2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-23295
Software Genérico General
8.8
HIGH
EPSS
2.3%
2023 1 PoC

Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as root.

CVE-2023-2674
openemr/openemr General
8.8
HIGH
EPSS
0.3%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.

CVE-2023-54333
Social-Share-Buttons Database
8.8
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

Social-Share-Buttons 2.2.3 contains a critical SQL injection vulnerability in the project_id parameter that allows attackers to manipulate database queries. Attackers can exploit this vulnerability by sending crafted POST requests with malicious SQL payloads to retrieve and potentially steal entire database contents.

CVE-2023-48171
Software Genérico General
8.8
HIGH
EPSS
1.1%
2023 1 PoC

An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.

CVE-2023-46478
Software Genérico General
8.8
HIGH
EPSS
2.2%
2023 2 PoCs

An issue in minCal v.1.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the customer_data parameter.

CVE-2023-32749
Software Genérico Web
8.8
HIGH
EPSS
47.3%
2023 5 PoCs

Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying the HTTP request sent when creating such an external user, it is possible to assign the new user arbitrary roles. By assigning all roles to a newly created user, access to all cells and non-personal workspaces is granted.

CVE-2023-1306
InsightCloudSec Cloud
8.8
HIGH
EPSS
0.6%
2023 CWE-94 1 PoC

An authenticated attacker can leverage an exposed resource.db() accessor method to smuggle Python method calls via a Jinja template, which can lead to code execution. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.

CVE-2023-34127
GMS Networking
8.8
HIGH
EPSS
90.6%
2023 CWE-78 1 PoC

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytics enables an authenticated attacker to execute arbitrary code with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

CVE-2023-47352
Software Genérico General
8.8
HIGH
EPSS
0.1%
2023 1 PoC

Technicolor TC8715D devices have predictable default WPA2 security passwords. An attacker who scans for SSID and BSSID values may be able to predict these passwords.

CVE-2023-6946
Autotitle for WordPress Web Windows
8.8
HIGH
EPSS
0.1%
2023 1 PoC

The Autotitle for WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVE-2023-25434
Software Genérico General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesBytes() at /libtiff/tools/tiffcrop.c:3215.

CVE-2023-46539
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function registerRequestHandle.

CVE-2023-24610
Software Genérico Web
8.8
HIGH
EPSS
16.7%
2023 1 PoC

NOSH 4a5cfdb allows remote authenticated users to execute PHP arbitrary code via the "practice logo" upload feature. The client-side checks can be bypassed. This may allow attackers to steal Protected Health Information because the product is for health charting.

CVE-2023-0611
TEW-652BRP General
8.8
HIGH
EPSS
2.9%
2023 CWE-77 1 PoC

A vulnerability, which was classified as critical, has been found in TRENDnet TEW-652BRP 3.04B01. This issue affects some unknown processing of the file get_set.ccp of the component Web Management Interface. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-219935.

CVE-2023-39508
Apache Airflow Web
8.8
HIGH
EPSS
0.5%
2023 CWE-250 1 PoC

Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Airflow.The "Run Task" feature enables authenticated user to bypass some of the restrictions put in place. It allows to execute code in the webserver context as well as allows to bypas limitation of access the user has to certain DAGs. The "Run Task" feature is considered dangerous and it has been removed entirely in Airflow 2.6.0 This issue affects Apache Airflow: before 2.6.0.

CVE-2023-1532
Chrome General
8.8
HIGH
EPSS
0.6%
2023 1 PoC

Out of bounds read in GPU Video in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-1241
answerdev/answer Web
8.8
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2023-4223
Chamilo Web
8.8
HIGH
EPSS
2.6%
2023 CWE-434 1 PoC

Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.

CVE-2023-51748
Software Genérico General
8.8
HIGH
EPSS
0.1%
2023 2 PoCs

ScaleFusion 10.5.2 does not properly limit users to the Edge application because Ctrl-O and Ctrl-S can be used. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode.

CVE-2023-0080
Customer Reviews for WooCommerce Web Windows
8.8
HIGH
EPSS
1.4%
2023 1 PoC

The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also be achieved if the attacker manage to upload a malicious image containing PHP code, and then include it via the affected attribute, on a default WP install, authors could easily achieve that given that they have the upload_file capability.