2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-23464
Media Control Panel General
8.1
HIGH
EPSS
0.2%
2023 1 PoC

Media CP Media Control Panel latest version. A Permissive Flash Cross-domain Policy may allow information disclosure.

CVE-2023-5355
Awesome Support Web Windows
8.1
HIGH
EPSS
0.2%
2023 1 PoC

The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server.

CVE-2023-34217
TN-5900 Series General
8.1
HIGH
EPSS
0.2%
2023 CWE-22 1 PoC

TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability stems from insufficient input validation in the certificate-delete function, which could potentially allow malicious users to delete arbitrary files.

CVE-2023-0441
Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery Web Windows
8.1
HIGH
EPSS
0.4%
2023 1 PoC

The Gallery Blocks with Lightbox WordPress plugin before 3.0.8 has an AJAX endpoint that can be accessed by any authenticated users, such as subscriber. The callback function allows numerous actions, the most serious one being reading and updating the WordPress options which could be used to enable registration with a default administrator user role.

CVE-2023-5353
salesagility/suitecrm General
8.1
HIGH
EPSS
0.1%
2023 CWE-284 1 PoC

Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.

CVE-2023-1104
flatpressblog/flatpress Web
8.1
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2023-3393
fossbilling/fossbilling General
8.0
HIGH
EPSS
0.1%
2023 CWE-94 1 PoC

Code Injection in GitHub repository fossbilling/fossbilling prior to 0.5.1.

CVE-2023-49224
Software Genérico Networking
8.0
HIGH
EPSS
0.5%
2023 1 PoC

Precor touchscreen console P62, P80, and P82 contains a default SSH public key in the authorized_keys file. A remote attacker could use this key to gain root privileges.

CVE-2023-28310
Microsoft Exchange Server 2016 Cumulative Update 23 Windows
8.0
HIGH
EPSS
10.0%
2023 CWE-502 1 PoC

Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2023-1242
answerdev/answer Web
8.0
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.

CVE-2023-27367
RAX30 Web Networking
8.0
HIGH
EPSS
0.4%
2023 CWE-78 1 PoC

NETGEAR RAX30 libcms_cli Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the libcms_cli module. The issue results from the lack of proper validation of a user-supplied command before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was Z

CVE-2023-47564
Qsync Central General
8.0
HIGH
EPSS
8.0%
2023 CWE-732 1 PoC

An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.15 ( 2024/01/04 ) and later Qsync Central 4.3.0.11 ( 2024/01/11 ) and later

CVE-2023-21476
Samsung Mobile Devices General
8.0
HIGH
EPSS
0.0%
2023 1 PoC

Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.

CVE-2023-49501
Software Genérico Networking
8.0
HIGH
EPSS
0.0%
2023 2 PoCs

Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component.

CVE-2023-0741
answerdev/answer Web
8.0
HIGH
EPSS
0.4%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4.

CVE-2023-50009
Software Genérico Networking
8.0
HIGH
EPSS
0.0%
2023 2 PoCs

FFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gaussian_blur_8 function in libavfilter/edge_template.c:116:5 component.

CVE-2023-24047
Software Genérico General
8.0
HIGH
EPSS
0.0%
2023 1 PoC

An Insecure Credential Management issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via use of weak hashing algorithm.

CVE-2023-50231
ProSAFE Network Management System Web
8.0
HIGH
EPSS
26.3%
2023 CWE-79 1 PoC

NETGEAR ProSAFE Network Management System saveNodeLabel Cross-Site Scripting Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of NETGEAR ProSAFE Network Management System. Minimal user interaction is required to exploit this vulnerability. The specific flaw exists within the saveNodeLabel method. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to escalate privileges to resources normally

CVE-2023-21125
Android General
8.0
HIGH
EPSS
0.1%
2023 2 PoCs

In btif_hh_hsdata_rpt_copy_cb of bta_hh.cc, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-36745
Microsoft Exchange Server 2019 Cumulative Update 13 Windows
8.0
HIGH
EPSS
73.6%
2023 CWE-502 1 PoC

Microsoft Exchange Server Remote Code Execution Vulnerability