2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-39211
Zoom Desktop Client for Windows and Zoom Rooms for Windows Windows
8.8
HIGH
EPSS
0.0%
2023 CWE-347 1 PoC

Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via local access.

CVE-2023-43239
Software Genérico General
8.8
HIGH
EPSS
57.5%
2023 1 PoC

D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter flag_5G in showMACfilterMAC.

CVE-2023-51063
Software Genérico Web
8.8
HIGH
EPSS
0.1%
2023 1 PoC

QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based Reflected Cross Site Scripting (XSS) vulnerability within the component qnme-ajax?method=tree_level.

CVE-2023-38043
Secure Access Client Windows Windows
8.8
HIGH
EPSS
0.2%
2023 1 PoC

A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine and, in some cases, resulting in a full compromise of the system.

CVE-2023-23492
Login with Phone Number WordPress Plugin Web Database Windows ⚡ nuclei
8.8
HIGH
EPSS
88.3%
2023 1 PoC

The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action.

CVE-2023-29048
OX App Suite General
8.8
HIGH
EPSS
0.4%
2023 CWE-78 1 PoC

A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user. Users and attackers could run system commands with limited privilege to gain unauthorized access to confidential information and potentially violate integrity by modifying resources. The template engine has been reconfigured to deny execution of harmful commands on a system level. No publicly available exploits are known.

CVE-2023-46478
Software Genérico General
8.8
HIGH
EPSS
2.2%
2023 2 PoCs

An issue in minCal v.1.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the customer_data parameter.

CVE-2023-2552
unilogies/bumsys Web
8.8
HIGH
EPSS
0.2%
2023 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository unilogies/bumsys prior to 2.1.1.

CVE-2023-23596
Software Genérico Web Networking
8.8
HIGH
EPSS
4.7%
2023 1 PoC

jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted username and/or password input that is concatenated without any validation, and is directly passed to the exec command, potentially allowing an authenticated attacker to execute arbitrary commands on the system. NOTE: this is not part of any NGINX software shipped by F5.

CVE-2023-22612
Software Genérico General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. A malicious host OS can invoke an Insyde SMI handler with malformed arguments, resulting in memory corruption in SMM.

CVE-2023-32707
Splunk Enterprise Cloud
8.8
HIGH
EPSS
82.7%
2023 CWE-285 3 PoCs

In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edit_user’ capability assigned to it can escalate their privileges to that of the admin user by providing specially crafted web requests.

CVE-2023-6078
BIOVIA Materials Studio products General
8.8
HIGH
EPSS
0.3%
2023 CWE-78 1 PoC

An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023. Upload of a specially crafted perl script can lead to arbitrary command execution.

CVE-2023-4697
usememos/memos General
8.8
HIGH
EPSS
0.1%
2023 CWE-269 1 PoC

Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.

CVE-2023-27893
Solution Manager and ABAP managed systems General
8.8
HIGH
EPSS
5.1%
2023 CWE-94 1 PoC

An attacker authenticated as a user with a non-administrative role and a common remote execution authorization in SAP Solution Manager and ABAP managed systems (ST-PI) - versions 2088_1_700, 2008_1_710, 740, can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform.  Depending on the function executed, the attack can read or modify any user or application data and can make the application unavailable.

CVE-2023-48171
Software Genérico General
8.8
HIGH
EPSS
1.1%
2023 1 PoC

An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.

CVE-2023-0953
Devolutions Server Database
8.8
HIGH
EPSS
0.7%
2023 1 PoC

Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to perform an SQL Injection, potentially resulting in unauthorized access to system resources.

CVE-2023-33782
Software Genérico General
8.8
HIGH
EPSS
52.2%
2023 2 PoCs

D-Link DIR-842V2 v1.0.3 was discovered to contain a command injection vulnerability via the iperf3 diagnostics function.

CVE-2023-46520
Software Genérico General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function uninstallPluginReqHandle.

CVE-2023-46534
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function modifyAccPwdRegister.