2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-46527
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin and TL-WDR7660 2.0.30 was discovered to contain a stack overflow via the function bindRequestHandle.

CVE-2023-31272
YF325 Web
8.8
HIGH
EPSS
0.2%
2023 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the httpd do_wds functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to stack-based buffer overflow. An attacker can send a network request to trigger this vulnerability.

CVE-2023-6528
Slider Revolution Web Windows
8.8
HIGH
EPSS
15.8%
2023 1 PoC

The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.

CVE-2023-35674
🔥 KEV Android Windows
8.8
HIGH
EPSS
0.1%
2023 2 PoCs

In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-0953
Devolutions Server Database
8.8
HIGH
EPSS
0.7%
2023 1 PoC

Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to perform an SQL Injection, potentially resulting in unauthorized access to system resources.

CVE-2023-46520
Software Genérico General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function uninstallPluginReqHandle.

CVE-2023-2843
MultiParcels Shipping For WooCommerce Web Database Windows
8.8
HIGH
EPSS
0.4%
2023 1 PoC

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.15 does not properly sanitize and escape a parameter before using it in an SQL statement, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks.

CVE-2023-54163
NLB mKlik Makedonija Database
8.8
HIGH
EPSS
0.1%
2023 CWE-89 2 PoCs

NLB mKlik Macedonia 3.3.12 contains a SQL injection vulnerability in international transfer parameters that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code through unsanitized input to potentially disclose sensitive information from the mobile banking application.

CVE-2023-42491
EisBaer Scada General
8.8
HIGH
EPSS
0.2%
2023 CWE-285 1 PoC

EisBaer Scada - CWE-285: Improper Authorization

CVE-2023-50015
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

An issue was discovered in Grandstream GXP14XX 1.0.8.9 and GXP16XX 1.0.7.13, allows remote attackers to escalate privileges via incorrect access control using an end-user session-identity token.

CVE-2023-32221
Todo Backup General
8.8
HIGH
EPSS
0.0%
2023 1 PoC

EaseUS Todo Backup version 20220111.390 - An omission during installation may allow a local attacker to perform privilege escalation.

CVE-2023-50386
Apache Solr Web
8.8
HIGH
EPSS
84.7%
2023 CWE-434 1 PoC

Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1. In the affected versions, Solr ConfigSets accepted Java jar and class files to be uploaded through the ConfigSets API. When backing up Solr Collections, these configSet files would be saved to disk when using the LocalFileSystemRepository (the default for backups). If the backup was saved to a directory that Solr uses in i

CVE-2023-21742
Microsoft SharePoint Enterprise Server 2016 Windows
8.8
HIGH
EPSS
16.5%
2023 CWE-284 1 PoC

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVE-2023-38346
Software Genérico General
8.8
HIGH
EPSS
0.9%
2023 1 PoC

An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also processes files within an archive that have relative or absolute file paths. A developer using the "tarExtract" function may expect that the function will strip leading slashes from absolute paths or stop processing when encountering relative paths that are outside of the extraction path, unless otherwise forced. This could lead to unexpected and undocumented behavior, which in general could result in a directory traversal, and associated unexpected behavior.

CVE-2023-33782
Software Genérico General
8.8
HIGH
EPSS
52.2%
2023 2 PoCs

D-Link DIR-842V2 v1.0.3 was discovered to contain a command injection vulnerability via the iperf3 diagnostics function.

CVE-2023-24269
Software Genérico General
8.8
HIGH
EPSS
0.4%
2023 1 PoC

An arbitrary file upload vulnerability in the plugin upload function of Textpattern v4.8.8 allows attackers to execute arbitrary code via a crafted Zip file.

CVE-2023-4226
Chamilo Web
8.8
HIGH
EPSS
24.0%
2023 CWE-434 3 PoCs

Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.

CVE-2023-24582
UR32L Networking
8.8
HIGH
EPSS
0.2%
2023 CWE-77 1 PoC

Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This OS command injection is triggered through a TCP packet.

CVE-2023-0820
User Role by BestWebSoft Web Windows
8.8
HIGH
EPSS
0.1%
2023 1 PoC

The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role.