2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-30350
Software Genérico Cloud
8.8
HIGH
EPSS
3.3%
2023 1 PoC

FS S3900-24T4S devices allow authenticated attackers with guest access to escalate their privileges and reset the admin password.

CVE-2023-50223
Ignition General
8.8
HIGH
EPSS
49.0%
2023 CWE-502 1 PoC

Inductive Automation Ignition ExtendedDocumentCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability. The specific flaw exists within the ExtendedDocumentCodec class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI

CVE-2023-6532
WP Blogs' Planetarium Web Windows
8.8
HIGH
EPSS
0.2%
2023 1 PoC

The WP Blogs' Planetarium WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2023-53974
DSL-124 Wireless N300 ADSL2+ Networking
8.8
HIGH
EPSS
0.1%
2023 CWE-306 1 PoC

D-Link DSL-124 ME_1.00 contains a configuration file disclosure vulnerability that allows unauthenticated attackers to retrieve router settings through a POST request. Attackers can send a specific POST request to the router's configuration endpoint to download a complete backup file containing sensitive network credentials and system configurations.

CVE-2023-39928
Webkit Web
8.8
HIGH
EPSS
0.2%
2023 CWE-416 1 PoC

A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to to visit a malicious webpage to trigger this vulnerability.

CVE-2023-34253
grav Web
8.8
HIGH
EPSS
2.1%
2023 CWE-184 1 PoC

Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prevent dangerous functions from being executed via injection of malicious templates was insufficient and could be easily subverted in multiple ways -- (1) using unsafe functions that are not banned, (2) using capitalised callable names, and (3) using fully-qualified names for referencing callables. Consequently, a low privileged attacker with login access to Grav Admin panel and page creation/update permissions is able to inject malicious templates to obtain remote code executio

CVE-2023-47992
Software Genérico General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

An integer overflow vulnerability in FreeImageIO.cpp::_MemoryReadProc in FreeImage 3.18.0 allows attackers to obtain sensitive information, cause a denial-of-service attacks and/or run arbitrary code.

CVE-2023-24344
Software Genérico Networking
8.8
HIGH
EPSS
0.6%
2023 1 PoC

D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWlanGuestSetup.

CVE-2023-50219
Ignition General
8.8
HIGH
EPSS
8.9%
2023 CWE-502 1 PoC

Inductive Automation Ignition RunQuery Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability. The specific flaw exists within the RunQuery class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-21625.

CVE-2023-46522
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TP-LINK device TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin and TL-WDR7660 2.0.30 were discovered to contain a stack overflow via the function deviceInfoRegister.

CVE-2023-33131
Microsoft Office 2019 General
8.8
HIGH
EPSS
2.7%
2023 1 PoC

Microsoft Outlook Remote Code Execution Vulnerability

CVE-2023-32632
YF325 General
8.8
HIGH
EPSS
0.2%
2023 CWE-284 1 PoC

A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.

CVE-2023-32749
Software Genérico Web
8.8
HIGH
EPSS
47.3%
2023 5 PoCs

Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying the HTTP request sent when creating such an external user, it is possible to assign the new user arbitrary roles. By assigning all roles to a newly created user, access to all cells and non-personal workspaces is granted.

CVE-2023-6702
Chrome General
8.8
HIGH
EPSS
57.9%
2023 1 PoC

Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-0340
Custom Content Shortcode Web Windows
8.8
HIGH
EPSS
1.2%
2023 1 PoC

The Custom Content Shortcode WordPress plugin through 4.0.2 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also be achieved if the attacker manage to upload a malicious image containing PHP code, and then include it via the affected attribute, on a default WP install, authors could easily achieve that given that they have the upload_file capability.

CVE-2023-45317
Analog FM transmitter Web
8.8
HIGH
EPSS
0.1%
2023 CWE-352 2 PoCs

The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.

CVE-2023-24610
Software Genérico Web
8.8
HIGH
EPSS
16.7%
2023 1 PoC

NOSH 4a5cfdb allows remote authenticated users to execute PHP arbitrary code via the "practice logo" upload feature. The client-side checks can be bypassed. This may allow attackers to steal Protected Health Information because the product is for health charting.

CVE-2023-26860
Software Genérico Database
8.8
HIGH
EPSS
0.5%
2023 1 PoC

SQL injection vulnerability found in PrestaShop Igbudget v.1.0.3 and before allow a remote attacker to gain privileges via the LgBudgetBudgetModuleFrontController::displayAjaxGenerateBudget component.

CVE-2023-33722
Software Genérico General
8.8
HIGH
EPSS
2.6%
2023 1 PoC

EDIMAX BR-6288ACL v1.12 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the pppUserName parameter.

CVE-2023-43238
Software Genérico General
8.8
HIGH
EPSS
2.5%
2023 1 PoC

D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter nvmacaddr in form2Dhcpip.cgi.