the blog

CVE-2023-23902
UR32L Web
9.8
CRITICAL
EPSS
2.3%
2023 CWE-121 1 PoC

A buffer overflow vulnerability exists in the uhttpd login functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to remote code execution. An attacker can send a network request to trigger this vulnerability.

CVE-2023-24800
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_495220 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-24202
Software Genérico Web
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php.

CVE-2023-48022
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
92.2%
2023 4 PoCs

Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment. (Also, within that environment, customers at version 2.52.0 and later can choose to use token authentication.)

CVE-2023-34752
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
30.2%
2023 1 PoC

bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.

CVE-2023-46980
Software Genérico General
9.8
CRITICAL
EPSS
7.5%
2023 3 PoCs

An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the userID parameter.

CVE-2023-33584
Software Genérico Database
9.8
CRITICAL
EPSS
30.7%
2023 4 PoCs

Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the username and password fields during the login process, enabling an attacker to inject malicious SQL code.

CVE-2023-29268
TIBCO Spotfire Statistics Services General
9.8
CRITICAL
EPSS
0.8%
2023 1 PoC

The Splus Server component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that allows an unauthenticated remote attacker to upload or modify arbitrary files within the web server directory on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Statistics Services: versions 11.4.10 and below, versions 11.5.0, 11.6.0, 11.6.1, 11.6.2, 11.7.0, 11.8.0, 11.8.1, 12.0.0, 12.0.1, and 12.0.2, versions 12.1.0 and 12.2.0.

CVE-2023-0856
Canon Office/Small Office Multifunction Printers and Laser Printers General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-121 1 PoC

Buffer overflow in IPP sides attribute process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i firmwa

CVE-2023-2780
mlflow/mlflow General ⚡ nuclei
9.8
CRITICAL
EPSS
86.8%
2023 CWE-29 1 PoC

Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1.

CVE-2023-52026
Software Genérico General
9.8
CRITICAL
EPSS
3.6%
2023 1 PoC

TOTOlink EX1800T V9.1.0cu.2112_B20220316 was discovered to contain a remote command execution (RCE) vulnerability via the telnet_enabled parameter of the setTelnetCfg interface

CVE-2023-24720
Software Genérico General
9.8
CRITICAL
EPSS
0.9%
2023 1 PoC

An arbitrary file upload vulnerability in readium-js v0.32.0 allows attackers to execute arbitrary code via uploading a crafted EPUB file.

CVE-2023-6229
Satera LBP670C Series General
9.8
CRITICAL
EPSS
0.5%
2023 CWE-787 2 PoCs

Buffer overflow in CPCA PDL Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.

CVE-2023-6049
Estatik Real Estate Plugin Web Windows
9.8
CRITICAL
EPSS
0.8%
2023 1 PoC

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget chain is present on the blog

CVE-2023-44077
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636.

CVE-2023-27742
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

IDURAR ERP/CRM v1 was discovered to contain a SQL injection vulnerability via the component /api/login.

CVE-2023-20887
🔥 KEV Aria Operations for Networks (Formerly vRealize Network Insight) General ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2023 4 PoCs

Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.

CVE-2023-46685
WBR-6013 General
9.8
CRITICAL
EPSS
0.6%
2023 CWE-259 2 PoCs

A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially crafted network packets can lead to arbitrary command execution.

CVE-2023-24501
Electra Central AC unit General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

Electra Central AC unit – Hardcoded Credentials in unspecified code used by the unit.