2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-29665
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2023 1 PoC

D-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters in SetPasswdSettings.

CVE-2023-51801
Software Genérico Web Database
9.8
CRITICAL
EPSS
7.2%
2023 1 PoC

SQL Injection vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the id parameter in the student_form.php and the class_form.php pages.

CVE-2023-28501
UniData General
9.8
CRITICAL
EPSS
2.0%
2023 CWE-190 1 PoC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a heap-based buffer overflow in the unirpcd daemon that, if successfully exploited, can lead to remote code execution as the root user.

CVE-2023-43373
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
17.2%
2023 0 PoCs

Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php.

CVE-2023-29727
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its database that is related to user privacy settings and affects the implementation of the normal functionality of the application. An attacker can use this to cause an escalation of privilege attack.

CVE-2023-52032
Software Genérico General
9.8
CRITICAL
EPSS
16.3%
2023 1 PoC

TOTOlink EX1200T V4.1.2cu.5232_B20210713 was discovered to contain a remote command execution (RCE) vulnerability via the "main" function.

CVE-2023-30331
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

An issue in the render function of beetl v3.15.0 allows attackers to execute server-side template injection (SSTI) via a crafted payload.

CVE-2023-34478
Apache Shiro Web
9.8
CRITICAL
EPSS
0.0%
2023 CWE-22 1 PoC

Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests. Mitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+

CVE-2023-49693
NETGEAR ProSAFE Network Management System General
9.8
CRITICAL
EPSS
0.7%
2023 CWE-306 2 PoCs

NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticated users, allowing attackers to execute arbitrary code.

CVE-2023-52028
Software Genérico General
9.8
CRITICAL
EPSS
20.6%
2023 1 PoC

TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setTracerouteCfg function.

CVE-2023-38408
Software Genérico Networking
9.8
CRITICAL
EPSS
64.4%
2023 13 PoCs

The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.

CVE-2023-27192
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2023 2 PoCs

An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the key_wifi_safe_net_check_url, KEY_Cirus_scan_whitelist and KEY_AD_NEW_USER_AVOID_TIME parameters.

CVE-2023-3047
Lockcell Database
9.8
CRITICAL
EPSS
8.8%
2023 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TMT Lockcell allows SQL Injection.This issue affects Lockcell: before 15.

CVE-2023-26866
Software Genérico General
9.8
CRITICAL
EPSS
9.3%
2023 1 PoC

GreenPacket OH736's WR-1200 Indoor Unit, OT-235 with firmware versions M-IDU-1.6.0.3_V1.1 and MH-46360-2.0.3-R5-GP respectively are vulnerable to remote command injection. Commands are executed using pre-login execution and executed with root privileges allowing complete takeover.

CVE-2023-51951
Software Genérico Web Database
9.8
CRITICAL
EPSS
3.5%
2023 2 PoCs

SQL Injection vulnerability in Stock Management System 1.0 allows a remote attacker to execute arbitrary code via the id parameter in the manage_bo.php file.

CVE-2023-51957
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv.

CVE-2023-47397
Software Genérico Web
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.

CVE-2023-29486
Software Genérico Windows
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

An issue was discovered in Heimdal Thor agent versions 3.4.2 and before 3.7.0 on Windows, allows attackers to bypass USB access restrictions, execute arbitrary code, and obtain sensitive information via Next-Gen Antivirus component. NOTE: Heimdal argues that the limitation described here is a Microsoft Windows issue, not a Heimdal specific vulnerability. The USB control solution by Heimdal is meant to manage Microsoft Windows native USB restrictions. They maintain that their solution functions as a management layer over Windows settings and is not to blame for limitations in Windows' detection

CVE-2023-30330
Software Genérico Web
9.8
CRITICAL
EPSS
1.8%
2023 1 PoC

SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defaultframe/2.0/defaultframe_filter.php.

CVE-2023-34426
YF325 Web
9.8
CRITICAL
EPSS
0.3%
2023 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the httpd manage_request functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to stack-based buffer overflow. An attacker can send a network request to trigger this vulnerability.