2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-0488
pyload/pyload Web
9.6
CRITICAL
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pyload/pyload prior to 0.5.0b3.dev42.

CVE-2023-5241
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services Web Windows
9.6
CRITICAL
EPSS
2.4%
2023 CWE-22 1 PoC

The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level attackers to append "<?php" to any existing file on the server resulting in potential DoS when appended to critical files such as wp-config.php.

CVE-2023-39213
Zoom Desktop Client for Windows and Zoom VDI Client Windows
9.6
CRITICAL
EPSS
1.0%
2023 CWE-176 1 PoC

Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticated user to enable an escalation of privilege via network access.

CVE-2023-33241
Wallet General
9.6
CRITICAL
EPSS
0.3%
2023 1 PoC

Crypto wallets implementing the GG18 or GG20 TSS protocol might allow an attacker to extract a full ECDSA private key by injecting a malicious pallier key and cheating in the range proof. Depending on the Beta parameters chosen in the protocol implementation, the attack might require 16 signatures or more fully exfiltrate the other parties' private key shares.

CVE-2023-28131
Expo AuthSession module General
9.6
CRITICAL
EPSS
1.3%
2023 2 PoCs

A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicious link. The link itself may be sent to the victim in various ways (including email, text message, an attacker-controlled website, etc).

CVE-2023-3824
PHP Web
9.4
CRITICAL
EPSS
29.4%
2023 CWE-119 14 PoCs

In PHP version 8.0.* before 8.0.30,  8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insufficient length checking may lead to a stack buffer overflow, leading potentially to memory corruption or RCE.

CVE-2023-3128
Grafana DevOps Cloud
9.4
CRITICAL
EPSS
1.9%
2023 CWE-290 1 PoC

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

CVE-2023-4966
🔥 KEV NetScaler ADC Networking Windows ⚡ nuclei
9.4
CRITICAL
EPSS
94.3%
2023 CWE-119 15 PoCs

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

CVE-2023-6930
ETL3100 General
9.4
CRITICAL
EPSS
0.0%
2023 CWE-284 1 PoC

EuroTel ETL3100 versions v01c01 and v01x37 suffer from an unauthenticated configuration and log download vulnerability. This enables the attacker to disclose sensitive information and assist in authentication bypass, privilege escalation, and full system access.

CVE-2023-2868
🔥 KEV Barracuda Email Security Gateway General
9.4
CRITICAL
EPSS
90.8%
2023 CWE-20 4 PoCs

A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete input validation of a user-supplied .tar file as it pertains to the names of the files contained within the archive. As a consequence, a remote attacker can specifically format these file names in a particular manner that will result in remotely executing a system command through

CVE-2023-23770
MBTS Site Controller General
9.4
CRITICAL
EPSS
0.1%
2023 CWE-259 1 PoC

Motorola MBTS Site Controller accepts hard-coded backdoor password. The Motorola MBTS Site Controller Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled.

CVE-2023-4523
460 Series Web
9.4
CRITICAL
EPSS
0.1%
2023 CWE-79 1 PoC

Real Time Automation 460 Series products with versions prior to v8.9.8 are vulnerable to cross-site scripting, which could allow an attacker to run any JavaScript reference from the URL string. If this were to occur, the gateway's HTTP interface would redirect to the main page, which is index.htm.

CVE-2023-53942
File Thingie Web
9.4
CRITICAL
EPSS
0.2%
2023 CWE-434 1 PoC

File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious PHP zip archives to the web server. Attackers can create a custom PHP payload, upload and unzip it, and then execute arbitrary system commands through a crafted PHP script with a command parameter.

CVE-2023-0017
NetWeaver AS for Java Web
9.4
CRITICAL
EPSS
5.0%
2023 CWE-284 1 PoC

An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and data on the current system. This could allow the attacker to have full read access to user data, make modifications to user data, and make services within the system unavailable.

CVE-2023-5878
OneWireless Network Wireless Device Manager General
9.4
CRITICAL
EPSS
0.3%
2023 CWE-77 1 PoC

Honeywell OneWireless Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, R330.1 contains a command injection vulnerability. An attacker who is authenticated could use the firmware update process to potentially exploit the vulnerability, leading to a command injection. Honeywell recommends updating to R322.3, R330.2 or the most recent version of this product2.

CVE-2023-7334
T+ General
9.3
CRITICAL
EPSS
0.3%
2023 CWE-502 1 PoC

Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code execution. A remote attacker can send a crafted request to /tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx?method=GetStoreWarehouseByStore with a malicious JSON body that leverages deserialization of attacker-controlled .NET types to invoke arbitrary methods such as System.Diagnostics.Process.Start. This can result in execution of arbitrary commands in the context of the T+ application service account. Exploitation evidence was observe

CVE-2023-6569
h2oai/h2o-3 General
9.3
CRITICAL
EPSS
0.2%
2023 CWE-73 1 PoC

External Control of File Name or Path in h2oai/h2o-3

CVE-2023-6038
h2oai/h2o-3 Web ⚡ nuclei
9.3
CRITICAL
EPSS
63.3%
2023 CWE-862 1 PoC

A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the server with the permissions of the user running the h2o-3 instance. This issue affects the default installation and does not require user interaction. The vulnerability can be exploited by making specific GET or POST requests to the ImportFiles and ParseSetup endpoints, respectively. This issue was identified in version 3.40.0.4 of h2o-3.

CVE-2023-54329
Inbit Messenger General
9.3
CRITICAL
EPSS
0.6%
2023 CWE-121 1 PoC

Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by exploiting a stack overflow in the messenger's protocol. Attackers can send specially crafted XML packets to port 10883 with a malicious payload to trigger the vulnerability and execute commands with system privileges.

CVE-2023-53948
Lilac-Reloaded General
9.3
CRITICAL
EPSS
0.5%
2023 CWE-78 1 PoC

Lilac-Reloaded for Nagios 2.0.8 contains a remote code execution vulnerability in the autodiscovery feature that allows attackers to inject arbitrary commands. Attackers can exploit the lack of input filtering in the nmap_binary parameter to execute a reverse shell by sending a crafted POST request to the autodiscovery endpoint.