2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-2034
froxlor/froxlor General
9.1
CRITICAL
EPSS
9.0%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository froxlor/froxlor prior to 2.0.14.

CVE-2023-2003
Vision1210 General
9.1
CRITICAL
EPSS
0.4%
2023 CWE-506 1 PoC

Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a remote attacker to store base64-encoded malicious code in the device's data tables via the PCOM protocol, which can then be retrieved by a client and executed on the device.

CVE-2023-23459
Priority for Windows Database Windows
9.1
CRITICAL
EPSS
0.4%
2023 CWE-89 1 PoC

Priority Windows may allow Command Execution via SQL Injection using an unspecified method.

CVE-2023-1721
Yoga Class Registration System General
9.1
CRITICAL
EPSS
0.1%
2023 CWE-434 2 PoCs

Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators.

CVE-2023-0321
CR6 Web
9.1
CRITICAL
EPSS
0.3%
2023 CWE-200 1 PoC

Campbell Scientific dataloggers CR6, CR300, CR800, CR1000 and CR3000 may allow an attacker to download configuration files, which may contain sensitive information about the internal network. From factory defaults, the mentioned datalogges have HTTP and PakBus enabled. The devices, with the default configuration, allow this situation via the PakBus port. The exploitation of this vulnerability may allow an attacker to download, modify, and upload new configuration files.

CVE-2023-27290
Observability with Instana DevOps
9.1
CRITICAL
EPSS
8.5%
2023 CWE-306 1 PoC

Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/write access. IBM X-Force ID: 248737.

CVE-2023-34034
Spring Security Web
9.1
CRITICAL
EPSS
47.9%
2023 1 PoC

Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.

CVE-2023-40275
Software Genérico General
9.1
CRITICAL
EPSS
0.6%
2023 2 PoCs

An issue was discovered in OpenClinic GA 5.247.01. It allows retrieval of patient lists via queries such as findFirstname= to _common/search/searchByAjax/patientslistShow.jsp.

CVE-2023-0306
thorsten/phpmyfaq Web
9.1
CRITICAL
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

CVE-2023-5841
OpenEXR General
9.1
CRITICAL
EPSS
0.8%
2023 CWE-122 1 PoC

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.

CVE-2023-23465
Media Control Panel Web
9.1
CRITICAL
EPSS
0.1%
2023 CWE-352 1 PoC

Media CP Media Control Panel latest version. CSRF possible through unspecified endpoint.

CVE-2023-32070
xwiki-rendering Web
9.1
CRITICAL
EPSS
4.7%
2023 CWE-83 1 PoC

XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki syntax. This has been patched in XWiki 14.6-rc-1. There are no known workarounds apart from upgrading to a fixed version.

CVE-2023-31475
Software Genérico General
9.0
CRITICAL
EPSS
25.8%
2023 1 PoC

An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the value is pasted into a char pointer to a buffer without checking the size of the buffer.

CVE-2023-5843
Ads by datafeedr.com Web Windows
9.0
CRITICAL
EPSS
9.3%
2023 CWE-94 1 PoC

The Ads by datafeedr.com plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.1.3 via the 'dfads_ajax_load_ads' function. This allows unauthenticated attackers to execute code on the server. The parameters of the callable function are limited, they cannot be specified arbitrarily.

CVE-2023-6730
huggingface/transformers General
9.0
CRITICAL
EPSS
0.2%
2023 CWE-502 1 PoC

Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.

CVE-2023-21456
Samsung Mobile Devices General
9.0
CRITICAL
EPSS
0.1%
2023 CWE-22 1 PoC

Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.

CVE-2023-25181
Gecko Platform Web
9.0
CRITICAL
EPSS
0.3%
2023 CWE-122 1 PoC

A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2023-0014
NetWeaver ABAP Server and ABAP Platform General
9.0
CRITICAL
EPSS
0.4%
2023 CWE-294 1 PoC

SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22EXT, creates information about system identity in an ambiguous format. This could lead to capture-replay vulnerability and may be exploited by malicious users to obtain illegitimate access to the system.

CVE-2023-5320
thorsten/phpmyfaq Web
9.0
CRITICAL
EPSS
0.5%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository thorsten/phpmyfaq prior to 3.1.18.

CVE-2023-21975
Application Express (APEX) Web Database
9.0
CRITICAL
EPSS
0.7%
2023 1 PoC

Vulnerability in the Application Express Customers Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Application Express Customers Plugin: 18.2-22.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Application Express Customers Plugin. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Application Express Customers Plugin, attacks may significantly impact additional products (scope change). Successful attac