2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-21517
Samsung Mobile Devices General
8.8
HIGH
EPSS
8.5%
2023 CWE-120 1 PoC

Heap out-of-bound write vulnerability in Exynos baseband prior to SMR Jun-2023 Release 1 allows remote attacker to execute arbitrary code.

CVE-2023-2017
Shopware 6 Web
8.8
HIGH
EPSS
2.3%
2023 CWE-184 1 PoC

Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows remote attackers with access to a Twig environment without the Sandbox extension to bypass the validation checks in `Shopware\Core\Framework\Adapter\Twig\SecurityExtension` and call any arbitrary PHP function and thus execute arbitrary code/commands via usage of fully-qualified names, supplied as array of strings, when referencing callables. Users are advised to upgrade to v6.4.20.1 to resolve this issue. This is a bypa

CVE-2023-4225
Chamilo Web
8.8
HIGH
EPSS
2.3%
2023 CWE-434 1 PoC

Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files.

CVE-2023-0940
ProfileGrid Web Windows
8.8
HIGH
EPSS
0.6%
2023 1 PoC

The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization. This allows a user with low privileges, such as subscriber, to change the password of any account, including Administrator ones.

CVE-2023-4355
Chrome General
8.8
HIGH
EPSS
39.3%
2023 1 PoC

Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-4697
usememos/memos General
8.8
HIGH
EPSS
0.1%
2023 CWE-269 1 PoC

Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.

CVE-2023-25194
Apache Kafka Connect API Web ⚡ nuclei
8.8
HIGH
EPSS
94.1%
2023 CWE-502 4 PoCs

A possible security vulnerability has been identified in Apache Kafka Connect API. This requires access to a Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and a SASL-based security protocol, which has been possible on Kafka Connect clusters since Apache Kafka Connect 2.3.0. When configuring the connector via the Kafka Connect REST API, an authenticated operator can set the `sasl.jaas.config` property for any of the connector's Kafka clients to "com.sun.security.auth.module.JndiLoginModule", which can be done via the `pro

CVE-2023-29842
Software Genérico Web Database
8.8
HIGH
EPSS
0.1%
2023 3 PoCs

ChurchCRM 4.5.4 endpoint /EditEventTypes.php is vulnerable to Blind SQL Injection (Time-based) via the EN_tyid POST parameter.

CVE-2023-3124
Elementor Website Builder Pro Web Windows
8.8
HIGH
EPSS
26.0%
2023 CWE-862 1 PoC

The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level capabilities to update arbitrary site options, which can lead to privilege escalation.

CVE-2023-31874
Software Genérico General
8.8
HIGH
EPSS
1.7%
2023 1 PoC

Yank Note (YN) 3.52.1 allows execution of arbitrary code when a crafted file is opened, e.g., via nodeRequire('child_process').

CVE-2023-31433
Software Genérico Database
8.8
HIGH
EPSS
0.5%
2023 2 PoCs

A SQL injection issue in Logbuch in evasys before 8.2 Build 2286 and 9.x before 9.0 Build 2401 allows authenticated attackers to execute SQL statements via the welche parameter.

CVE-2023-50233
Ignition General
8.8
HIGH
EPSS
3.7%
2023 CWE-22 1 PoC

Inductive Automation Ignition getJavaExecutable Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this vulnerability in that the target must connect to a malicious server. The specific flaw exists within the getJavaExecutable method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context

CVE-2023-7074
WP SOCIAL BOOKMARK MENU Web Windows
8.8
HIGH
EPSS
0.1%
2023 1 PoC

The WP SOCIAL BOOKMARK MENU WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVE-2023-4033
mlflow/mlflow General
8.8
HIGH
EPSS
0.2%
2023 CWE-78 1 PoC

OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0.

CVE-2023-33781
Software Genérico General
8.8
HIGH
EPSS
42.4%
2023 2 PoCs

An issue in D-Link DIR-842V2 v1.0.3 allows attackers to execute arbitrary commands via importing a crafted file.

CVE-2023-4536
My Account Page Editor Web Windows
8.8
HIGH
EPSS
0.6%
2023 1 PoC

The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE

CVE-2023-0189
vGPU software (guest driver - Linux), NVIDIA Cloud Gaming (guest driver - Linux) Cloud
8.8
HIGH
EPSS
0.2%
2023 CWE-822 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2023-46536
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function chkRegVeriRegister.

CVE-2023-46521
Software Genérico General
8.8
HIGH
EPSS
0.2%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function RegisterRegister.

CVE-2023-46534
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function modifyAccPwdRegister.