2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-54329
Inbit Messenger General
9.3
CRITICAL
EPSS
0.6%
2023 CWE-121 1 PoC

Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by exploiting a stack overflow in the messenger's protocol. Attackers can send specially crafted XML packets to port 10883 with a malicious payload to trigger the vulnerability and execute commands with system privileges.

CVE-2023-53975
Atom CMS Web Database
9.3
CRITICAL
EPSS
0.1%
2023 CWE-89 1 PoC

Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the 'id' parameter of the admin index page to execute time-based blind SQL injection attacks.

CVE-2023-32590
Subscribe to Category Database ⚡ nuclei
9.3
CRITICAL
EPSS
19.3%
2023 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category.This issue affects Subscribe to Category: from n/a through 2.7.4.

CVE-2023-2507
Cordova Plugin Web
9.3
CRITICAL
EPSS
0.1%
2023 CWE-79 1 PoC

CleverTap Cordova Plugin version 2.6.2 allows a remote attacker to execute JavaScript code in any application that is opened via a specially constructed deeplink by an attacker. This is possible because the plugin does not correctly validate the data coming from the deeplinks before using them.

CVE-2023-53955
Impact/Pulse/First General
9.3
CRITICAL
EPSS
0.7%
2023 CWE-639 2 PoCs

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access hidden system resources. Attackers can exploit the vulnerability by manipulating user-supplied input to execute privileged functionalities without proper authentication.

CVE-2023-7304
RG-UAC Web
9.3
CRITICAL
EPSS
2.5%
2023 CWE-78 1 PoC

Ruijie RG-UAC Application Management Gateway contains a command injection vulnerability via the 'nmc_sync.php' interface. An unauthenticated attacker able to reach the affected endpoint can inject shell commands via crafted request data, causing the application to execute arbitrary commands on the host. Successful exploitation can yield full control of the application process and may lead to system-level access depending on the service privileges. VulnCheck has observed this vulnerability being targeted by the RondoDox botnet campaign.

CVE-2023-25610
FortiSwitchManager Networking
9.3
CRITICAL
EPSS
16.0%
2023 CWE-124 1 PoC

A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below and FortiOS-6K7K version 7.0.5, version 6.4.0 through 6.4.10 and version 6.2.0 through 6.2.10 and below allows a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

CVE-2023-53967
Screen SFT DAB 600/C Web
9.3
CRITICAL
EPSS
0.4%
2023 CWE-306 2 PoCs

Screen SFT DAB 600/C firmware 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without requiring the current credentials. Attackers can exploit the userManager.cgx API endpoint by sending a crafted POST request with a new MD5-hashed password to directly modify the admin account's authentication.

CVE-2023-7311
Flow Control Router Networking
9.3
CRITICAL
EPSS
0.3%
2023 CWE-78 2 PoCs

BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoint. The `path` parameter is not properly validated and is echoed into a shell context, allowing an attacker to inject and execute arbitrary shell commands on the device. Successful exploitation can lead to writing backdoors, privilege escalation on the host, and full compromise of the router and its management functions. VulnCheck has observed this vulnerability being targeted by the RondoDox botnet campaign.

CVE-2023-6038
h2oai/h2o-3 Web ⚡ nuclei
9.3
CRITICAL
EPSS
63.3%
2023 CWE-862 1 PoC

A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the server with the permissions of the user running the h2o-3 instance. This issue affects the default installation and does not require user interaction. The vulnerability can be exploited by making specific GET or POST requests to the ImportFiles and ParseSetup endpoints, respectively. This issue was identified in version 3.40.0.4 of h2o-3.

CVE-2023-53950
WYSIWYG Editor General
9.3
CRITICAL
EPSS
0.1%
2023 CWE-434 1 PoC

InnovaStudio WYSIWYG Editor 5.4 contains an unrestricted file upload vulnerability that allows attackers to bypass file extension restrictions through filename manipulation. Attackers can upload malicious ASP shells by using null byte techniques and alternate file extensions to circumvent upload controls in the asset manager.

CVE-2023-7330
NBR Series Routers Web Networking
9.3
CRITICAL
EPSS
0.8%
2023 CWE-434 1 PoC

Ruijie NBR series routers contain an unauthenticated arbitrary file upload vulnerability via /ddi/server/fileupload.php. The endpoint accepts attacker-supplied values in the name and uploadDir parameters and saves the provided multipart file content without adequate validation or sanitization of file type, path, or extension. A remote attacker can upload a crafted PHP file and then access it from the web root, resulting in arbitrary code execution in the context of the web service. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-14 UTC.

CVE-2023-53951
ever gauzy General
9.3
CRITICAL
EPSS
0.1%
2023 CWE-347 1 PoC

Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key implementation. Attackers can leverage the exposed JWT token to authenticate and gain unauthorized access with administrative permissions.

CVE-2023-44393
Piwigo Web ⚡ nuclei
9.3
CRITICAL
EPSS
6.2%
2023 CWE-79 0 PoCs

Piwigo is an open source photo gallery application. Prior to version 14.0.0beta4, a reflected cross-site scripting (XSS) vulnerability is in the` /admin.php?page=plugins&tab=new&installstatus=ok&plugin_id=[here]` page. This vulnerability can be exploited by an attacker to inject malicious HTML and JS code into the HTML page, which could then be executed by admin users when they visit the URL with the payload. The vulnerability is caused by the insecure injection of the `plugin_id` value from the URL into the HTML page. An attacker can exploit this vulnerability by crafting a malicious URL that

CVE-2023-53923
Ulicms Web
9.3
CRITICAL
EPSS
0.2%
2023 CWE-862 1 PoC

UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrative accounts through the UserController endpoint. Attackers can send a crafted POST request to /dist/admin/index.php with specific parameters to generate a new admin user with full system access.

CVE-2023-53960
Impact/Pulse/First Web Database
9.3
CRITICAL
EPSS
0.3%
2023 CWE-89 2 PoCs

SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mechanism that allows attackers to manipulate login credentials. Attackers can inject malicious SQL code through the 'password' POST parameter to bypass authentication and potentially gain unauthorized access to the system.

CVE-2023-6569
h2oai/h2o-3 General
9.3
CRITICAL
EPSS
0.2%
2023 CWE-73 1 PoC

External Control of File Name or Path in h2oai/h2o-3

CVE-2023-53922
TinyWebGallery Web
9.3
CRITICAL
EPSS
2.3%
2023 CWE-434 1 PoC

TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload malicious PHP files. Attackers can upload .phar files with embedded system commands to execute arbitrary code on the server by accessing the uploaded file's URL.

CVE-2023-0606
ampache/ampache Web
9.3
CRITICAL
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository ampache/ampache prior to 5.5.7.

CVE-2023-53982
PMB Web Database
9.3
CRITICAL
EPSS
0.0%
2023 CWE-89 1 PoC

PMB 7.4.6 contains a SQL injection vulnerability in the storage parameter of the ajax.php endpoint that allows remote attackers to manipulate database queries. Attackers can exploit the unsanitized 'id' parameter by injecting conditional sleep statements to extract information or perform time-based blind SQL injection attacks.