2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-27179
Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
85.8%
2023 1 PoC

GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via the filename parameter at /_admin/imgdownload.php.

CVE-2023-49979
Software Genérico General
7.5
HIGH
EPSS
0.6%
2023 2 PoCs

A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.

CVE-2023-7239
WP Dashboard Notes Web Windows
7.5
HIGH
EPSS
0.7%
2023 1 PoC

The WP Dashboard Notes WordPress plugin before 1.0.11 does not validate that the user has access to the post_id parameter in its wpdn_update_note AJAX action. This allows users with a role of contributor and above to update notes created by other users.

CVE-2023-28760
Software Genérico Networking
7.5
HIGH
EPSS
0.1%
2023 1 PoC

TP-Link AX1800 WiFi 6 Router (Archer AX21) devices allow unauthenticated attackers (on the LAN) to execute arbitrary code as root via the db_dir field to minidlnad. The attacker obtains the ability to modify files.db, and that can be used to reach a stack-based buffer overflow in minidlna-1.1.2/upnpsoap.c. Exploitation requires that a USB flash drive is connected to the router (customers often do this to make a \\192.168.0.1 share available on their local network).

CVE-2023-4279
User Activity Log Web Windows
7.5
HIGH
EPSS
2.1%
2023 2 PoCs

This User Activity Log WordPress plugin before 1.6.7 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to hide the source of malicious traffic.

CVE-2023-25948
Experion Server General
7.5
HIGH
EPSS
0.1%
2023 CWE-394 1 PoC

Server information leak of configuration data when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-44833
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the GuardInt parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-20529
2nd Gen EPYC General
7.5
HIGH
EPSS
0.4%
2023 1 PoC

Insufficient bound checks in the SMU may allow an attacker to update the from/to address space to an invalid value potentially resulting in a denial of service.

CVE-2023-49338
Software Genérico General
7.5
HIGH
EPSS
0.4%
2023 2 PoCs

Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.

CVE-2023-0678
phpipam/phpipam Web ⚡ nuclei
7.5
HIGH
EPSS
67.6%
2023 CWE-862 0 PoCs

Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.

CVE-2023-31893
Software Genérico General
7.5
HIGH
EPSS
0.1%
2023 2 PoCs

Telefnica Brasil Vivo Play (IPTV) Firmware: 2023.04.04.01.06.15 is vulnerable to Denial of Service (DoS) via DNS Recursion.

CVE-2023-6505
Migrate WordPress Website & Backups Web Windows ⚡ nuclei
7.5
HIGH
EPSS
73.8%
2023 1 PoC

The Migrate WordPress Website & Backups WordPress plugin before 1.9.3 does not prevent directory listing in sensitive directories containing export files.

CVE-2023-3154
WordPress Gallery Plugin Web Windows
7.5
HIGH
EPSS
0.5%
2023 1 PoC

The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.

CVE-2023-21838
WebLogic Server Database
7.5
HIGH
EPSS
0.9%
2023 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVE-2023-29743
Software Genérico General
7.5
HIGH
EPSS
0.2%
2023 1 PoC

An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database.

CVE-2023-46346
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 4.1.1 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a path traversal to view all files on the information system.

CVE-2023-7012
Chrome General
7.5
HIGH
EPSS
0.1%
2023 1 PoC

Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convinced a user to install a malicious app to potentially perform a sandbox escape via a malicious file. (Chromium security severity: Medium)

CVE-2023-30445
DB2 for Linux, UNIX and Windows Windows
7.5
HIGH
EPSS
0.1%
2023 CWE-20 1 PoC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253357.

CVE-2023-37607
Software Genérico Web
7.5
HIGH
EPSS
0.3%
2023 1 PoC

Directory Traversal in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information via csvServer.php?file= with a .. in the dir parameter.

CVE-2023-0612
TEW-811DRU Web
7.5
HIGH
EPSS
0.3%
2023 CWE-120 1 PoC

A vulnerability, which was classified as critical, was found in TRENDnet TEW-811DRU 1.0.10.0. Affected is an unknown function of the file /wireless/basic.asp of the component httpd. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-219936.