2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-33510
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
71.5%
2023 1 PoC

Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters.

CVE-2023-26106
dot-lens General
7.5
HIGH
EPSS
0.3%
2023 CWE-1321 1 PoC

All versions of the package dot-lens are vulnerable to Prototype Pollution via the set() function in index.js file.

CVE-2023-1809
Download Manager Web Windows
7.5
HIGH
EPSS
0.7%
2023 1 PoC

The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbitrary password-protected package files.

CVE-2023-23571
UR32L General
7.5
HIGH
EPSS
0.1%
2023 CWE-126 2 PoCs

An access violation vulnerability exists in the eventcore functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to denial of service. An attacker can send a network request to trigger this vulnerability.

CVE-2023-26102
rangy General
7.5
HIGH
EPSS
0.4%
2023 CWE-1321 1 PoC

All versions of the package rangy are vulnerable to Prototype Pollution when using the extend() function in file rangy-core.js.The function uses recursive merge which can lead an attacker to modify properties of the Object.prototype

CVE-2023-32309
pymdown-extensions General
7.5
HIGH
EPSS
3.5%
2023 CWE-22 1 PoC

PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. In affected versions an arbitrary file read is possible when using include file syntax. By using the syntax `--8<--"/etc/passwd"` or `--8<--"/proc/self/environ"` the content of these files will be rendered in the generated documentation. Additionally, a path relative to a specified, allowed base path can also be used to render the content of a file outside the specified base paths: `--8<-- "../../../../etc/passwd"`. Within the Snippets extension, there exists a `base_path` option but the implementation is vul

CVE-2023-44227
Simple File List General
7.5
HIGH
EPSS
0.2%
2023 CWE-862 1 PoC

Missing Authorization vulnerability in Mitchell Bennis Simple File List.This issue affects Simple File List: from n/a through 6.1.9.

CVE-2023-27640
Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
81.0%
2023 1 PoC

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the POST parameter type in the /tshirtecommerce/fonts.php endpoint, to allow a remote attacker to traverse directories on the system in order to open files (without restriction on the extension and path). The content of the file is returned with base64 encoding. This is exploited in the wild in March 2023.

CVE-2023-1719
Bitrix24 Web ⚡ nuclei
7.5
HIGH
EPSS
86.1%
2023 CWE-665 1 PoC

Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via overwriting uninitialised variables.

CVE-2023-4486
Metasys NAE55/SNE/SNC General
7.5
HIGH
EPSS
0.2%
2023 CWE-400 1 PoC

Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to versions 11.0.6 and 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service.

CVE-2023-22845
OpenImageIO General
7.5
HIGH
EPSS
0.2%
2023 CWE-125 1 PoC

An out-of-bounds read vulnerability exists in the TGAInput::decode_pixel() functionality of OpenImageIO Project OpenImageIO v2.4.7.1. A specially crafted targa file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-6271
Backup Migration Web Windows
7.5
HIGH
EPSS
0.3%
2023 2 PoCs

The Backup Migration WordPress plugin before 1.3.6 stores in-progress backups information in easy to find, publicly-accessible files, which may allow attackers monitoring those to leak sensitive information from the site's backups.

CVE-2023-49545
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 2 PoCs

A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.

CVE-2023-20197
Cisco Secure Endpoint Networking
7.5
HIGH
EPSS
0.4%
2023 CWE-835 1 PoC

A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affected software to stop responding. An attacker could exploit this vulnerability by submitting a crafted HFS+ filesystem image to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause th

CVE-2023-32235
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
94.1%
2023 2 PoCs

Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory traversal. This occurs in frontend/web/middleware/static-theme.js.

CVE-2023-27705
Software Genérico General
7.5
HIGH
EPSS
0.3%
2023 1 PoC

APNG_Optimizer v1.4 was discovered to contain a buffer overflow via the component /apngopt/ubuntu.png.

CVE-2023-27532
🔥 KEV Veeam Backup & Replication General
7.5
HIGH
EPSS
82.3%
2023 CWE-306 3 PoCs

Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.

CVE-2023-42494
v3.0.6433.1964 General
7.5
HIGH
EPSS
0.2%
2023 CWE-749 1 PoC

EisBaer Scada - CWE-749: Exposed Dangerous Method or Function

CVE-2023-0331
Correos Oficial Web Windows
7.5
HIGH
EPSS
0.5%
2023 1 PoC

The Correos Oficial WordPress plugin through 1.2.0.2 does not have an authorization check user input validation when generating a file path, allowing unauthenticated attackers to download arbitrary files from the server.

CVE-2023-26130
yhirose/cpp-httplib Web
7.5
HIGH
EPSS
0.2%
2023 CWE-93 2 PoCs

Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type header in the HTTP .Patch, .Post, .Put and .Delete requests. This can lead to logical errors and other misbehaviors. **Note:** This issue is present due to an incomplete fix for [CVE-2020-11709](https://security.snyk.io/vuln/SNYK-UNMANAGED-YHIROSECPPHTTPLIB-2366507).