2785 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-27032
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
40.8%
2023 1 PoC

Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component AdvancedPopup::getPopups().

CVE-2023-6928
ETL3100 General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-307 1 PoC

EuroTel ETL3100 versions v01c01 and v01x37 does not limit the number of attempts to guess administrative credentials in remote password attacks to gain full control of the system.

CVE-2023-24199
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php.

CVE-2023-29732
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

SoLive 1.6.14 thru 1.6.20 for Android exists exposed component, the component provides the method to modify the SharedPreference file. The attacker can use the method to modify the data in any SharedPreference file, these data will be loaded into the memory when the application is opened. Depending on how the data is used, this can result in various attack consequences, such as ad display exceptions.

CVE-2023-50578
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
31.7%
2023 1 PoC

Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.

CVE-2023-42374
Software Genérico General
9.8
CRITICAL
EPSS
2.8%
2023 3 PoCs

An issue in mystenlabs Sui Blockchain before v.1.6.3 allow a remote attacker to execute arbitrary code and cause a denial of service via a crafted compressed script to the Sui node component.

CVE-2023-6233
Satera LBP670C Series General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-787 2 PoCs

Buffer overflow in SLP attribute request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.

CVE-2023-26999
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file.

CVE-2023-34152
ImageMagick General
9.8
CRITICAL
EPSS
69.5%
2023 CWE-20 2 PoCs

A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.

CVE-2023-1307
froxlor/froxlor General
9.8
CRITICAL
EPSS
0.2%
2023 CWE-305 1 PoC

Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13.

CVE-2023-23059
Software Genérico Windows
9.8
CRITICAL
EPSS
0.8%
2023 1 PoC

An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions within the default installation and allows attackers to execute arbitrary code and gain escalated privileges.

CVE-2023-51717
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass.

CVE-2023-24198
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Raffle Draw System v1.0 was discovered to contain multiple SQL injection vulnerabilities at save_winner.php via the ticket_id and draw parameters.

CVE-2023-34039
Aria Operations for Networks Networking
9.8
CRITICAL
EPSS
93.2%
2023 7 PoCs

Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for Networks CLI.

CVE-2023-32222
DSL-G256DG firmware version vBZ_1.00.27 General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

D-Link DSL-G256DG version vBZ_1.00.27 web management interface allows authentication bypass via an unspecified method.

CVE-2023-46661
PolyEco1000 General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-284 1 PoC

Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests.

CVE-2023-28504
UniData General
9.8
CRITICAL
EPSS
2.0%
2023 CWE-120 1 PoC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow that can lead to remote code execution as the root user.

CVE-2023-2732
MStore API – Create Native Android & iOS Apps On The Cloud Web Cloud Windows ⚡ nuclei
9.8
CRITICAL
EPSS
90.3%
2023 CWE-288 5 PoCs

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.

CVE-2023-49543
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 2 PoCs

Incorrect access control in Book Store Management System v1 allows attackers to access unauthorized pages and execute administrative functions without authenticating.

CVE-2023-39667
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the FUN_0000acb4 function.