2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-1196
Advanced Custom Fields (ACF) Web Windows
8.8
HIGH
EPSS
0.9%
2023 2 PoCs

The Advanced Custom Fields (ACF) Free and Pro WordPress plugins 6.x before 6.1.0 and 5.x before 5.12.5 unserialize user controllable data, which could allow users with a role of Contributor and above to perform PHP Object Injection when a suitable gadget is present.

CVE-2023-22613
Software Genérico General
8.8
HIGH
EPSS
0.1%
2023 1 PoC

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI handler with a malformed pointer in RCX that overlaps SMRAM, resulting in SMM memory corruption.

CVE-2023-6528
Slider Revolution Web Windows
8.8
HIGH
EPSS
15.8%
2023 1 PoC

The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.

CVE-2023-5041
Track The Click Web Database Windows
8.8
HIGH
EPSS
0.3%
2023 1 PoC

The Track The Click WordPress plugin before 0.3.12 does not properly sanitize query parameters to the stats REST endpoint before using them in a database query, allowing a logged in user with an author role or higher to perform time based blind SQLi attacks on the database.

CVE-2023-5311
WP EXtra – One Click Optimize Web Windows
8.8
HIGH
EPSS
6.6%
2023 CWE-862 1 PoC

The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to modify the contents of the .htaccess files located in a site's root directory or /wp-content and /wp-includes folders and achieve remote code execution. CVE-2023-46623 appears to be a duplicate of this issue.

CVE-2023-2934
Chrome General
8.8
HIGH
EPSS
0.8%
2023 1 PoC

Out of bounds memory access in Mojo in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-32031
Microsoft Exchange Server 2019 Cumulative Update 12 Windows
8.8
HIGH
EPSS
42.1%
2023 CWE-502 1 PoC

Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2023-50702
Software Genérico Windows
8.8
HIGH
EPSS
0.2%
2023 1 PoC

Sikka SSCWindowsService 5 2023-09-14 executes a program as LocalSystem but allows full control by low-privileged users (and low-privileged users have write access to %PROGRAMDATA%\SSCService). Consequently, low-privileged users can execute arbitrary code as LocalSystem.

CVE-2023-1306
InsightCloudSec Cloud
8.8
HIGH
EPSS
0.6%
2023 CWE-94 1 PoC

An authenticated attacker can leverage an exposed resource.db() accessor method to smuggle Python method calls via a Jinja template, which can lead to code execution. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.

CVE-2023-31275
WPS Office General
8.8
HIGH
EPSS
1.0%
2023 CWE-457 1 PoC

An uninitialized pointer use vulnerability exists in the functionality of WPS Office 11.2.0.11537 that handles Data elements in an Excel file. A specially crafted malformed file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-39928
Webkit Web
8.8
HIGH
EPSS
0.2%
2023 CWE-416 1 PoC

A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to to visit a malicious webpage to trigger this vulnerability.

CVE-2023-28231
Windows Server 2019 Windows
8.8
HIGH
EPSS
75.5%
2023 CWE-122 2 PoCs

DHCP Server Service Remote Code Execution Vulnerability

CVE-2023-7074
WP SOCIAL BOOKMARK MENU Web Windows
8.8
HIGH
EPSS
0.1%
2023 1 PoC

The WP SOCIAL BOOKMARK MENU WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVE-2023-6976
mlflow/mlflow General
8.8
HIGH
EPSS
0.1%
2023 CWE-434 1 PoC

This vulnerability is capable of writing arbitrary files into arbitrary locations on the remote filesystem in the context of the server process.

CVE-2023-46537
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function getRegVeriRegister.

CVE-2023-4125
answerdev/answer General
8.8
HIGH
EPSS
0.2%
2023 CWE-521 1 PoC

Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0.

CVE-2023-20872
VMware Workstation Pro / Player (Workstation) and VMware Fusion General
8.8
HIGH
EPSS
1.1%
2023 1 PoC

VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation.

CVE-2023-45160
1E Client Windows
8.8
HIGH
EPSS
0.3%
2023 CWE-552 1 PoC

In the affected version of the 1E Client, an ordinary user could subvert downloaded instruction resource files, e.g., to substitute a harmful script. by replacing a resource script file created by an instruction at run time with a malicious script. The 1E Client's temporary directory is now locked down in the released patch. Resolution: This has been fixed in patch Q23094  This issue has also been fixed in the Mac Client in updated versions of Non-Windows release v8.1.2.62 - please re-download from the 1E Support site. Customers with Mac Client versions higher than v8.1 will need to upgr

CVE-2023-1304
InsightCloudSec Cloud
8.8
HIGH
EPSS
0.5%
2023 CWE-94 1 PoC

An authenticated attacker can leverage an exposed getattr() method via a Jinja template to smuggle OS commands and perform other actions that are normally expected to be private methods. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.

CVE-2023-34448
grav Web
8.8
HIGH
EPSS
8.8%
2023 CWE-20 1 PoC

Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side template injection vulnerability in Grav leveraging the default `filter()` function, did not block other built-in functions exposed by Twig's Core Extension that could be used to invoke arbitrary unsafe functions, thereby allowing for remote code execution. A patch in version 1.74.2 overrides the built-in Twig `map()` and `reduce()` filter functions in `system/src/Grav/Common/Twig/Extension/GravExtension.php` to validate the argument passed to the filter in `$arrow`.