2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-24480
C300 General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-116 1 PoC

Controller DoS due to stack overflow when decoding a message from the server.  See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-32222
DSL-G256DG firmware version vBZ_1.00.27 General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

D-Link DSL-G256DG version vBZ_1.00.27 web management interface allows authentication bypass via an unspecified method.

CVE-2023-39453
ImageGear General
9.8
CRITICAL
EPSS
0.4%
2023 CWE-416 1 PoC

A use-after-free vulnerability exists in the tif_parse_sub_IFD functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can deliver this file to trigger this vulnerability.

CVE-2023-43091
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2023 CWE-79 1 PoC

A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is malicious, it may execute arbitrary code.

CVE-2023-2734
MStore API – Create Native Android & iOS Apps On The Cloud Web Cloud Windows ⚡ nuclei
9.8
CRITICAL
EPSS
63.1%
2023 CWE-288 0 PoCs

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart sync from mobile REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.

CVE-2023-52041
Software Genérico Web
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

An issue discovered in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary code via the sub_410118 function of the shttpd program.

CVE-2023-27638
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
39.0%
2023 1 PoC

An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised tshirtecommerce_design_cart_id GET parameter in order to exploit an insecure parameter in the functions hookActionCartSave and updateCustomizationTable, which could lead to a SQL injection. This is exploited in the wild in March 2023.

CVE-2023-47246
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2023 3 PoCs

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

CVE-2023-5074
D-View 8 General ⚡ nuclei
9.8
CRITICAL
EPSS
92.1%
2023 CWE-798 2 PoCs

Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28

CVE-2023-24320
Software Genérico General
9.8
CRITICAL
EPSS
0.8%
2023 1 PoC

An access control issue in Axcora POS #0~gitf77ec09 allows unauthenticated attackers to execute arbitrary commands via unspecified vectors.

CVE-2023-23305
Software Genérico Web
9.8
CRITICAL
EPSS
0.8%
2023 1 PoC

The GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 is vulnerable to various buffer overflows when loading binary resources. A malicious application embedding specially crafted resources could hijack the execution of the device's firmware.

CVE-2023-7227
NVR 504 General
9.8
CRITICAL
EPSS
0.7%
2023 CWE-77 1 PoC

SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command injection vulnerability in the dynamic domain name system (DDNS) settings that could allow an attacker to execute arbitrary commands with root privileges.

CVE-2023-24350
Software Genérico Networking
9.8
CRITICAL
EPSS
1.1%
2023 1 PoC

D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the config.smtp_email_subject parameter at /goform/formSetEmail.

CVE-2023-5688
modoboa/modoboa Web
9.8
CRITICAL
EPSS
0.2%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository modoboa/modoboa prior to 2.2.2.

CVE-2023-2231
MAX-G866ac General
9.8
CRITICAL
EPSS
0.2%
2023 CWE-306 2 PoCs

A vulnerability, which was classified as critical, was found in MAXTECH MAX-G866ac 0.4.1_TBRO_20160314. This affects an unknown part of the component Remote Management. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227001 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-20887
🔥 KEV Aria Operations for Networks (Formerly vRealize Network Insight) General ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2023 4 PoCs

Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.

CVE-2023-41999
Arcserve UDP General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-287 1 PoC

An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifier that allows them to authenticate to the management console and perform tasks that require authentication.

CVE-2023-29486
Software Genérico Windows
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

An issue was discovered in Heimdal Thor agent versions 3.4.2 and before 3.7.0 on Windows, allows attackers to bypass USB access restrictions, execute arbitrary code, and obtain sensitive information via Next-Gen Antivirus component. NOTE: Heimdal argues that the limitation described here is a Microsoft Windows issue, not a Heimdal specific vulnerability. The USB control solution by Heimdal is meant to manage Microsoft Windows native USB restrictions. They maintain that their solution functions as a management layer over Windows settings and is not to blame for limitations in Windows' detection

CVE-2023-51957
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv.

CVE-2023-49693
NETGEAR ProSAFE Network Management System General
9.8
CRITICAL
EPSS
0.7%
2023 CWE-306 2 PoCs

NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port 11611 and it is remotely accessible by unauthenticated users, allowing attackers to execute arbitrary code.