17307 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-24022
Nova 227 Networking
10.0
CRITICAL
EPSS
0.8%
2023 CWE-284 1 PoC

Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices with firmware through RTS/RTD 3.7.11.3 have hardcoded credentials that are easily discovered and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by the crypt function.)

CVE-2023-41892
cms Web ⚡ nuclei
10.0
CRITICAL
EPSS
93.8%
2023 CWE-94 7 PoCs

Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.

CVE-2023-22527
🔥 KEV Confluence Data Center General ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2023 27 PoCs

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.

CVE-2023-37462
xwiki-platform Web Networking ⚡ nuclei
10.0
CRITICAL
EPSS
90.3%
2023 CWE-74 0 PoCs

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode.XWikiSkinsSheet` leads to an injection vector from view right on that document to programming rights, or in other words, it is possible to execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents. The attack works by opening a non-existing page with a name crafted to contain a dangerous payload. It is possible to check if an existing insta

CVE-2023-6977
mlflow/mlflow General ⚡ nuclei
10.0
CRITICAL
EPSS
83.0%
2023 CWE-29 1 PoC

This vulnerability enables malicious users to read sensitive files on the server.

CVE-2023-2356
mlflow/mlflow General ⚡ nuclei
10.0
CRITICAL
EPSS
90.5%
2023 CWE-23 1 PoC

Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1.

CVE-2023-50029
Software Genérico Web
10.0
CRITICAL
EPSS
0.6%
2023 1 PoC

PHP Injection vulnerability in the module "M4 PDF Extensions" (m4pdf) up to version 3.3.2 from PrestaAddons for PrestaShop allows attackers to run arbitrary code via the M4PDF::saveTemplate() method.

CVE-2023-6018
mlflow/mlflow General ⚡ nuclei
10.0
CRITICAL
EPSS
91.3%
2023 CWE-78 0 PoCs

An attacker can overwrite any file on the server hosting MLflow without any authentication.

CVE-2023-4804
Quantum HD Unity Compressor General
10.0
CRITICAL
EPSS
0.1%
2023 CWE-489 1 PoC

An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.

CVE-2023-2163
Linux Kernel DevOps
10.0
CRITICAL
EPSS
0.2%
2023 CWE-682 1 PoC

Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe code paths being incorrectly marked as safe, resulting in arbitrary read/write in kernel memory, lateral privilege escalation, and container escape.

CVE-2023-22518
🔥 KEV Confluence Data Center Cloud ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2023 12 PoCs

All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative actions that are available to Confluence instance administrator leading to - but not limited to - full loss of confidentiality, integrity and availability.  Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net doma

CVE-2023-6015
mlflow/mlflow General
10.0
CRITICAL
EPSS
0.8%
2023 CWE-22 1 PoC

MLflow allowed arbitrary files to be PUT onto the server.

CVE-2023-5572
vriteio/vrite General
10.0
CRITICAL
EPSS
0.3%
2023 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository vriteio/vrite prior to 0.3.0.

CVE-2023-7163
D-View 8 General
10.0
CRITICAL
EPSS
3.4%
2023 CWE-20 1 PoC

A security issue exists in D-Link D-View 8 v2.0.2.89 and prior that could allow an attacker to manipulate the probe inventory of the D-View service. This could result in the disclosure of information from other probes, denial of service conditions due to the probe inventory becoming full, or the execution of tasks on other probes.

CVE-2023-43654
serve Web ⚡ nuclei
10.0
CRITICAL
EPSS
91.6%
2023 CWE-918 2 PoCs

TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper input validation, enabling third parties to invoke remote HTTP download requests and write files to the disk. This issue could be taken advantage of to compromise the integrity of the system and sensitive data. This issue is present in versions 0.1.0 to 0.8.1. A user is able to load the model of their choice from any URL that they would like to use. The user of TorchServe is responsible for configuring both the allowed_urls and specifying the model URL to be used. A pull req

CVE-2023-25813
sequelize Database
10.0
CRITICAL
EPSS
3.5%
2023 CWE-89 6 PoCs

Sequelize is a Node.js ORM tool. In versions prior to 6.19.1 a SQL injection exploit exists related to replacements. Parameters which are passed through replacements are not properly escaped which can lead to arbitrary SQL injection depending on the specific queries in use. The issue has been fixed in Sequelize 6.19.1. Users are advised to upgrade. Users unable to upgrade should not use the `replacements` and the `where` option in the same query.

CVE-2023-45318
Gecko Platform Web
10.0
CRITICAL
EPSS
0.6%
2023 CWE-122 2 PoCs

A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2023-40151
ST-IPm-8460 General
10.0
CRITICAL
EPSS
0.4%
2023 CWE-749 1 PoC

When user authentication is not enabled the shell can execute commands with the highest privileges. Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message comes over TCP/IP the RTU will simply accept the message with no authentication challenge.

CVE-2023-27497
Diagnostics Agent (EventLogServiceCollector) Windows
10.0
CRITICAL
EPSS
0.4%
2023 CWE-306 1 PoC

Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker to execute malicious scripts on all connected Diagnostics Agents running on Windows. On successful exploitation, the attacker can completely compromise confidentiality, integrity and availability of the system.

CVE-2023-3703
ICR Series routers FW Networking
10.0
CRITICAL
EPSS
0.1%
2023 CWE-1392 1 PoC

Proscend Advice ICR Series routers FW version 1.76 - CWE-1392: Use of Default Credentials