728 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-24351
Software Genérico Networking
9.8
CRITICAL
EPSS
1.1%
2023 1 PoC

D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the FILECODE parameter at /goform/formLogin.

CVE-2023-29739
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 2 PoCs

An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the component.

CVE-2023-28662
Gift Cards (Gift Vouchers and Packages) WordPress Plugin Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
74.3%
2023 1 PoC

The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action.

CVE-2023-39169
Storage Box V1 General
9.8
CRITICAL
EPSS
0.4%
2023 CWE-798 2 PoCs

The affected devices use publicly available default credentials with administrative privileges.

CVE-2023-30280
Software Genérico General
9.8
CRITICAL
EPSS
4.5%
2023 1 PoC

Buffer Overflow vulnerability found in Netgear R6900 v.1.0.2.26, R6700v3 v.1.0.4.128, R6700 v.1.0.0.26 allows a remote attacker to execute arbitrary code and cause a denial ofservice via the getInputData parameter of the fwSchedule.cgi page.

CVE-2023-30192
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
41.9%
2023 1 PoC

Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().

CVE-2023-24352
Software Genérico Networking
9.8
CRITICAL
EPSS
0.5%
2023 1 PoC

D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWPS.

CVE-2023-5642
R-SeeNet General
9.8
CRITICAL
EPSS
41.8%
2023 CWE-200 1 PoC

Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive information.

CVE-2023-4744
AC8 General
9.8
CRITICAL
EPSS
0.4%
2023 CWE-121 1 PoC

A vulnerability was found in Tenda AC8 16.03.34.06_cn_TDC01. It has been declared as critical. Affected by this vulnerability is the function formSetDeviceName. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-238633 was assigned to this vulnerability.

CVE-2023-1698
Compact Controller CC100 General ⚡ nuclei
9.8
CRITICAL
EPSS
93.8%
2023 CWE-78 6 PoCs

In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.

CVE-2023-0851
Canon Office/Small Office Multifunction Printers and Laser Printers General
9.8
CRITICAL
EPSS
0.3%
2023 CWE-122 1 PoC

Buffer overflow in CPCA Resource Download process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i fir

CVE-2023-30013
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
92.4%
2023 1 PoC

TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.

CVE-2023-1730
SupportCandy Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
81.8%
2023 1 PoC

The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks

CVE-2023-51968
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function getIptvInfo.

CVE-2023-28503
UniData General
9.8
CRITICAL
EPSS
64.8%
2023 CWE-798 2 PoCs

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user.

CVE-2023-25218
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2023 1 PoC

Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the form_fast_setting_wifi_set function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

CVE-2023-27396
Multiple OMRON products which implement FINS protocol General
9.8
CRITICAL
EPSS
1.7%
2023 2 PoCs

FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation) networks, and is used in FA networks composed of OMRON products. Multiple OMRON products that implement FINS protocol contain following security issues -- (1)Plaintext communication, and (2)No authentication required. When FINS messages are intercepted, the contents may be retrieved. When arbitrary FINS messages are injected, any commands may be executed on, or the system information may be retrieved from, the affected device. Affected products and versio

CVE-2023-51812
Software Genérico General
9.8
CRITICAL
EPSS
2.6%
2023 1 PoC

Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList.

CVE-2023-26802
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
83.6%
2023 0 PoCs

An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass authentication and execute arbitrary commands via a crafted request.

CVE-2023-25078
Experion Server General
9.8
CRITICAL
EPSS
0.1%
2023 CWE-787 1 PoC

Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation.  See Honeywell Security Notification for recommendations on upgrading and versioning.