728 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-27648
Software Genérico General
9.8
CRITICAL
EPSS
6.0%
2023 1 PoC

Directory Traversal vulnerability found in T-ME Studios Change Color of Keypad v.1.275.1.277 allows a remote attacker to execute arbitrary code via the dex file in the internal storage.

CVE-2023-46485
Software Genérico General
9.8
CRITICAL
EPSS
4.6%
2023 1 PoC

An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setTracerouteCfg function of the stecgi.cgi component.

CVE-2023-49954
Software Genérico Database
9.8
CRITICAL
EPSS
0.7%
2023 1 PoC

The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search string, or email address.

CVE-2023-35965
YF325 Web
9.8
CRITICAL
EPSS
0.3%
2023 CWE-190 1 PoC

Two heap-based buffer overflow vulnerabilities exist in the httpd manage_post functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger these vulnerabilities.This integer overflow result is used as argument for the malloc function.

CVE-2023-28502
UniData General
9.8
CRITICAL
EPSS
69.3%
2023 CWE-120 2 PoCs

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "udadmin" service that can lead to remote code execution as the root user.

CVE-2023-1133
InfraSuite Device Master General
9.8
CRITICAL
EPSS
86.1%
2023 1 PoC

Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated attacker to remotely execute arbitrary code.

CVE-2023-52031
Software Genérico General
9.8
CRITICAL
EPSS
14.8%
2023 1 PoC

TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the UploadFirmwareFile function.

CVE-2023-22741
sofia-sip General
9.8
CRITICAL
EPSS
1.4%
2023 CWE-120 2 PoCs

Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. In affected versions Sofia-SIP **lacks both message length and attributes length checks** when it handles STUN packets, leading to controllable heap-over-flow. For example, in stun_parse_attribute(), after we get the attribute's type and length value, the length will be used directly to copy from the heap, regardless of the message's left size. Since network users control the overflowed length, and the data is written to heap chunks later, attackers may achieve remote code execution by heap groom

CVE-2023-28667
Lead Generated WordPress Plugin Web Windows
9.8
CRITICAL
EPSS
1.0%
2023 1 PoC

The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels parameter of the tve_api_form_submit action is passed to the PHP unserialize() function without being sanitized or verified, and as a result could lead to PHP object injection, which when combined with certain class implementations / gadget chains could be leveraged to perform a variety of malicious actions granted a POP chain is also present.

CVE-2023-34365
YF325 General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the libutils.so nvram_restore functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a buffer overflow. An attacker can send a network request to trigger this vulnerability.

CVE-2023-5601
WooCommerce Ninja Forms Product Add-ons Web Windows
9.8
CRITICAL
EPSS
0.8%
2023 2 PoCs

The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE.

CVE-2023-29728
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of privilege attack.

CVE-2023-37895
Apache Jackrabbit Webapp (jackrabbit-webapp) Web
9.8
CRITICAL
EPSS
9.9%
2023 CWE-502 1 PoC

Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (including) 2.20.10 (stable branch) and 2.21.17 (unstable branch) use the component "commons-beanutils", which contains a class that can be used for remote code execution over RMI. Users are advised to immediately update to versions 2.20.11 or 2.21.18. Note that earlier stable branches (1.0.x .. 2.18.x) have been EOLd already and do not receive updates anymore. In general, RMI support can expose vulnerabilities by the mere presence of an exploitabl

CVE-2023-31814
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2023 1 PoC

D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.

CVE-2023-3277
MStore API – Create Native Android & iOS Apps On The Cloud Web Cloud Windows ⚡ nuclei
9.8
CRITICAL
EPSS
47.2%
2023 CWE-288 0 PoCs

The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows unauthenticated attackers to log in as any user as long as they know the user's email address.

CVE-2023-50488
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2023 2 PoCs

An issue in Blurams Lumi Security Camera (A31C) v23.0406.435.4120 allows attackers to execute arbitrary code.

CVE-2023-5174
Firefox Windows
9.8
CRITICAL
EPSS
0.4%
2023 1 PoC

If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash. *This bug only affects Firefox on Windows when run in non-standard configurations (such as using `runas`). Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVE-2023-30945
com.palantir.gotham:clips2 General
9.8
CRITICAL
EPSS
0.4%
2023 CWE-287 1 PoC

Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vulnerability due to missing input validation on filenames. A malicious attacker could read sensitive files from the filesystem or write/delete arbitrary files on the filesystem as well.

CVE-2023-24331
Software Genérico General
9.8
CRITICAL
EPSS
5.6%
2023 1 PoC

Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands via the urlAdd parameter.

CVE-2023-2449
UserPro - Community and User Profile WordPress Plugin Web Database Windows
9.8
CRITICAL
EPSS
0.6%
2023 CWE-620 2 PoCs

The UserPro plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 5.1.1. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (userpro_process_form). The function uses the plaintext value of a password reset key instead of a hashed value which means it can easily be retrieved and subsequently used. An attacker can leverage CVE-2023-2448 and CVE-2023-2446, or another vulnerability like SQL Injection in another plugin or theme installed on the site to successfully exploit thi