2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-25181
Gecko Platform Web
9.0
CRITICAL
EPSS
0.3%
2023 CWE-122 1 PoC

A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2023-31422
Kibana General
9.0
CRITICAL
EPSS
0.4%
2023 CWE-532 1 PoC

An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. The issue impacts only Kibana version 8.10.0 when logging in the JSON layout or when the pattern layout is configured to log the %meta pattern. Elastic has released Kibana 8.10.1 which resolves this issue. The error object recorded in the log contains request information, which can include sensitive data, such as authentication credentials, cookies, authorization headers, query params, request paths, and other metadata. Some examples of sensitive data which can be included in t

CVE-2023-4202
EKI-1524 Web
9.0
CRITICAL
EPSS
0.2%
2023 CWE-79 3 PoCs

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the device name field of the web-interface.

CVE-2023-21456
Samsung Mobile Devices General
9.0
CRITICAL
EPSS
0.1%
2023 CWE-22 1 PoC

Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.

CVE-2023-27882
Gecko Platform Web
9.0
CRITICAL
EPSS
0.3%
2023 CWE-122 1 PoC

A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2023-3020
mkucej/i-librarian-free Web
9.0
CRITICAL
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository mkucej/i-librarian-free prior to 5.10.4.

CVE-2023-38388
JupiterX Core General
9.0
CRITICAL
EPSS
22.9%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from n/a through 3.3.5.

CVE-2023-21975
Application Express (APEX) Web Database
9.0
CRITICAL
EPSS
0.7%
2023 1 PoC

Vulnerability in the Application Express Customers Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Application Express Customers Plugin: 18.2-22.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Application Express Customers Plugin. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Application Express Customers Plugin, attacks may significantly impact additional products (scope change). Successful attac

CVE-2023-4203
EKI-1524 Web
9.0
CRITICAL
EPSS
0.9%
2023 CWE-79 3 PoCs

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by a Stored Cross-Site Scripting vulnerability, which can be triggered by authenticated users in the ping tool of the web-interface.

CVE-2023-25617
Business Objects (Adaptive Job Server) General
9.0
CRITICAL
EPSS
1.7%
2023 CWE-78 1 PoC

SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, when program objects execution is enabled, to authenticated users with scheduling rights, using the BI Launchpad, Central Management Console or a custom application based on the public java SDK. Programs could impact the confidentiality, integrity and availability of the system.

CVE-2023-20025
Cisco Small Business RV Series Router Firmware Web Networking
9.0
CRITICAL
EPSS
0.3%
2023 CWE-293 2 PoCs

A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Routers could allow an unauthenticated, remote attacker to bypass authentication on an affected device. This vulnerability is due to improper validation of user input within incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface. A successful exploit could allow the attacker to bypass authentication and gain root access on the underlying operating system.

CVE-2023-27267
Diagnostics Agent (OSCommand Bridge) General
9.0
CRITICAL
EPSS
2.4%
2023 CWE-306 1 PoC

Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with deep knowledge of the system to execute scripts on all connected Diagnostics Agents. On successful exploitation, the attacker can completely compromise confidentiality, integrity and availability of the system.

CVE-2023-21974
Application Express (APEX) Web Database
9.0
CRITICAL
EPSS
0.7%
2023 1 PoC

Vulnerability in the Application Express Team Calendar Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Application Express Team Calendar Plugin: 18.2-22.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Application Express Team Calendar Plugin. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Application Express Team Calendar Plugin, attacks may significantly impact additional products (scope change).

CVE-2023-1715
Bitrix24 Web
9.0
CRITICAL
EPSS
0.1%
2023 CWE-79 1 PoC

A logic error when using mb_strpos() to check for potential XSS payload in Bitrix24 22.0.300 allows attackers to bypass XSS sanitisation via placing HTML tags at the begining of the payload.

CVE-2023-47861
AVideo Web
9.0
CRITICAL
EPSS
0.3%
2023 CWE-79 2 PoCs

A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.

CVE-2023-0106
usememos/memos Web
9.0
CRITICAL
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

CVE-2023-0432
DX-2100-L1-CN General
9.0
CRITICAL
EPSS
1.8%
2023 CWE-79 1 PoC

The web configuration service of the affected device contains an authenticated command injection vulnerability. It can be used to execute system commands on the operating system (OS) from the device in the context of the user "root." If the attacker has credentials for the web service, then the device could be fully compromised.

CVE-2023-34192
🔥 KEV Software Genérico General ⚡ nuclei
9.0
CRITICAL
EPSS
89.0%
2023 0 PoCs

Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.

CVE-2023-1287
ENOVIA Live Collaboration General
9.0
CRITICAL
EPSS
2.6%
2023 CWE-74 1 PoC

An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution.

CVE-2023-31703
Software Genérico Web
9.0
CRITICAL
EPSS
1.6%
2023 3 PoCs

Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the from parameter.