2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-6528
Slider Revolution Web Windows
8.8
HIGH
EPSS
15.8%
2023 1 PoC

The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.

CVE-2023-4352
Chrome General
8.8
HIGH
EPSS
1.4%
2023 1 PoC

Type confusion in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-32207
Firefox General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

A missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

CVE-2023-22613
Software Genérico General
8.8
HIGH
EPSS
0.1%
2023 1 PoC

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI handler with a malformed pointer in RCX that overlaps SMRAM, resulting in SMM memory corruption.

CVE-2023-24583
UR32L Networking
8.8
HIGH
EPSS
0.2%
2023 CWE-77 1 PoC

Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This OS command injection is triggered through a UDP packet.

CVE-2023-5953
Welcart e-Commerce Web Windows
8.8
HIGH
EPSS
0.2%
2023 1 PoC

The Welcart e-Commerce WordPress plugin before 2.9.5 does not validate files to be uploaded, as well as does not have authorisation and CSRF in an AJAX action handling such upload. As a result, any authenticated users, such as subscriber could upload arbitrary files, such as PHP on the server

CVE-2023-25266
Software Genérico General
8.8
HIGH
EPSS
5.7%
2023 1 PoC

An issue was discovered in Docmosis Tornado prior to version 2.9.5. An authenticated attacker can change the Office directory setting pointing to an arbitrary remote network path. This triggers the execution of the soffice binary under the attackers control leading to arbitrary remote code execution (RCE).

CVE-2023-28659
Waiting: One-click Countdowns WordPress Plugin Web Database Windows
8.8
HIGH
EPSS
1.1%
2023 1 PoC

The Waiting: One-click Countdowns WordPress Plugin, version <= 0.6.2, is affected by an authenticated SQL injection vulnerability in the pbc_down[meta][id] parameter of the pbc_save_downs action.

CVE-2023-50159
Software Genérico Windows
8.8
HIGH
EPSS
0.0%
2023 2 PoCs

In ScaleFusion (Windows Desktop App) agent 10.5.2, Kiosk mode application restrictions can be bypassed allowing arbitrary code to be executed. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode.

CVE-2023-24269
Software Genérico General
8.8
HIGH
EPSS
0.4%
2023 1 PoC

An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Zip file.

CVE-2023-2288
Otter Web Windows
8.8
HIGH
EPSS
14.1%
2023 1 PoC

The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operations on them. This leads to a PHAR deserialization vulnerability on PHP < 8.0 using the phar:// stream wrapper.

CVE-2023-24652
Software Genérico Database
8.8
HIGH
EPSS
0.2%
2023 2 PoCs

Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the Description parameter under the Create ticket function.

CVE-2023-6391
Custom User CSS Web Windows
8.8
HIGH
EPSS
0.1%
2023 1 PoC

The Custom User CSS WordPress plugin through 0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVE-2023-1713
Bitrix24 Web
8.8
HIGH
EPSS
3.9%
2023 CWE-434 2 PoCs

Insecure temporary file creation in bitrix/modules/crm/lib/order/import/instagram.php in Bitrix24 22.0.300 hosted on Apache HTTP Server allows remote authenticated attackers to execute arbitrary code via uploading a crafted ".htaccess" file.

CVE-2023-41993
🔥 KEV macOS General
8.8
HIGH
EPSS
24.2%
2023 4 PoCs

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CVE-2023-26876
Software Genérico Web Database
8.8
HIGH
EPSS
54.1%
2023 2 PoCs

SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id parameter to the admin.php?page=history&filter_image_id=&filter_user_id endpoint.

CVE-2023-38573
Foxit Reader Web
8.8
HIGH
EPSS
0.0%
2023 CWE-416 2 PoCs

A use-after-free vulnerability exists in the way Foxit Reader 12.1.2.15356 handles a signature field. A specially crafted Javascript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

CVE-2023-36899
Microsoft .NET Framework 4.8 General
8.8
HIGH
EPSS
70.0%
2023 CWE-20 2 PoCs

ASP.NET Elevation of Privilege Vulnerability

CVE-2023-43641
libcue Web
8.8
HIGH
EPSS
80.2%
2023 CWE-787 2 PoCs

libcue provides an API for parsing and extracting data from CUE sheets. Versions 2.2.1 and prior are vulnerable to out-of-bounds array access. A user of the GNOME desktop environment can be exploited by downloading a cue sheet from a malicious webpage. Because the file is saved to `~/Downloads`, it is then automatically scanned by tracker-miners. And because it has a .cue filename extension, tracker-miners use libcue to parse the file. The file exploits the vulnerability in libcue to gain code execution. This issue is patched in version 2.3.0.