2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-25356
Software Genérico General
8.8
HIGH
EPSS
17.5%
2023 1 PoC

CoreDial sipXcom up to and including 21.04 is vulnerable to Improper Neutralization of Argument Delimiters in a Command. XMPP users are able to inject arbitrary arguments into a system command, which can be used to read files from, and write files to, the sipXcom server. This can also be leveraged to gain remote command execution.

CVE-2023-2724
Chrome General
8.8
HIGH
EPSS
15.2%
2023 1 PoC

Type confusion in V8 in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-39508
Apache Airflow Web
8.8
HIGH
EPSS
0.5%
2023 CWE-250 1 PoC

Execution with Unnecessary Privileges, : Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Airflow.The "Run Task" feature enables authenticated user to bypass some of the restrictions put in place. It allows to execute code in the webserver context as well as allows to bypas limitation of access the user has to certain DAGs. The "Run Task" feature is considered dangerous and it has been removed entirely in Airflow 2.6.0 This issue affects Apache Airflow: before 2.6.0.

CVE-2023-23490
Survey Maker WordPress Plugin Web Database Windows
8.8
HIGH
EPSS
1.4%
2023 1 PoC

The Survey Maker WordPress Plugin, version < 3.1.2, is affected by an authenticated SQL injection vulnerability in the 'surveys_ids' parameter of its 'ays_surveys_export_json' action.

CVE-2023-1532
Chrome General
8.8
HIGH
EPSS
0.6%
2023 1 PoC

Out of bounds read in GPU Video in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-1241
answerdev/answer Web
8.8
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2023-4223
Chamilo Web
8.8
HIGH
EPSS
2.6%
2023 CWE-434 1 PoC

Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.

CVE-2023-51748
Software Genérico General
8.8
HIGH
EPSS
0.1%
2023 2 PoCs

ScaleFusion 10.5.2 does not properly limit users to the Edge application because Ctrl-O and Ctrl-S can be used. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode.

CVE-2023-50702
Software Genérico Windows
8.8
HIGH
EPSS
0.2%
2023 1 PoC

Sikka SSCWindowsService 5 2023-09-14 executes a program as LocalSystem but allows full control by low-privileged users (and low-privileged users have write access to %PROGRAMDATA%\SSCService). Consequently, low-privileged users can execute arbitrary code as LocalSystem.

CVE-2023-0080
Customer Reviews for WooCommerce Web Windows
8.8
HIGH
EPSS
1.4%
2023 1 PoC

The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also be achieved if the attacker manage to upload a malicious image containing PHP code, and then include it via the affected attribute, on a default WP install, authors could easily achieve that given that they have the upload_file capability.

CVE-2023-24652
Software Genérico Database
8.8
HIGH
EPSS
0.2%
2023 2 PoCs

Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the Description parameter under the Create ticket function.

CVE-2023-47179
WooODT Lite General
8.8
HIGH
EPSS
19.1%
2023 CWE-862 1 PoC

Missing Authorization vulnerability in mdalabar WooODT Lite byconsole-woo-order-delivery-time allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooODT Lite: from n/a through <= 2.4.6.

CVE-2023-46748
🔥 KEV BIG-IP Database
8.8
HIGH
EPSS
4.3%
2023 CWE-89 1 PoC

An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2023-24333
Software Genérico General
8.8
HIGH
EPSS
0.1%
2023 1 PoC

A stack overflow vulnerability in Tenda AC21 with firmware version US_AC21V1.0re_V16.03.08.15_cn_TDC01 allows attackers to run arbitrary commands via crafted POST request to /goform/openSchedWifi.

CVE-2023-35985
Foxit Reader Web
8.8
HIGH
EPSS
0.3%
2023 CWE-73 4 PoCs

An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to a failure to properly validate a dangerous extension. A specially crafted malicious file can create files at arbitrary locations, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially-crafted malicious site if the browser plugin extension is enabled.

CVE-2023-34468
Apache NiFi Web
8.8
HIGH
EPSS
77.8%
2023 CWE-94 4 PoCs

The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The resolution validates the Database URL and rejects H2 JDBC locations. You are recommended to upgrade to version 1.22.0 or later which fixes this issue.

CVE-2023-31061
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2023 1 PoC

Repetier Server through 1.4.10 does not have CSRF protection.

CVE-2023-6991
JSM file_get_contents() Shortcode Web Windows
8.8
HIGH
EPSS
0.2%
2023 1 PoC

The JSM file_get_contents() Shortcode WordPress plugin before 2.7.1 does not validate one of its shortcode's parameters before making a request to it, which could allow users with contributor role and above to perform SSRF attacks.

CVE-2023-22612
Software Genérico General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. A malicious host OS can invoke an Insyde SMI handler with malformed arguments, resulting in memory corruption in SMM.