2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-5400
Experion Server General
8.1
HIGH
EPSS
1.6%
2023 CWE-122 1 PoC

Server receiving a malformed message based on a using the specified key values can cause a heap overflow vulnerability which could lead to an attacker performing remote code execution or causing a failure.  See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-39372
Softswitch Web
8.1
HIGH
EPSS
0.1%
2023 CWE-352 1 PoC

StarTrinity Softswitch version 2023-02-16 - Multiple CSRF (CWE-352)

CVE-2023-40464
ALEOS General
8.1
HIGH
EPSS
0.0%
2023 CWE-321 1 PoC

Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An attacker with access to these items could potentially perform a man in the middle attack between the ACEManager client and ACEManager server.

CVE-2023-46694
Software Genérico General
8.1
HIGH
EPSS
9.1%
2023 1 PoC

Vtenext 21.02 allows an authenticated attacker to upload arbitrary files, potentially enabling them to execute remote commands. This flaw exists due to the application's failure to enforce proper authentication controls when accessing the Ckeditor file manager functionality.

CVE-2023-40461
ALEOS Web
8.1
HIGH
EPSS
0.0%
2023 CWE-79 1 PoC

The ACEManager component of ALEOS 4.16 and earlier allows an authenticated user with Administrator privileges to access a file upload field which does not fully validate the file name, creating a Stored Cross-Site Scripting condition.

CVE-2023-46304
Software Genérico Web
8.1
HIGH
EPSS
20.8%
2023 1 PoC

modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).

CVE-2023-50447
Software Genérico General
8.1
HIGH
EPSS
0.7%
2023 2 PoCs

Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).

CVE-2023-0787
thorsten/phpmyfaq Web
8.1
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

CVE-2023-4899
mintplex-labs/anything-llm Database
8.1
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.

CVE-2023-4395
cockpit-hq/cockpit Web
8.1
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.4.

CVE-2023-0441
Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery Web Windows
8.1
HIGH
EPSS
0.4%
2023 1 PoC

The Gallery Blocks with Lightbox WordPress plugin before 3.0.8 has an AJAX endpoint that can be accessed by any authenticated users, such as subscriber. The callback function allows numerous actions, the most serious one being reading and updating the WordPress options which could be used to enable registration with a default administrator user role.

CVE-2023-51073
Software Genérico General
8.1
HIGH
EPSS
26.0%
2023 1 PoC

An issue in Buffalo LS210D v.1.78-0.03 allows a remote attacker to execute arbitrary code via the Firmware Update Script at /etc/init.d/update_notifications.sh.

CVE-2023-44857
Software Genérico General
8.1
HIGH
EPSS
0.4%
2023 1 PoC

An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_21D24 function in the acu_web component.

CVE-2023-34216
TN-5900 Series General
8.1
HIGH
EPSS
0.3%
2023 CWE-22 1 PoC

TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability derives from insufficient input validation in the key-delete function, which could potentially allow malicious users to delete arbitrary files.

CVE-2023-3224
nuxt/nuxt General
8.1
HIGH
EPSS
2.1%
2023 CWE-94 1 PoC

Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3.

CVE-2023-26984
Software Genérico General
8.1
HIGH
EPSS
0.8%
2023 1 PoC

An issue in the password reset function of Peppermint v0.2.4 allows attackers to access the emails and passwords of the Tickets page via a crafted request.

CVE-2023-20938
Android General
8.1
HIGH
EPSS
0.2%
2023 1 PoC

In binder_transaction_buffer_release of binder.c, there is a possible use after free due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-257685302References: Upstream kernel

CVE-2023-3191
nilsteampassnet/teampass Web
8.1
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

CVE-2023-45841
Buildroot General
8.1
HIGH
EPSS
0.1%
2023 CWE-494 2 PoCs

Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `versal-firmware` package.

CVE-2023-5355
Awesome Support Web Windows
8.1
HIGH
EPSS
0.2%
2023 1 PoC

The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server.